Interface SecurityFilterChain
- All Known Implementing Classes:
DefaultSecurityFilterChain
public interface SecurityFilterChain
The filters that guard some of a server's requests. An application declares
one as a bean, built from the HttpSecurity it is handed:
@Configuration
public class SecurityConfig {
@Bean
@Order(1)
SecurityFilterChain api(HttpSecurity http) {
http.securityMatcher("/api/**")
.authorizeHttpRequests(auth -> auth.anyRequest().hasRole("API"))
.httpBasic(Customizer.withDefaults())
.csrf(csrf -> csrf.disable());
return http.build();
}
@Bean
SecurityFilterChain pages(HttpSecurity http) {
http.authorizeHttpRequests(auth -> auth
.requestMatchers("/", "/css/**").permitAll()
.anyRequest().authenticated())
.formLogin(Customizer.withDefaults());
return http.build();
}
}
A request is put to the chains in @Order, and the first whose
matches(HttpServer.Request) answers true is the only one that sees it. A request no chain
matches is not guarded at all. The server's own endpoints -- management, MCP,
the telemetry relay -- are not put to any chain: they keep their own tokens.
-
Method Summary
Modifier and TypeMethodDescriptionThe filters, in the order they run.booleanmatches(HttpServer.Request request) Whether this chain guardsrequest.
-
Method Details
-
matches
Whether this chain guardsrequest. -
getFilters
List<SecurityFilter> getFilters()The filters, in the order they run.
-