Skip to content

Temp Security Documentation

Edward edited this page Mar 20, 2017 · 1 revision

Import:

import org.springframework.security.access.prepost.PreAuthorize;    

Example:

/**
* This is an example of some different kinds of granular restriction for endpoints. You can use the built-in SPEL expressions
* in @PreAuthorize such as 'hasRole()' to determine if a user has access. Remember that the hasRole expression assumes a
* 'ROLE_' prefix on all role names. So 'ADMIN' here is actually stored as 'ROLE_ADMIN' in database!
**/
@RequestMapping(method = RequestMethod.GET)
@PreAuthorize("hasRole('ADMIN')")

Just add @PreAuthorize annotation with the role.

Clone this wiki locally