Spring security @PreAuthorize not working












0















I have working basic security example, now I need to add @PreAuthorize on API level. in my controller



@RequestMapping(value = "/user", method = RequestMethod.GET)
@PreAuthorize("hasRole('ROLE_USER')")
public Data userHome() {
Data d = new Data();
d.setName("user");
d.setRollNo(5);
d.setD(new Date());
return d;
}

@RequestMapping(value = "/admin", method = RequestMethod.GET)
@PreAuthorize("hasRole('ROLE_ADMIN')")
public Data adminHome() {
Data d = new Data();
d.setName("admin");
d.setRollNo(2);
return d;
}


spring security configuration is as below



    <beans:beans xmlns="http://www.springframework.org/schema/security"
xmlns:beans="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://www.springframework.org/schema/beans
http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
http://www.springframework.org/schema/security
http://www.springframework.org/schema/security/spring-security.xsd">
<global-method-security pre-post-annotations="enabled" />
<http auto-config="true" use-expressions="true">
<logout delete-cookies="JSESSIONID" />
<remember-me />
<intercept-url pattern="/*" access="isAuthenticated()" />
</http>
<debug />
<authentication-manager>
<authentication-provider>
<user-service id="userService">
<user name="admin" password="{noop}admin" authorities="ROLE_ADMIN" />
<user name="user" password="{noop}user" authorities="ROLE_USER" />
</user-service>
</authentication-provider>
</authentication-manager>
<beans:bean id="passwordEncoder"
class="org.springframework.security.crypto.password.NoOpPasswordEncoder"
factory-method="getInstance" />
<beans:bean id="loggerListener" class="org.springframework.security.authentication.event.LoggerListener" />
</beans:beans>


authentication is working fine, the issue is that even user with ROLE_USER is able to access /admin API, so does user with ROLE_ADMIN can access /user API, I have used <global-method-security pre-post-annotations="enabled"/> but it dosent seems to be working, what else am I missing?










share|improve this question



























    0















    I have working basic security example, now I need to add @PreAuthorize on API level. in my controller



    @RequestMapping(value = "/user", method = RequestMethod.GET)
    @PreAuthorize("hasRole('ROLE_USER')")
    public Data userHome() {
    Data d = new Data();
    d.setName("user");
    d.setRollNo(5);
    d.setD(new Date());
    return d;
    }

    @RequestMapping(value = "/admin", method = RequestMethod.GET)
    @PreAuthorize("hasRole('ROLE_ADMIN')")
    public Data adminHome() {
    Data d = new Data();
    d.setName("admin");
    d.setRollNo(2);
    return d;
    }


    spring security configuration is as below



        <beans:beans xmlns="http://www.springframework.org/schema/security"
    xmlns:beans="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="http://www.springframework.org/schema/beans
    http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
    http://www.springframework.org/schema/security
    http://www.springframework.org/schema/security/spring-security.xsd">
    <global-method-security pre-post-annotations="enabled" />
    <http auto-config="true" use-expressions="true">
    <logout delete-cookies="JSESSIONID" />
    <remember-me />
    <intercept-url pattern="/*" access="isAuthenticated()" />
    </http>
    <debug />
    <authentication-manager>
    <authentication-provider>
    <user-service id="userService">
    <user name="admin" password="{noop}admin" authorities="ROLE_ADMIN" />
    <user name="user" password="{noop}user" authorities="ROLE_USER" />
    </user-service>
    </authentication-provider>
    </authentication-manager>
    <beans:bean id="passwordEncoder"
    class="org.springframework.security.crypto.password.NoOpPasswordEncoder"
    factory-method="getInstance" />
    <beans:bean id="loggerListener" class="org.springframework.security.authentication.event.LoggerListener" />
    </beans:beans>


    authentication is working fine, the issue is that even user with ROLE_USER is able to access /admin API, so does user with ROLE_ADMIN can access /user API, I have used <global-method-security pre-post-annotations="enabled"/> but it dosent seems to be working, what else am I missing?










    share|improve this question

























      0












      0








      0








      I have working basic security example, now I need to add @PreAuthorize on API level. in my controller



      @RequestMapping(value = "/user", method = RequestMethod.GET)
      @PreAuthorize("hasRole('ROLE_USER')")
      public Data userHome() {
      Data d = new Data();
      d.setName("user");
      d.setRollNo(5);
      d.setD(new Date());
      return d;
      }

