Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.
public final class HttpSecurity
- Object
- HttpSecurity
Builds one SecurityFilterChain. A @Bean method that returns a chain
declares a parameter of this type and is handed a new one:
@Bean
SecurityFilterChain web(HttpSecurity http) {
http.authorizeHttpRequests(auth -> auth
.requestMatchers("/public/**").permitAll()
.anyRequest().authenticated())
.formLogin(Customizer.withDefaults())
.httpBasic(Customizer.withDefaults());
return http.build();
}
Out of the box a chain guards every request, writes the security headers, keeps who is signed in in the HTTP session, protects that session against CSRF and gives a request nobody signed in for an anonymous authentication. It has no way of signing in and no authorization rules until it is given them.
Everything else is there only when the chain asks for it, and a server
carries the code of only what its chains ask for: formLogin – which
brings sign-out and the memory of where a request was going with it –
httpBasic, oauth2Login, oauth2ResourceServer,
authorizationServer, apiKey, rateLimit, rememberMe, mfa,
webAuthn, logout and requestCache. A server that only
verifies tokens has no login page, no password hashing and no user store in
it. This makes two departures from Spring Security. The first: a chain
without formLogin has no POST /logout until it calls logout.
The second: a chain whose session policy is
SessionCreationPolicy.STATELESS keeps nothing a forged request could
ride on, and has no CSRF filter unless csrf asks for one. One that takes
HTTP Basic credentials from browsers should ask.
Users come from the application’s beans: a
UserDetailsService and, if there is one, a
PasswordEncoder and a
UserDetailsPasswordService
– or AuthenticationProvider beans, or an AuthenticationManager bean. A
chain can also be told directly, with userDetailsService,
authenticationProvider or authenticationManager.
Fields
public static final String USER_NAME = "cn1.security.user.name" | The name of the one user a server with no user store has, when USER_PASSWORD is set; user unless set. |
public static final String USER_PASSWORD = "cn1.security.user.password" | That user’s password, as it would be stored; one written without an {id} is taken as {noop}, which verifies on a development profile only. |
public static final String USER_ROLES = "cn1.security.user.roles" | That user’s roles, separated by commas. |
public static final String PASSWORD_MAX_CONCURRENT = "cn1.security.password.maxConcurrent" | The most passwords checked at one time; a sign-in beyond that is answered 503 at once. |
Methods
Inherited methods
Field details
USER_NAME
public static final String USER_NAME = "cn1.security.user.name"USER_PASSWORD is set; user unless set.USER_PASSWORD
public static final String USER_PASSWORD = "cn1.security.user.password"{id} is taken as {noop}, which verifies on a development profile only.USER_ROLES
public static final String USER_ROLES = "cn1.security.user.roles"PASSWORD_MAX_CONCURRENT
public static final String PASSWORD_MAX_CONCURRENT = "cn1.security.password.maxConcurrent"DaoAuthenticationProvider.setMaxConcurrentPasswordChecks.Method details
securityMatcher
public HttpSecurity securityMatcher(String... patterns)AntPathRequestMatcher. A chain without one guards every
request, and must then be the last in @Order.securityMatcher
public HttpSecurity securityMatcher(RequestMatcher requestMatcher)requestMatcher matches.authorizeHttpRequests
public HttpSecurity authorizeHttpRequests(Customizer<AuthorizeHttpRequestsConfigurer.AuthorizationManagerRequestMatcherRegistry> customizer)AuthorizeHttpRequestsConfigurer.formLogin
public HttpSecurity formLogin(Customizer<FormLoginConfigurer> customizer)FormLoginConfigurer. Brings sign-out
(logout) and the memory of where a request was going
(requestCache) with it, unless the chain has turned those off.httpBasic
public HttpSecurity httpBasic(Customizer<HttpBasicConfigurer> customizer)HttpBasicConfigurer.oauth2ResourceServer
public HttpSecurity oauth2ResourceServer(Customizer<OAuth2ResourceServerConfigurer> customizer)OAuth2ResourceServerConfigurer.oauth2Login
public HttpSecurity oauth2Login(Customizer<OAuth2LoginConfigurer> customizer)OAuth2LoginConfigurer. Brings sign-out and the memory of
where a request was going with it, as formLogin does.authorizationServer
public HttpSecurity authorizationServer(Customizer<AuthorizationServerConfigurer> customizer)AuthorizationServerConfigurer. How a user signs in to it is whatever
else the chain declares.rememberMe
public HttpSecurity rememberMe(Customizer<RememberMeConfigurer> customizer)RememberMeConfigurer.
