Skip to content

Latest commit

 

History

History
52 lines (34 loc) · 1.33 KB

File metadata and controls

52 lines (34 loc) · 1.33 KB

Demo state:

Pages:

  • Public page
  • Private page

Users:

  1. Basic app local login
  • /admin page -> .hasRole("...")
  • Admin method on the public page (?mode=admin) -> @PreAuthorize("hasRole('admin')")
  1. Request-level security

We've seen .hasRole()

  • /profile/{username} page -> .hasVariable("...")
  • /corp page -> .access(email.endsWith("@corp.example.com")
  • /profile/{username} page -> add .hasRole("admin"), and then compose
  1. Method-level

We've seen @PreAuthorize

  • /shipments page shows shipments -> @PreAuthorize(authentication.email.endsWith('@corp.example.com') or authentication.email.endsWith('@example.com'))
  • /method-security/profile/{username} -> @PostAuthorize(authentication.email.sameDomain(returnObject))
  • /shipments page -> @HasDomain(...) custom annotation
  1. Field-level
  • /shipmemts address -> @PreAuthorize("hasRole('admin')")
  1. Information is key
  • Login-based timing
    • HTTP-basic vs LoginForm -> custom AuthenticationDetailsSource
    • Optional: Custom authentication provider to compare email
  • Context is key
    • /localhost endpoint allowed only on localhost

Parked:

  • Role hierarchy
  • External auth service