summaryrefslogtreecommitdiffhomepage
path: root/backend/src/main/java/com/blog/web/security
diff options
context:
space:
mode:
authorrealtradam <[email protected]>2024-07-25 22:52:33 -0400
committerrealtradam <[email protected]>2024-07-25 22:52:33 -0400
commit6b342f97f6a605b7e1fe34584abbbf962ca39b7c (patch)
tree5d81805b3167b247e203a78a0c84bf11865ee9cd /backend/src/main/java/com/blog/web/security
parentc01264b60b7ad8bb3eb3dcf4d3ec0b77bcd4c3d1 (diff)
downloadspring-blog-6b342f97f6a605b7e1fe34584abbbf962ca39b7c.tar.gz
spring-blog-6b342f97f6a605b7e1fe34584abbbf962ca39b7c.zip
implement user login
Diffstat (limited to 'backend/src/main/java/com/blog/web/security')
-rw-r--r--backend/src/main/java/com/blog/web/security/SecurityConfig.java2
1 files changed, 1 insertions, 1 deletions
diff --git a/backend/src/main/java/com/blog/web/security/SecurityConfig.java b/backend/src/main/java/com/blog/web/security/SecurityConfig.java
index 17e09c7..2be6909 100644
--- a/backend/src/main/java/com/blog/web/security/SecurityConfig.java
+++ b/backend/src/main/java/com/blog/web/security/SecurityConfig.java
@@ -28,7 +28,7 @@ public class SecurityConfig {
@Bean
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
// disabling csrf leaves us vulnerable, in a real production app do not do this
- http.csrf(c -> c.disable()).cors(c -> c.disable()).authorizeHttpRequests(auths -> auths.anyRequest().permitAll()).formLogin(form -> form.loginPage("/userlogin").usernameParameter("username").passwordParameter("password").defaultSuccessUrl("/articles").loginProcessingUrl("/userlogin").failureUrl("/userlogin?error=true").permitAll()).logout(logout -> logout.logoutUrl("/logout").logoutSuccessUrl("/articles"));
+ http.csrf(c -> c.disable()).cors(c -> c.disable()).authorizeHttpRequests(auths -> auths.anyRequest().permitAll()).formLogin(form -> form.loginPage("/login").usernameParameter("username").passwordParameter("password").defaultSuccessUrl("/").loginProcessingUrl("/userlogin").failureUrl("/userlogin?error=true").permitAll()).logout(logout -> logout.logoutUrl("/logout").logoutSuccessUrl("/articles"));
return http.build();
}