Demo state:
Pages:
- Public page
- Private page
Users:
- daniel, daniel@example.com, ["user"]
- josh, josh@example.com, ["admin", "user"]
- alice, alice@corp.example.com, ["user"]
- bob, bob@ext.example.com, ["user"]
- Basic app local login
- /admin page ->
.hasRole("...") - Admin method on the public page (?mode=admin) ->
@PreAuthorize("hasRole('admin')")
- Request-level security
We've seen .hasRole()
- /profile/{username} page ->
.hasVariable("...") - /corp page ->
.access(email.endsWith("@corp.example.com") - /profile/{username} page -> add
.hasRole("admin"), and then compose
- Method-level
We've seen @PreAuthorize
/shipmentspage shows shipments ->@PreAuthorize(authentication.email.endsWith('@corp.example.com') or authentication.email.endsWith('@example.com'))/method-security/profile/{username}->@PostAuthorize(authentication.email.sameDomain(returnObject))/shipmentspage ->@HasDomain(...)custom annotation
- Field-level
/shipmemtsaddress ->@PreAuthorize("hasRole('admin')")
- Information is key
- Login-based timing
- HTTP-basic vs LoginForm -> custom
AuthenticationDetailsSource - Optional: Custom authentication provider to compare email
- HTTP-basic vs LoginForm -> custom
- Context is key
/localhostendpoint allowed only on localhost
Parked:
- Role hierarchy
- External auth service