-
Notifications
You must be signed in to change notification settings - Fork 0
/
security-context.xml
103 lines (71 loc) · 3.26 KB
/
security-context.xml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
<?xml version="1.0" encoding="UTF-8"?>
<beans xmlns="http://www.springframework.org/schema/beans"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:security="http://www.springframework.org/schema/security"
xsi:schemaLocation="http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security-4.1.xsd
http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd">
<!-- <security:csrf disabled="true" /> -->
<security:authentication-manager>
<security:authentication-provider>
<security:jdbc-user-service
data-source-ref="dataSource"
authorities-by-username-query='select username, authority from users where binary username = ?'
users-by-username-query='select username, password, enabled from users where binary username = ?'
id="jdbcUserService" />
<security:password-encoder ref="passwordEncoder"></security:password-encoder>
</security:authentication-provider>
</security:authentication-manager>
<security:http use-expressions="true">
<security:intercept-url pattern="/admin"
access="hasAuthority('ROLE_ADMIN')" />
<security:intercept-url pattern="/create"
access="isAuthenticated()" />
<security:intercept-url pattern="/offerDeleted"
access="isAuthenticated()" />
<security:intercept-url pattern="/iscreated"
access="isAuthenticated()" />
<security:intercept-url pattern="/sendMessage"
access="isAuthenticated()" />
<security:intercept-url pattern="/offerCreated"
access="isAuthenticated()" />
<security:intercept-url pattern="/messages"
access="isAuthenticated()" />
<security:intercept-url pattern="/getMessages"
access="isAuthenticated()" />
<security:intercept-url pattern="/" access="permitAll" />
<security:intercept-url pattern="/message" access="permitAll" />
<security:intercept-url pattern="/denied"
access="permitAll" />
<security:intercept-url pattern="/newAccount"
access="permitAll" />
<security:intercept-url pattern="/register"
access="permitAll" />
<security:intercept-url pattern="/loggedOut"
access="permitAll" />
<security:intercept-url pattern="/loginForm"
access="permitAll" />
<security:intercept-url pattern="/createAccount"
access="permitAll" />
<security:intercept-url pattern="/accountCreated"
access="permitAll" />
<security:intercept-url pattern="/show" access="permitAll" />
<security:intercept-url pattern="/static/**"
access="permitAll" />
<security:intercept-url pattern="/login"
access="permitAll" />
<security:intercept-url pattern="/logout"
access="permitAll" />
<security:intercept-url pattern="/**" access="denyAll" />
<security:form-login login-page="/loginForm"
authentication-failure-url="/login?error=true" default-target-url="/"
always-use-default-target="true" />
<security:access-denied-handler
error-page="/denied" />
<security:remember-me key="offersAppKey"
user-service-ref="jdbcUserService" />
</security:http>
<security:global-method-security
secured-annotations="enabled"></security:global-method-security>
<bean id="passwordEncoder"
class="org.springframework.security.crypto.password.StandardPasswordEncoder">
</bean>
</beans>