Spring Boot Security + Sping Boot REST Repository config issue
I have Spring boot application as below
And the Web Security Config as
@Configuration
@EnableWebSecurity
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
@Override
protected void configure(HttpSecurity http) throws Exception {
http.authorizeRequests().anyRequest().authenticated().and().formLogin();
}
@Override
protected void configure(AuthenticationManagerBuilder auth) throws Exception {
// @formatter:off
auth.inMemoryAuthentication().withUser("chiru").password("{noop}chiru").roles("ADMIN").and().withUser("user")
.password("{noop}user").roles("USER");
// @formatter:on
}
}
And the i have Repository as below
public interface IssuesRepository extends CrudRepository<Issues, Integer> {
}
when i try to add data through REST Using Postman with Basic Authentication, its failing
spring-boot spring-security spring-repositories
add a comment |
I have Spring boot application as below
And the Web Security Config as
@Configuration
@EnableWebSecurity
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
@Override
protected void configure(HttpSecurity http) throws Exception {
http.authorizeRequests().anyRequest().authenticated().and().formLogin();
}
@Override
protected void configure(AuthenticationManagerBuilder auth) throws Exception {
// @formatter:off
auth.inMemoryAuthentication().withUser("chiru").password("{noop}chiru").roles("ADMIN").and().withUser("user")
.password("{noop}user").roles("USER");
// @formatter:on
}
}
And the i have Repository as below
public interface IssuesRepository extends CrudRepository<Issues, Integer> {
}
when i try to add data through REST Using Postman with Basic Authentication, its failing
spring-boot spring-security spring-repositories
Firstof all in the password i see that you make {noop}... is that normale ? Else try to put on top of your rest method @PreAuthorize("hasAnyRole('ADMIN')") and test if it will be ok
– TinyOS
Nov 28 '18 at 12:57
{noop} means i dont want to encrypt the password
– chiranjeevigk
Nov 29 '18 at 6:43
add a comment |
I have Spring boot application as below
And the Web Security Config as
@Configuration
@EnableWebSecurity
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
@Override
protected void configure(HttpSecurity http) throws Exception {
http.authorizeRequests().anyRequest().authenticated().and().formLogin();
}
@Override
protected void configure(AuthenticationManagerBuilder auth) throws Exception {
// @formatter:off
auth.inMemoryAuthentication().withUser("chiru").password("{noop}chiru").roles("ADMIN").and().withUser("user")
.password("{noop}user").roles("USER");
// @formatter:on
}
}
And the i have Repository as below
public interface IssuesRepository extends CrudRepository<Issues, Integer> {
}
when i try to add data through REST Using Postman with Basic Authentication, its failing
spring-boot spring-security spring-repositories
I have Spring boot application as below
And the Web Security Config as
@Configuration
@EnableWebSecurity
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
@Override
protected void configure(HttpSecurity http) throws Exception {
http.authorizeRequests().anyRequest().authenticated().and().formLogin();
}
@Override
protected void configure(AuthenticationManagerBuilder auth) throws Exception {
// @formatter:off
auth.inMemoryAuthentication().withUser("chiru").password("{noop}chiru").roles("ADMIN").and().withUser("user")
.password("{noop}user").roles("USER");
// @formatter:on
}
}
And the i have Repository as below
public interface IssuesRepository extends CrudRepository<Issues, Integer> {
}
when i try to add data through REST Using Postman with Basic Authentication, its failing
spring-boot spring-security spring-repositories
spring-boot spring-security spring-repositories
asked Nov 28 '18 at 12:20
chiranjeevigkchiranjeevigk
76511132
76511132
Firstof all in the password i see that you make {noop}... is that normale ? Else try to put on top of your rest method @PreAuthorize("hasAnyRole('ADMIN')") and test if it will be ok
– TinyOS
Nov 28 '18 at 12:57
{noop} means i dont want to encrypt the password
– chiranjeevigk
Nov 29 '18 at 6:43
add a comment |
Firstof all in the password i see that you make {noop}... is that normale ? Else try to put on top of your rest method @PreAuthorize("hasAnyRole('ADMIN')") and test if it will be ok
– TinyOS
Nov 28 '18 at 12:57
{noop} means i dont want to encrypt the password
– chiranjeevigk
Nov 29 '18 at 6:43
Firstof all in the password i see that you make {noop}... is that normale ? Else try to put on top of your rest method @PreAuthorize("hasAnyRole('ADMIN')") and test if it will be ok
– TinyOS
Nov 28 '18 at 12:57
Firstof all in the password i see that you make {noop}... is that normale ? Else try to put on top of your rest method @PreAuthorize("hasAnyRole('ADMIN')") and test if it will be ok
– TinyOS
Nov 28 '18 at 12:57
{noop} means i dont want to encrypt the password
– chiranjeevigk
Nov 29 '18 at 6:43
{noop} means i dont want to encrypt the password
– chiranjeevigk
Nov 29 '18 at 6:43
add a comment |
1 Answer
1
active
oldest
votes
Use httpBasic()
instead of formLogin()
, like http.authorizeRequests().anyRequest().authenticated().and().httpBasic();
.
formLogin() is used when you want to have login page to authenticate the user (so you have), but in your example you are using http basic to do that. Spring security doesn't recognizes your http basic header and returns login page.
PS. You can use both methods http.httpBasic().and().formLogin()
add a comment |
Your Answer
StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53519362%2fspring-boot-security-sping-boot-rest-repository-config-issue%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
Use httpBasic()
instead of formLogin()
, like http.authorizeRequests().anyRequest().authenticated().and().httpBasic();
.
formLogin() is used when you want to have login page to authenticate the user (so you have), but in your example you are using http basic to do that. Spring security doesn't recognizes your http basic header and returns login page.
PS. You can use both methods http.httpBasic().and().formLogin()
add a comment |
Use httpBasic()
instead of formLogin()
, like http.authorizeRequests().anyRequest().authenticated().and().httpBasic();
.
formLogin() is used when you want to have login page to authenticate the user (so you have), but in your example you are using http basic to do that. Spring security doesn't recognizes your http basic header and returns login page.
PS. You can use both methods http.httpBasic().and().formLogin()
add a comment |
Use httpBasic()
instead of formLogin()
, like http.authorizeRequests().anyRequest().authenticated().and().httpBasic();
.
formLogin() is used when you want to have login page to authenticate the user (so you have), but in your example you are using http basic to do that. Spring security doesn't recognizes your http basic header and returns login page.
PS. You can use both methods http.httpBasic().and().formLogin()
Use httpBasic()
instead of formLogin()
, like http.authorizeRequests().anyRequest().authenticated().and().httpBasic();
.
formLogin() is used when you want to have login page to authenticate the user (so you have), but in your example you are using http basic to do that. Spring security doesn't recognizes your http basic header and returns login page.
PS. You can use both methods http.httpBasic().and().formLogin()
answered Nov 28 '18 at 13:06
Andrew SashaAndrew Sasha
581315
581315
add a comment |
add a comment |
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53519362%2fspring-boot-security-sping-boot-rest-repository-config-issue%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Firstof all in the password i see that you make {noop}... is that normale ? Else try to put on top of your rest method @PreAuthorize("hasAnyRole('ADMIN')") and test if it will be ok
– TinyOS
Nov 28 '18 at 12:57
{noop} means i dont want to encrypt the password
– chiranjeevigk
Nov 29 '18 at 6:43