Browse Source
Merge pull request #6485 from smatvienko-tb/web-security-ignore-replaced-with-permit-all
[3.4] You are asking Spring Security to ignore Ant [pattern='/*.js']. This is not recommended -- please use permitAll via HttpSecurity#authorizeHttpRequests instead.
pull/6519/head
Andrew Shvayka
4 years ago
committed by
GitHub
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with
5 additions and
5 deletions
application/src/main/java/org/thingsboard/server/config/ThingsboardSecurityConfiguration.java
@ -176,16 +176,16 @@ public class ThingsboardSecurityConfiguration extends WebSecurityConfigurerAdapt
return new BCryptPasswordEncoder ( ) ;
return new BCryptPasswordEncoder ( ) ;
}
}
@Override
public void configure ( WebSecurity web ) throws Exception {
web . ignoring ( ) . antMatchers ( "/*.js" , "/*.css" , "/*.ico" , "/assets/**" , "/static/**" ) ;
}
@Autowired
@Autowired
private OAuth2AuthorizationRequestResolver oAuth2AuthorizationRequestResolver ;
private OAuth2AuthorizationRequestResolver oAuth2AuthorizationRequestResolver ;
@Override
@Override
protected void configure ( HttpSecurity http ) throws Exception {
protected void configure ( HttpSecurity http ) throws Exception {
http . authorizeHttpRequests ( ( authorizeHttpRequests ) - >
authorizeHttpRequests
. antMatchers ( "/*.js" , "/*.css" , "/*.ico" , "/assets/**" , "/static/**" )
. permitAll ( )
) ;
http . headers ( ) . cacheControl ( ) . and ( ) . frameOptions ( ) . disable ( )
http . headers ( ) . cacheControl ( ) . and ( ) . frameOptions ( ) . disable ( )
. and ( )
. and ( )
. cors ( )
. cors ( )