-
Notifications
You must be signed in to change notification settings - Fork 0
/
fixture-security.xml
43 lines (36 loc) · 2.29 KB
/
fixture-security.xml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
<?xml version="1.0" encoding="UTF-8"?>
<beans xmlns="http://www.springframework.org/schema/beans"
xmlns:context="http://www.springframework.org/schema/context"
xmlns:security="http://www.springframework.org/schema/security"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd
http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security.xsd
http://www.springframework.org/schema/context http://www.springframework.org/schema/context/spring-context.xsd">
<context:component-scan base-package="io.fixture.security"/>
<bean id="passwordEncoder" class="org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder"/>
<security:authentication-manager id="authenticationManager">
<security:authentication-provider user-service-ref="userDetailsManagerImpl">
<security:password-encoder ref="passwordEncoder"/>
</security:authentication-provider>
</security:authentication-manager>
<security:global-method-security authentication-manager-ref="authenticationManager"
secured-annotations="enabled"/>
<security:http authentication-manager-ref="authenticationManager"
use-expressions="true">
<security:intercept-url pattern="/secure/**"
access="isAuthenticated()"/>
<security:intercept-url pattern="/administration/**"
access="hasRole('administrator')"/>
<security:access-denied-handler error-page="/access-denied" />
<security:anonymous/>
<security:form-login login-page="/login"
login-processing-url="/login/authenticate"/>
<security:remember-me user-service-ref="userDetailsManagerImpl"
key="fixture-dot-io"
token-repository-ref="persistentTokenRepositoryImpl"/>
<security:logout logout-url="/logout"/>
<security:session-management>
<security:concurrency-control max-sessions="1"/>
</security:session-management>
</security:http>
</beans>