Brings sign-out with it, as formLogin does.mfa
public HttpSecurity mfa(Customizer<MfaConfigurer> customizer)MfaConfigurer. Brings sign-out with
it, as formLogin does.webAuthn
public HttpSecurity webAuthn(Customizer<WebAuthnConfigurer> customizer)WebAuthnConfigurer. Brings sign-out with it, as
formLogin does.apiKey
public HttpSecurity apiKey(Customizer<ApiKeyConfigurer> customizer)ApiKeyConfigurer.rateLimit
public HttpSecurity rateLimit(RequestMatcher matcher, RateLimitKeyResolver keyResolver, RateLimiter limiter)Limits how often the requests matcher matches may be made under one
key, and answers 429 with Retry-After beyond that.
http.rateLimit(AntPathRequestMatcher.antMatcher("/login"),
RateLimitKeys.clientAddress(), new InMemoryRateLimiter(5, 60));
http.rateLimit("/api/**", RateLimitKeys.firstOf(RateLimitKeys.apiKeyId(),
RateLimitKeys.principal()), new InMemoryRateLimiter(600, 60));
A limit keyed by something the request has from the start – its client’s address, its session – is applied before anything else in the chain. One keyed by who signed in is applied once that is known, and does not apply to a request nobody signed in for. Rules are consulted in the order given, and a request counts against every rule that matches it up to the one that refuses it.
Two rules given the same limiter share its counts for any key they have in common; give each its own unless that is what is meant.
Parameters
matcherRequestMatcher- Not documented.
keyResolverRateLimitKeyResolver- which key a request counts under; see
RateLimitKeys limiterRateLimiter- what counts; null for the application’s one
RateLimiterbean.InMemoryRateLimitercounts in this process alone.
rateLimit
public HttpSecurity rateLimit(String pattern, RateLimitKeyResolver keyResolver, RateLimiter limiter)rateLimit(RequestMatcher, RateLimitKeyResolver, RateLimiter) for the
requests whose path matches an Ant pattern.logout
public HttpSecurity logout(Customizer<LogoutConfigurer> customizer)LogoutConfigurer. A chain with formLogin has it
already; any other chain has none until it calls this.csrf
public HttpSecurity csrf(Customizer<CsrfConfigurer> customizer)CsrfConfigurer. On for every chain that keeps a
session; a SessionCreationPolicy.STATELESS chain has it only when it
calls this.sessionManagement
public HttpSecurity sessionManagement(Customizer<SessionManagementConfigurer> customizer)SessionManagementConfigurer.headers
public HttpSecurity headers(Customizer<HeadersConfigurer> customizer)HeadersConfigurer.requestCache
public HttpSecurity requestCache(Customizer<RequestCacheConfigurer> customizer)RequestCacheConfigurer.exceptionHandling
public HttpSecurity exceptionHandling(Customizer<ExceptionHandlingConfigurer> customizer)ExceptionHandlingConfigurer.securityContext
public HttpSecurity securityContext(Customizer<SecurityContextConfigurer> customizer)SecurityContextConfigurer.anonymous
public HttpSecurity anonymous(Customizer<AnonymousConfigurer> customizer)AnonymousConfigurer.with
public <C extends SecurityConfigurer> HttpSecurity with(C configurer, Customizer<C> customizer)customizer set it up.getConfigurer
public <C extends SecurityConfigurer> C getConfigurer(Class<C> type)authenticationManager
public HttpSecurity authenticationManager(AuthenticationManager authenticationManager)AuthenticationManager the chain’s sign-in filters use, in place of
what the application’s beans would give.authenticationProvider
public HttpSecurity authenticationProvider(AuthenticationProvider authenticationProvider)userDetailsService
public HttpSecurity userDetailsService(UserDetailsService userDetailsService)UserDetailsService bean.addFilterBefore
public HttpSecurity addFilterBefore(SecurityFilter filter, Class<? extends SecurityFilter> beforeFilter)filter just before the filter of class beforeFilter.addFilterAfter
public HttpSecurity addFilterAfter(SecurityFilter filter, Class<? extends SecurityFilter> afterFilter)filter just after the filter of class afterFilter.addFilterAt
public HttpSecurity addFilterAt(SecurityFilter filter, Class<? extends SecurityFilter> atFilter)filter at the place of the filter of class atFilter, beside it
rather than instead of it: which of the two runs first is not defined.getConfig
public Config getConfig()build
public DefaultSecurityFilterChain build()HttpSecurity builds one chain, once.authenticationCodec
public HttpSecurity authenticationCodec(AuthenticationCodec codec)Authentication in the session as itself; see
AuthenticationCodec. Called before the chain is built, or from a
configurer’s init: the ways of signing in that have a kind of their
own – oauth2Login, webAuthn – each call it for theirs.