Require admin role for admin endpoints
This commit is contained in:
@@ -23,7 +23,7 @@ public class SecurityConfig {
|
|||||||
.authorizeHttpRequests(auth -> auth
|
.authorizeHttpRequests(auth -> auth
|
||||||
.requestMatchers("/auth/**").permitAll()
|
.requestMatchers("/auth/**").permitAll()
|
||||||
.requestMatchers("/debug/**").permitAll()
|
.requestMatchers("/debug/**").permitAll()
|
||||||
.requestMatchers("/admin/**").permitAll()
|
.requestMatchers("/admin/**").hasRole("ADMIN")
|
||||||
.requestMatchers("/api/backend/**").authenticated()
|
.requestMatchers("/api/backend/**").authenticated()
|
||||||
.anyRequest().permitAll()
|
.anyRequest().permitAll()
|
||||||
)
|
)
|
||||||
|
|||||||
Reference in New Issue
Block a user