ResourceServerConfig.java 2.7 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152
  1. package com.ym.mec.web.config;
  2. import org.springframework.beans.factory.annotation.Autowired;
  3. import org.springframework.context.annotation.Configuration;
  4. import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity;
  5. import org.springframework.security.config.annotation.web.builders.HttpSecurity;
  6. import org.springframework.security.oauth2.config.annotation.web.configuration.EnableResourceServer;
  7. import org.springframework.security.oauth2.config.annotation.web.configuration.ResourceServerConfigurerAdapter;
  8. import org.springframework.security.oauth2.config.annotation.web.configurers.ResourceServerSecurityConfigurer;
  9. import com.ym.mec.common.security.BaseAccessDeniedHandler;
  10. import com.ym.mec.common.security.BaseAuthenticationEntryPoint;
  11. @Configuration
  12. @EnableResourceServer
  13. @EnableGlobalMethodSecurity(prePostEnabled = true)
  14. public class ResourceServerConfig extends ResourceServerConfigurerAdapter {
  15. @Autowired
  16. private BaseAccessDeniedHandler baseAccessDeniedHandler;
  17. @Autowired
  18. private BaseAuthenticationEntryPoint baseAuthenticationEntryPoint;
  19. @Override
  20. public void configure(HttpSecurity http) throws Exception {
  21. http.csrf()
  22. .disable()
  23. .exceptionHandling()
  24. .accessDeniedHandler(baseAccessDeniedHandler)
  25. .authenticationEntryPoint(baseAuthenticationEntryPoint)
  26. .and()
  27. .authorizeRequests()
  28. .antMatchers("/task/**")
  29. .hasIpAddress("0.0.0.0/0")
  30. .antMatchers("/v2/api-docs", "/classGroup/highClassGroups", "/code/*", "/api/*", "/appVersionInfo/queryByPlatform", "/eduDegree/*",
  31. "/uploadFile", "/eduContracts/queryProduceContract", "/activity/doubleEleven2020Statis", "/replacementInstrument/queryPage",
  32. "/replacementInstrumentActivity/queryReplacementsStat", "/eduStudentRegistration/queryPreApplyList",
  33. "/eduSubject/findSubSubjects", "/eduFinancialExpenditure/batchAdd", "/eduSendNotice/*",
  34. "/oaContracts/*", "/eduStudent/organStudentOverView", "/activity/countCloudTeacherActive",
  35. "/activity/organDoubleEleven2021Statis", "/activity/doubleEleven2021Statis", "/questionnaireTopic/getDetail", "/questionnaireUserResult/add",
  36. "/tenantInfo/info/*","/tenantInfo/pay/*","/tenantInfo/notify"
  37. )
  38. .permitAll().anyRequest().authenticated().and().httpBasic();
  39. }
  40. @Override
  41. public void configure(ResourceServerSecurityConfigurer resources) throws Exception {
  42. resources.authenticationEntryPoint(baseAuthenticationEntryPoint).accessDeniedHandler(baseAccessDeniedHandler);
  43. }
  44. }