Commit db3b4cf0 authored by François-Xavier Lebastard's avatar François-Xavier Lebastard
Browse files

Merge branch 'feature/UNOTOPLYS-26_security' into 'develop'

UNOTOPLYS-26: Security

See merge request !18
parents 4ba7ac0c 129496a4
......@@ -77,14 +77,15 @@ public class SecurityConfiguration extends WebSecurityConfigurerAdapter {
.and()
.authorizeRequests()
.antMatchers("/api/authenticate").permitAll()
.antMatchers("/api/register").permitAll()
.antMatchers("/api/activate").permitAll()
.antMatchers("/api/account/reset-password/init").permitAll()
.antMatchers("/api/account/reset-password/finish").permitAll()
.antMatchers("/api/**").permitAll()
.antMatchers("/api/register").authenticated()
.antMatchers("/api/activate").authenticated()
.antMatchers("/api/account/reset-password/init").authenticated()
.antMatchers("/api/account/reset-password/finish").authenticated()
.antMatchers("/api/form/**").permitAll()
.antMatchers("/api/**").authenticated()
.antMatchers("/management/health").permitAll()
.antMatchers("/management/info").permitAll()
.antMatchers("/management/prometheus").permitAll()
.antMatchers("/management/info").authenticated()
.antMatchers("/management/prometheus").authenticated()
.antMatchers("/management/**").hasAuthority(AuthoritiesConstants.ADMIN)
.and()
.httpBasic()
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment