Posts

Showing posts with the label Configuration

Spring Security: Configuring HttpSecurity

Spring Security 5.4 introduced the ability to configure HttpSecurity by creating a SecurityFilterChain bean. Below is an example configuration using the WebSecurityConfigurerAdapter that secures all endpoints with HTTP Basic: @Configuration public class SecurityConfiguration extends WebSecurityConfigurerAdapter {     @Override     protected void configure(HttpSecurity http) throws Exception {         http             .authorizeHttpRequests((authz) -> authz                 .anyRequest().authenticated()             )             .httpBasic(withDefaults());     } } Going forward, the recommended way of doing this is registering a SecurityFilterChain bean: @Configuration public class SecurityConfiguration {     @Bean     public SecurityFilterChain filterChain(HttpSecurity http) throws Except...

Spring Security: Configuring WebSecurity

Spring Security 5.4 also introduced the WebSecurityCustomizer. The WebSecurityCustomizer is a callback interface that can be used to customize WebSecurity. Below is an example configuration using the WebSecurityConfigurerAdapter that ignores requests that match /ignore1 or /ignore2: @Configuration public class SecurityConfiguration extends WebSecurityConfigurerAdapter {     @Override     public void configure(WebSecurity web) {         web.ignoring().antMatchers("/ignore1", "/ignore2");     } } Going forward, the recommended way of doing this is registering a WebSecurityCustomizer bean: @Configuration public class SecurityConfiguration {     @Bean     public WebSecurityCustomizer webSecurityCustomizer() {         return (web) -> web.ignoring().antMatchers("/ignore1", "/ignore2");     } } WARNING: If you are configuring WebSecurity to ignore requests, consider using permitAll via HttpSe...

Spring Security: LDAP Authentication exampe

Spring Security 5.7 introduced the EmbeddedLdapServerContextSourceFactoryBean, LdapBindAuthenticationManagerFactory and LdapPasswordComparisonAuthenticationManagerFactory which can be used to create an embedded LDAP Server and an AuthenticationManager that performs LDAP authentication. Below is an example configuration using WebSecurityConfigurerAdapter the that creates an embedded LDAP server and an AuthenticationManager that performs LDAP authentication using bind authentication: @Configuration public class SecurityConfiguration extends WebSecurityConfigurerAdapter {     @Override     protected void configure(AuthenticationManagerBuilder auth) throws Exception {         auth             .ldapAuthentication()             .userDetailsContextMapper(new PersonContextMapper())             .userDnPatterns("uid={0},ou=people")           ...