chore(swagger): 移除Swagger相关配置和依赖
This commit is contained in:
+38
-63
@@ -75,71 +75,46 @@ public class SpringSecurityConfig {
|
||||
protected SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception {
|
||||
// 获取匿名标记
|
||||
Map<String, Set<String>> anonymousUrls = CsAnonTagUtil.getAnonymousUrl(applicationContext);
|
||||
|
||||
|
||||
// 创建TokenFilter实例
|
||||
TokenFilter customFilter = new TokenFilter(tokenProvider, systemUserOnlineInfoDAO);
|
||||
|
||||
|
||||
return httpSecurity
|
||||
// 禁用 CSRF
|
||||
.csrf(AbstractHttpConfigurer::disable)
|
||||
.addFilter(corsFilter)
|
||||
.addFilterBefore(customFilter, UsernamePasswordAuthenticationFilter.class)
|
||||
// 授权异常
|
||||
.exceptionHandling(exceptionHandling -> exceptionHandling
|
||||
.authenticationEntryPoint(authenticationErrorHandler)
|
||||
.accessDeniedHandler(jwtAccessDeniedHandler))
|
||||
// 防止iframe 造成跨域
|
||||
.headers(headers -> headers
|
||||
.frameOptions(HeadersConfigurer.FrameOptionsConfig::disable))
|
||||
// 不创建会话
|
||||
.sessionManagement(sessionManagement -> sessionManagement
|
||||
.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
|
||||
.authorizeHttpRequests(authorizeRequests -> authorizeRequests
|
||||
// 静态资源等等
|
||||
.requestMatchers(HttpMethod.GET, "/*.html", "/**/*.html", "/**/*.css", "/**/*.js", "/websocket/**")
|
||||
.permitAll()
|
||||
// swagger 文档
|
||||
.requestMatchers("/swagger-ui.html")
|
||||
.permitAll()
|
||||
.requestMatchers("/swagger-resources/**")
|
||||
.permitAll()
|
||||
.requestMatchers("/webjars/**")
|
||||
.permitAll()
|
||||
.requestMatchers("/*/api-docs")
|
||||
.permitAll()
|
||||
// 文件
|
||||
.requestMatchers("/avatar/**")
|
||||
.permitAll()
|
||||
.requestMatchers("/file/**")
|
||||
.permitAll()
|
||||
// 阿里巴巴 druid
|
||||
.requestMatchers("/druid/**")
|
||||
.permitAll()
|
||||
// 放行OPTIONS请求
|
||||
.requestMatchers(HttpMethod.OPTIONS, "/**")
|
||||
.permitAll()
|
||||
// 自定义匿名访问所有url放行:允许匿名和带Token访问,细腻化到每个 Request 类型
|
||||
// GET
|
||||
.requestMatchers(HttpMethod.GET, anonymousUrls.get(RequestMethodEnum.GET.getType()).toArray(new String[0]))
|
||||
.permitAll()
|
||||
// POST
|
||||
.requestMatchers(HttpMethod.POST, anonymousUrls.get(RequestMethodEnum.POST.getType()).toArray(new String[0]))
|
||||
.permitAll()
|
||||
// PUT
|
||||
.requestMatchers(HttpMethod.PUT, anonymousUrls.get(RequestMethodEnum.PUT.getType()).toArray(new String[0]))
|
||||
.permitAll()
|
||||
// PATCH
|
||||
.requestMatchers(HttpMethod.PATCH, anonymousUrls.get(RequestMethodEnum.PATCH.getType()).toArray(new String[0]))
|
||||
.permitAll()
|
||||
// DELETE
|
||||
.requestMatchers(HttpMethod.DELETE, anonymousUrls.get(RequestMethodEnum.DELETE.getType()).toArray(new String[0]))
|
||||
.permitAll()
|
||||
// 所有类型的接口都放行
|
||||
.requestMatchers(anonymousUrls.get(RequestMethodEnum.ALL.getType()).toArray(new String[0]))
|
||||
.permitAll()
|
||||
// 所有请求都需要认证
|
||||
.anyRequest()
|
||||
.authenticated())
|
||||
.build();
|
||||
// 禁用 CSRF
|
||||
.csrf(AbstractHttpConfigurer::disable).addFilter(corsFilter).addFilterBefore(customFilter, UsernamePasswordAuthenticationFilter.class)
|
||||
// 授权异常
|
||||
.exceptionHandling(
|
||||
exceptionHandling -> exceptionHandling.authenticationEntryPoint(authenticationErrorHandler).accessDeniedHandler(jwtAccessDeniedHandler))
|
||||
// 防止iframe 造成跨域
|
||||
.headers(headers -> headers.frameOptions(HeadersConfigurer.FrameOptionsConfig::disable))
|
||||
// 不创建会话
|
||||
.sessionManagement(sessionManagement -> sessionManagement.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
|
||||
.authorizeHttpRequests(authorizeRequests -> authorizeRequests
|
||||
// 静态资源等等
|
||||
.requestMatchers(HttpMethod.GET, "*.html", "*.css", "*.js", "/websocket/**").permitAll()
|
||||
// // Knife4j 和 OpenAPI 相关路径
|
||||
// .requestMatchers("/doc.html", "/webjars/**", "/v3/api-docs", "/v3/api-docs/**", "/swagger-resources", "/swagger-resources/**",
|
||||
// "/configuration/ui", "/configuration/security").permitAll()
|
||||
// 文件
|
||||
.requestMatchers("/avatar/**").permitAll().requestMatchers("/file/**").permitAll()
|
||||
// 阿里巴巴 druid
|
||||
.requestMatchers("/druid/**").permitAll()
|
||||
// 放行OPTIONS请求
|
||||
.requestMatchers(HttpMethod.OPTIONS, "/**").permitAll()
|
||||
// 自定义匿名访问所有url放行:允许匿名和带Token访问,细腻化到每个 Request 类型
|
||||
// GET
|
||||
.requestMatchers(HttpMethod.GET, anonymousUrls.get(RequestMethodEnum.GET.getType()).toArray(new String[0])).permitAll()
|
||||
// POST
|
||||
.requestMatchers(HttpMethod.POST, anonymousUrls.get(RequestMethodEnum.POST.getType()).toArray(new String[0])).permitAll()
|
||||
// PUT
|
||||
.requestMatchers(HttpMethod.PUT, anonymousUrls.get(RequestMethodEnum.PUT.getType()).toArray(new String[0])).permitAll()
|
||||
// PATCH
|
||||
.requestMatchers(HttpMethod.PATCH, anonymousUrls.get(RequestMethodEnum.PATCH.getType()).toArray(new String[0])).permitAll()
|
||||
// DELETE
|
||||
.requestMatchers(HttpMethod.DELETE, anonymousUrls.get(RequestMethodEnum.DELETE.getType()).toArray(new String[0])).permitAll()
|
||||
// 所有类型的接口都放行
|
||||
.requestMatchers(anonymousUrls.get(RequestMethodEnum.ALL.getType()).toArray(new String[0])).permitAll()
|
||||
// 所有请求都需要认证
|
||||
.anyRequest().authenticated()).build();
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user