| | |
| | | package com.trafficaudit.security.config; |
| | | |
| | | import com.trafficaudit.security.filter.JwtAuthFilter; |
| | | import org.springframework.context.annotation.Bean; |
| | | import org.springframework.context.annotation.Configuration; |
| | | import org.springframework.security.config.annotation.web.builders.HttpSecurity; |
| | |
| | | import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; |
| | | import org.springframework.security.crypto.password.PasswordEncoder; |
| | | import org.springframework.security.web.SecurityFilterChain; |
| | | import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter; |
| | | |
| | | import javax.annotation.Resource; |
| | | |
| | | @Configuration |
| | | @EnableWebSecurity |
| | | public class SecurityConfig { |
| | | |
| | | @Resource |
| | | private JwtAuthFilter jwtAuthFilter; |
| | | |
| | | @Bean |
| | | public PasswordEncoder passwordEncoder() { |
| | |
| | | public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { |
| | | http |
| | | .csrf().disable() |
| | | .cors().and() |
| | | .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS) |
| | | .and() |
| | | .authorizeRequests() |
| | | .antMatchers("/api/**").permitAll() |
| | | .antMatchers("/", "/index.html", "/js/**", "/css/**", "/fonts/**", "/img/**", "/favicon.ico").permitAll() |
| | | .anyRequest().authenticated(); |
| | | // 登录前必须可用的接口 |
| | | .antMatchers("/api/auth/login", "/api/auth/captcha", "/api/auth/captcha/verify", |
| | | "/api/auth/captcha-config").permitAll() |
| | | // 前端静态资源 |
| | | .antMatchers("/", "/index.html", "/favicon.ico", "/js/**", "/css/**", "/fonts/**", "/img/**", "/static/**").permitAll() |
| | | .anyRequest().permitAll() |
| | | .and() |
| | | // 接口鉴权在 JwtAuthFilter 内完成(返回 JSON 401) |
| | | .addFilterBefore(jwtAuthFilter, UsernamePasswordAuthenticationFilter.class); |
| | | return http.build(); |
| | | } |
| | | } |
| | | } |