      @RequestMapping(value = "/admin", method = RequestMethod.GET)
      @PreAuthorize("hasRole('ROLE_ADMIN')")
      public Data adminHome() {
      Data d = new Data();
      d.setName("admin");
      d.setRollNo(2);
      return d;
      }


      spring security configuration is as below



          <beans:beans xmlns="http://www.springframework.org/schema/security"
      xmlns:beans="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
      xsi:schemaLocation="http://www.springframework.org/schema/beans
      http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
      http://www.springframework.org/schema/security
      http://www.springframework.org/schema/security/spring-security.xsd">
      <global-method-security pre-post-annotations="enabled" />
      <http auto-config="true" use-expressions="true">
      <logout delete-cookies="JSESSIONID" />
      <remember-me />
      <intercept-url pattern="/*" access="isAuthenticated()" />
      </http>
      <debug />
      <authentication-manager>
      <authentication-provider>
      <user-service id="userService">
      <user name="admin" password="{noop}admin" authorities="ROLE_ADMIN" />
      <user name="user" password="{noop}user" authorities="ROLE_USER" />
      </user-service>
      </authentication-provider>
      </authentication-manager>
      <beans:bean id="passwordEncoder"
      class="org.springframework.security.crypto.password.NoOpPasswordEncoder"
      factory-method="getInstance" />
      <beans:bean id="loggerListener" class="org.springframework.security.authentication.event.LoggerListener" />
      </beans:beans>


      authentication is working fine, the issue is that even user with ROLE_USER is able to access /admin API, so does user with ROLE_ADMIN can access /user API, I have used <global-method-security pre-post-annotations="enabled"/> but it dosent seems to be working, what else am I missing?










      share|improve this question














      I have working basic security example, now I need to add @PreAuthorize on API level. in my controller



      @RequestMapping(value = "/user", method = RequestMethod.GET)
      @PreAuthorize("hasRole('ROLE_USER')")
      public Data userHome() {
      Data d = new Data();
      d.setName("user");
      d.setRollNo(5);
      d.setD(new Date());
      return d;
      }

      @RequestMapping(value = "/admin", method = RequestMethod.GET)
      @PreAuthorize("hasRole('ROLE_ADMIN')")
      public Data adminHome() {
      Data d = new Data();
      d.setName("admin");
      d.setRollNo(2);
      return d;
      }


      spring security configuration is as below



          <beans:beans xmlns="http://www.springframework.org/schema/security"
      xmlns:beans="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
      xsi:schemaLocation="http://www.springframework.org/schema/beans
      http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
      http://www.springframework.org/schema/security
      http://www.springframework.org/schema/security/spring-security.xsd">
      <global-method-security pre-post-annotations="enabled" />
      <http auto-config="true" use-expressions="true">
      <logout delete-cookies="JSESSIONID" />
      <remember-me />
      <intercept-url pattern="/*" access="isAuthenticated()" />
      </http>
      <debug />
      <authentication-manager>
      <authentication-provider>
      <user-service id="userService">
      <user name="admin" password="{noop}admin" authorities="ROLE_ADMIN" />
      <user name="user" password="{noop}user" authorities="ROLE_USER" />
      </user-service>
      </authentication-provider>
      </authentication-manager>
      <beans:bean id="passwordEncoder"
      class="org.springframework.security.crypto.password.NoOpPasswordEncoder"
      factory-method="getInstance" />
      <beans:bean id="loggerListener" class="org.springframework.security.authentication.event.LoggerListener" />
      </beans:beans>


      authentication is working fine, the issue is that even user with ROLE_USER is able to access /admin API, so does user with ROLE_ADMIN can access /user API, I have used <global-method-security pre-post-annotations="enabled"/> but it dosent seems to be working, what else am I missing?







      spring security methods m






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 25 '18 at 6:58









      shrikant.sharmashrikant.sharma

      99110




      99110
























          0






          active

          oldest

          votes











          Your Answer






          StackExchange.ifUsing("editor", function () {
          StackExchange.using("externalEditor", function () {
          StackExchange.using("snippets", function () {
          StackExchange.snippets.init();
          });
          });
          }, "code-snippets");

          StackExchange.ready(function() {
          var channelOptions = {
          tags: "".split(" "),
          id: "1"
          };
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function() {
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled) {
          StackExchange.using("snippets", function() {
          createEditor();
          });
          }
          else {
          createEditor();
          }
          });

          function createEditor() {
          StackExchange.prepareEditor({
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader: {
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          },
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          });


          }
          });














          draft saved

          draft discarded


















          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53465358%2fspring-security-preauthorize-not-working%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown

























          0






          active

          oldest

          votes








          0






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes
















          draft saved

          draft discarded




















































          Thanks for contributing an answer to Stack Overflow!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid



          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.


          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53465358%2fspring-security-preauthorize-not-working%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          A CLEAN and SIMPLE way to add appendices to Table of Contents and bookmarks

          Calculate evaluation metrics using cross_val_predict sklearn

          Insert data from modal to MySQL (multiple modal on website)