Spring Security基于角色授权:删除/创建接口403 Forbidden问题
问题:删除库存项及创建新资源时遭遇403 Forbidden错误
我在删除库存项以及在数据库中创建新资源时遇到403 Forbidden错误,以下是我的配置代码和控制器实现:
WebSecurityConfiguration 类
package com.inventoryservice.config; import org.springframework.context.annotation.Bean; import org.springframework.http.HttpMethod; import org.springframework.security.authorization.AuthorityAuthorizationManager; import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; import org.springframework.security.crypto.password.NoOpPasswordEncoder; import org.springframework.security.crypto.password.PasswordEncoder; @EnableWebSecurity public class WebSecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(AuthenticationManagerBuilder auth) throws Exception { auth.inMemoryAuthentication() .withUser("test") .password("test_pass") .roles("ADMIN") .and() .withUser("store") .password("store_pass") .roles("USER"); } @Override protected void configure(HttpSecurity http) throws Exception { http .authorizeHttpRequests() .antMatchers(HttpMethod.DELETE, "/items-management").hasRole("ADMIN") .antMatchers(HttpMethod.POST, "/items-management").hasAnyRole("ADMIN","USER") .antMatchers(HttpMethod.GET, "/items-management").permitAll() .anyRequest().authenticated(); } @Bean public PasswordEncoder passwordEncoder() { return NoOpPasswordEncoder.getInstance(); } }
Inventory 控制器
该控制器配置了所有从服务获取数据库记录的端点,代码如下:
package com.inventoryservice.controller; import com.inventoryservice.dto.request.InventoryRequestDto; import com.inventoryservice.dto.response.InventoryItemDto; import com.inventoryservice.dto.response.InventoryResponseDto; import com.inventoryservice.entity.Inventory; import com.inventoryservice.service.ItemService; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.http.HttpStatus; import org.springframework.http.ResponseEntity; import org.springframework.web.bind.annotation.*; @RestController @RequestMapping("/items-management") public class InventoryController { private ItemService itemService; @Autowired public InventoryController(ItemService itemService) { this.itemService = itemService; } @GetMapping public ResponseEntity<InventoryResponseDto> getItems() { return new ResponseEntity( InventoryResponseDto.builder() .lines(itemService.getItems()) .build() , HttpStatus.OK ); } @PostMapping public ResponseEntity<InventoryResponseDto> create(@RequestBody InventoryRequestDto inventory) { return new ResponseEntity( InventoryResponseDto .builder() .lines(itemService.create(inventory.getLines())) .build() , HttpStatus.CREATED ); } @DeleteMapping public ResponseEntity delete(@RequestBody InventoryItemDto inventoryItemDto) { itemService.deleteItems( inventoryItemDto.getItemIds() ); return ResponseEntity.ok(inventoryItemDto); } }
内容的提问来源于stack exchange,提问作者Raza Haider
相关产品推荐
相关产品推荐

