Class AuthorizeHttpRequestsConfigurer

java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.AuthorizeHttpRequestsConfigurer

public final class AuthorizeHttpRequestsConfigurer extends SecurityConfigurer

The authorization rules of a chain: which requests need what.

http.authorizeHttpRequests(auth -> auth
        .requestMatchers("/", "/css/**").permitAll()
        .requestMatchers("/admin/**").hasRole("ADMIN")
        .requestMatchers(AntPathRequestMatcher.antMatcher("DELETE", "/api/**"))
                .hasAuthority("api:delete")
        .anyRequest().authenticated());

The rules are asked in the order they are written and the first that matches decides. A request no rule matches is denied.