Spring Security 6角色前缀设置方法及旧代码迁移咨询
问题:Spring Security 6 中设置角色前缀并迁移旧代码
我是Java与Spring Security的新手,Spring Security 6中有大量类和接口已被弃用。我知晓该版本需使用AuthorizationManager,但不清楚如何设置角色前缀。此前用于设置角色前缀的RoleVoter类也已被弃用,现需将以下旧代码迁移至Spring Security 6:
import java.util.List; import org.aopalliance.intercept.MethodInterceptor; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.security.access.AccessDecisionManager; import org.springframework.security.access.AccessDecisionVoter; import org.springframework.security.access.intercept.aopalliance.MethodSecurityInterceptor; import org.springframework.security.access.vote.AbstractAccessDecisionManager; import org.springframework.security.access.vote.RoleVoter; import org.springframework.stereotype.Component; import jakarta.annotation.PostConstruct; @Component public class AccessDecisionManagerCustomizer { @Autowired protected MethodInterceptor methodSecurityInterceptor; @PostConstruct public void init() { if (methodSecurityInterceptor instanceof MethodSecurityInterceptor) { AccessDecisionManager accessDecisionManager = ((MethodSecurityInterceptor) methodSecurityInterceptor).getAccessDecisionManager(); if (accessDecisionManager instanceof AbstractAccessDecisionManager) { List<AccessDecisionVoter<? extends Object>> voters = ((AbstractAccessDecisionManager) accessDecisionManager).getDecisionVoters(); RoleVoter scopeVoter = new RoleVoter(); scopeVoter.setRolePrefix("SCOPE_"); voters.add(scopeVoter); } else // throw exception here } else // throw exception here } }
此外,我们自定义OAuth库中的SecurityFilterChain类如下:
import org.springframework.beans.factory.annotation.Autowired; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.ComponentScan; import org.springframework.context.annotation.Configuration; import org.springframework.security.authentication.AuthenticationProvider; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.oauth2.jwt.JwtDecoder; import org.springframework.security.oauth2.server.resource.authentication.JwtAuthenticationProvider; import org.springframework.security.web.access.ExceptionTranslationFilter; import com.oauth.web.filter.SSOCookieAuthenticationFilter; import com.oauth.web.security.oauth2.PreAuthAccessDeniedHandler; @Configuration @ComponentScan("com.oauth.web") public class SecurityFilterChain { @Autowired SSOCookieAuthenticationFilter sSOCookieAuthenticationFilter; public void configure(HttpSecurity http) throws Exception { http.addFilterAfter(sSOCookieAuthenticationFilter, ExceptionTranslationFilter.class); http.exceptionHandling().authenticationEntryPoint(new PreAuthAccessDeniedHandler()); } }
项目中继承该类的配置类如下:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.core.env.Environment; import org.springframework.security.config.Customizer; import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityCustomizer; import org.springframework.security.config.annotation.web.configurers.HeadersConfigurer; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.csrf.CookieCsrfTokenRepository; import org.springframework.security.web.csrf.CsrfTokenRepository; import static org.springframework.security.config.Customizer.withDefaults; import com.oauth.web.SecurityFilterChain; @Configuration @EnableWebSecurity @EnableMethodSecurity(securedEnabled = true) public class SSOSecurityConfig extends SecurityFilterChain { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http.headers(headers -> headers.frameOptions(createFrameOptionCustomizer()) .contentSecurityPolicy(csp -> csp.policyDirectives(CSP))) .authorizeHttpRequests(auth -> auth .requestMatchers(EndpointRequest.to(InfoEndpoint.class), EndpointRequest.to(HealthEndpoint.class)).permitAll() .requestMatchers(EndpointRequest.toAnyEndpoint()).authenticated() .requestMatchers("/", "/login**", "/callback/", "/oauth2/authorization/**", "/error**").permitAll() .anyRequest().fullyAuthenticated()) .httpBasic(withDefaults()); http.csrf(csrf -> csrf.csrfTokenRepository(createCsrfTokenRepository())); super.configure(http); return http.build(); } private CsrfTokenRepository createCsrfTokenRepository() { CookieCsrfTokenRepository cookieCsrfTokenRepository = CookieCsrfTokenRepository.withHttpOnlyFalse(); cookieCsrfTokenRepository.setCookiePath("/"); return cookieCsrfTokenRepository; } private Customizer<HeadersConfigurer<HttpSecurity>.FrameOptionsConfig> createFrameOptionCustomizer() { if (Arrays.stream(environment.getActiveProfiles()).anyMatch("local"::equalsIgnoreCase)) { return HeadersConfigurer.FrameOptionsConfig::disable; } return HeadersConfigurer.FrameOptionsConfig::sameOrigin; } }
我已查阅官方文档,但未找到Spring Security 6中修改角色前缀的相关内容,恳请各位提供帮助。
内容的提问来源于stack exchange,提问作者Sachin Brar
相关产品推荐
相关产品推荐

