Package app.YUP.config
Class SecurityConfig
java.lang.Object
app.YUP.config.SecurityConfig
Configuration class for Spring Security.
This class is responsible for setting up the security configuration of the application.
It defines the security filter chain and the URLs that are allowed to be accessed without authentication.
It is annotated with @Configuration to indicate that it is a Spring configuration class, @EnableWebSecurity to enable Spring Security's web security support, and @EnableMethodSecurity to enable method-level security.
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionorg.springframework.security.web.SecurityFilterChainsecurityFilterChain(org.springframework.security.config.annotation.web.builders.HttpSecurity http) Bean definition for SecurityFilterChain.
-
Constructor Details
-
SecurityConfig
public SecurityConfig()
-
-
Method Details
-
securityFilterChain
@Bean public org.springframework.security.web.SecurityFilterChain securityFilterChain(org.springframework.security.config.annotation.web.builders.HttpSecurity http) throws Exception Bean definition for SecurityFilterChain. This chain is used for applying the security configurations to the incoming requests. It disables CSRF, allows requests to the URLs in the white list, requires authentication for any other request, sets the session management policy to stateless, sets the authentication provider, and adds the JwtAuthenticationFilter before the UsernamePasswordAuthenticationFilter in the filter chain.- Parameters:
http- the HttpSecurity instance for building the security configuration- Returns:
- the SecurityFilterChain instance
- Throws:
Exception- if an error occurs while building the filter chain
-