Require admin role for admin endpoints
This commit is contained in:
@@ -23,7 +23,7 @@ public class SecurityConfig {
|
||||
.authorizeHttpRequests(auth -> auth
|
||||
.requestMatchers("/auth/**").permitAll()
|
||||
.requestMatchers("/debug/**").permitAll()
|
||||
.requestMatchers("/admin/**").permitAll()
|
||||
.requestMatchers("/admin/**").hasRole("ADMIN")
|
||||
.requestMatchers("/api/backend/**").authenticated()
|
||||
.anyRequest().permitAll()
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user