diff options
| author | realtradam <[email protected]> | 2024-07-20 00:51:37 -0400 |
|---|---|---|
| committer | realtradam <[email protected]> | 2024-07-20 00:51:37 -0400 |
| commit | 5e2eab6f32bc76918aa17791b688d1df27d6ddfc (patch) | |
| tree | 420a0bcb5091d1e220fa8c42565a507897e11ec4 /src/main/java/com/blog/web/security/SecurityConfig.java | |
| parent | a6a60a5e774eed9d84f522fc452b67ee52e033cb (diff) | |
| download | spring-blog-5e2eab6f32bc76918aa17791b688d1df27d6ddfc.tar.gz spring-blog-5e2eab6f32bc76918aa17791b688d1df27d6ddfc.zip | |
code cleanup
Diffstat (limited to 'src/main/java/com/blog/web/security/SecurityConfig.java')
| -rw-r--r-- | src/main/java/com/blog/web/security/SecurityConfig.java | 19 |
1 files changed, 1 insertions, 18 deletions
diff --git a/src/main/java/com/blog/web/security/SecurityConfig.java b/src/main/java/com/blog/web/security/SecurityConfig.java index b459224..17e09c7 100644 --- a/src/main/java/com/blog/web/security/SecurityConfig.java +++ b/src/main/java/com/blog/web/security/SecurityConfig.java @@ -28,24 +28,7 @@ public class SecurityConfig { @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { // disabling csrf leaves us vulnerable, in a real production app do not do this - http.csrf(c -> c.disable()) - .cors(c -> c.disable()) - .authorizeHttpRequests( auths -> auths - .anyRequest() - .permitAll() - ) - .formLogin(form -> form - .loginPage("/userlogin") - .usernameParameter("username") - .passwordParameter("password") - .defaultSuccessUrl("/articles") - .loginProcessingUrl("/userlogin") - .failureUrl("/userlogin?error=true") - .permitAll() - ).logout( - logout -> logout - .logoutUrl("/logout") - .logoutSuccessUrl("/articles")); + http.csrf(c -> c.disable()).cors(c -> c.disable()).authorizeHttpRequests(auths -> auths.anyRequest().permitAll()).formLogin(form -> form.loginPage("/userlogin").usernameParameter("username").passwordParameter("password").defaultSuccessUrl("/articles").loginProcessingUrl("/userlogin").failureUrl("/userlogin?error=true").permitAll()).logout(logout -> logout.logoutUrl("/logout").logoutSuccessUrl("/articles")); return http.build(); } |
