{"id":1816,"date":"2019-09-06T22:45:23","date_gmt":"2019-09-06T13:45:23","guid":{"rendered":"http:\/\/idealive.jp\/blog\/?p=1816"},"modified":"2019-09-06T22:46:40","modified_gmt":"2019-09-06T13:46:40","slug":"spring-security%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6","status":"publish","type":"post","link":"https:\/\/idealive.jp\/blog\/2019\/09\/06\/spring-security%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6\/","title":{"rendered":"Spring Security\u306b\u3064\u3044\u3066"},"content":{"rendered":"<p>\u7686\u3055\u3093\u3053\u3093\u306b\u3061\u306f\u3001r.matsumoto\u3067\u3059\u3002<\/p>\n<p>\u4eca\u56de\u306e\u8a18\u4e8b\u306fSpring Security\u306b\u3064\u3044\u3066\u3067\u3059\u3002<\/p>\n<p>Spring Security\u3068\u306fSpring\u3067\u30ed\u30b0\u30a4\u30f3\u6a5f\u80fd\u306a\u3069\u3092\u5b9f\u88c5\u3059\u308b\u969b\u306b\u3068\u3066\u3082\u4fbf\u5229\u3067\u3001\u6a29\u9650\u6bce\u306b\u95b2\u89a7\u3067\u304d\u308b\u30da\u30fc\u30b8\u3092\u8a2d\u5b9a\u51fa\u6765\u305f\u308a\u3001CSRF\u5bfe\u7b56\u306a\u3069\u3082\u3084\u3063\u3066\u304f\u308b\u3068\u3066\u3082\u4fbf\u5229\u306a\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u3067\u3059\u3002<\/p>\n<p>\u305d\u3093\u306a\u4fbf\u5229\u306aSpring Security\u3067\u3059\u304c\u79c1\u304c\u3068\u3066\u3082\u30cf\u30de\u3063\u3066\u3057\u307e\u3063\u305f\u4e8b\u304c\u3042\u308b\u306e\u3067\u305d\u308c\u306b\u3064\u3044\u3066\u8a73\u3057\u304f\u66f8\u3044\u3066\u3044\u3053\u3046\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n<h4>Spring Security\u306e\u6a29\u9650\u8a2d\u5b9a<\/h4>\n<p>\u307e\u305aSpring Security\u306e\u5927\u307e\u304b\u306a\u5b9f\u88c5\u65b9\u6cd5\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u6bce\u306b\u6a29\u9650\u3092\u6301\u305f\u305b\u3066\u304a\u304d\u305d\u306e\u6a29\u9650\u3092SpringConfig\u30af\u30e9\u30b9\u306b\u30ea\u30af\u30a8\u30b9\u30c8\u6bce\u306b\u8a2d\u5b9a\u3057\u3066\u3044\u304f\u3068\u3044\u3063\u305f\u6d41\u308c\u306a\u306e\u3067\u3059\u304c\u3001\u5b9f\u969b\u306b\u79c1\u304c\u30cf\u30de\u3063\u3066\u3057\u307e\u3063\u305f\u306e\u304c\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u3068\u3053\u308d\u3067\u3059\u3002<\/p>\n<pre class=\"lang:java decode:true\">@Configuration\r\n@EnableWebSecurity\r\npublic class WebSecurityConfig extends WebSecurityConfigurerAdapter\r\n{\r\n\t...\r\n\r\n\t@Override\r\n    protected void configure(HttpSecurity http) throws Exception\r\n\t{\r\n\t\thttp\r\n        .authorizeRequests()\r\n            .antMatchers(\"\/admin_cost\/**\").hasRole(\"Admin\")\r\n            .antMatchers(\"\/employee\/**\").hasRole(\"Admin\")\r\n            .anyRequest().authenticated()\r\n            .and()\r\n        .formLogin()\r\n            .loginPage(\"\/login\")\r\n            .loginProcessingUrl(\"\/sign_in\")\r\n            .usernameParameter(\"username\")\r\n            .passwordParameter(\"password\")\r\n            .successForwardUrl(\"\/login\")\r\n            .failureUrl(\"\/login\/error\")\r\n            .permitAll()\r\n            .and()\r\n        .logout()\r\n            .logoutUrl(\"\/logout\")\r\n            .logoutRequestMatcher(new AntPathRequestMatcher(\"\/logout\"))\r\n            .logoutSuccessUrl(\"\/login?logout\")\r\n            .permitAll();\r\n\t\thttp.csrf().ignoringAntMatchers(\"\/nocsrf\",\"\/admin_cost\");\r\n\t\thttp.csrf().ignoringAntMatchers(\"\/nocsrf\",\"\/logout\");\r\n    \t}\r\n\t...\r\n}<\/pre>\n<p>http.authorizeRequests()\u4ee5\u4e0b\u3067\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u3064\u3044\u3066\u306e\u8a2d\u5b9a\u304c\u66f8\u304b\u308c\u3066\u3044\u3066\u3001hasRole()\u3067\u305d\u306e\u6a29\u9650\u3092\u6301\u3064\u30e6\u30fc\u30b6\u30fc\u3060\u3051\u306b\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u901a\u3059\u3068\u3044\u3046\u51e6\u7406\u3092\u884c\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u79c1\u306f\u6700\u521dhasRole()\u3067\u6e21\u3057\u3066\u3044\u308b\u6a29\u9650\u540d\u3092\u305d\u306e\u307e\u307e\u30e6\u30fc\u30b6\u30fc\u306e\u6a29\u9650\u3068\u3057\u3066\u4f7f\u3063\u3066\u3044\u305f\u306e\u3067\u3059\u304c\u4f55\u6545\u304b\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u901a\u3089\u305a\u60a9\u3093\u3067\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u3053\u3053\u3067\u306f\u9577\u304f\u306a\u3063\u3066\u3057\u307e\u3046\u306e\u3067\u30bd\u30fc\u30b9\u306f\u5272\u611b\u3055\u305b\u3066\u9802\u304d\u307e\u3059\u304c\u539f\u56e0\u306f\u3069\u3046\u3084\u3089hasRole()\u30e1\u30bd\u30c3\u30c9\u304c\u53d7\u3051\u53d6\u3063\u305f\u6587\u5b57\u5217\u306e\u5148\u982d\u306b&#8221;ROLE_&#8221;\u3092\u81ea\u52d5\u7684\u306b\u4ed8\u52a0\u3059\u308b\u3089\u3057\u304f\u3001\u3053\u306e\u4f8b\u3060\u3068\u30e6\u30fc\u30b6\u30fc\u306e\u6a29\u9650\u306b&#8221;ROLE_Admin&#8221;\u3092\u8a2d\u5b9a\u3057\u3066\u3042\u3052\u308b\u3068\u3046\u307e\u304f\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u901a\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>Spring Security\u3092\u3053\u308c\u304b\u3089\u4f7f\u3063\u3066\u307f\u3088\u3046\u3068\u8003\u3048\u3066\u3044\u308b\u65b9\u306f\u826f\u304b\u3063\u305f\u3089\u53c2\u8003\u306b\u3057\u3066\u307f\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7686\u3055\u3093\u3053\u3093\u306b\u3061\u306f\u3001r.matsumoto\u3067\u3059\u3002 \u4eca\u56de\u306e\u8a18\u4e8b\u306fSpring Security\u306b\u3064\u3044\u3066\u3067\u3059\u3002 Spring Security\u3068\u306fSpring\u3067\u30ed\u30b0\u30a4\u30f3\u6a5f\u80fd\u306a\u3069\u3092\u5b9f\u88c5\u3059\u308b\u969b\u306b\u3068\u3066\u3082\u4fbf\u5229\u3067\u3001\u6a29\u9650\u6bce\u306b\u95b2\u89a7\u3067\u304d\u308b\u30da\u30fc&#8230;<a class=\"read-more-link button\" href=\"https:\/\/idealive.jp\/blog\/2019\/09\/06\/spring-security%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6\/\">\u7d9a\u304d\u3092\u8aad\u3080<\/a><\/p>\n","protected":false},"author":10,"featured_media":1663,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[],"class_list":["post-1816","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-spring"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/idealive.jp\/blog\/wp-json\/wp\/v2\/posts\/1816"}],"collection":[{"href":"https:\/\/idealive.jp\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/idealive.jp\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/idealive.jp\/blog\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/idealive.jp\/blog\/wp-json\/wp\/v2\/comments?post=1816"}],"version-history":[{"count":7,"href":"https:\/\/idealive.jp\/blog\/wp-json\/wp\/v2\/posts\/1816\/revisions"}],"predecessor-version":[{"id":1823,"href":"https:\/\/idealive.jp\/blog\/wp-json\/wp\/v2\/posts\/1816\/revisions\/1823"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/idealive.jp\/blog\/wp-json\/wp\/v2\/media\/1663"}],"wp:attachment":[{"href":"https:\/\/idealive.jp\/blog\/wp-json\/wp\/v2\/media?parent=1816"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/idealive.jp\/blog\/wp-json\/wp\/v2\/categories?post=1816"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/idealive.jp\/blog\/wp-json\/wp\/v2\/tags?post=1816"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}