Quellcode durchsuchen

Update HttpSecurity Formatting

Josh Cummings vor 3 Jahren
Ursprung
Commit
3a58daf55d
27 geänderte Dateien mit 98 neuen und 100 gelöschten Zeilen
  1. 1 1
      reactive/webflux/java/authentication/username-password/form/src/main/java/example/WebfluxFormSecurityConfiguration.java
  2. 1 1
      reactive/webflux/java/authentication/x509/src/main/java/example/WebfluxX509Application.java
  3. 1 1
      reactive/webflux/java/hello-security-explicit/src/main/java/example/SecurityConfiguration.java
  4. 1 1
      reactive/webflux/java/method/src/main/java/example/SecurityConfiguration.java
  5. 1 1
      reactive/webflux/java/oauth2/resource-server/src/main/java/example/SecurityConfiguration.java
  6. 1 1
      reactive/webflux/java/oauth2/webclient/src/main/java/example/SecurityConfiguration.java
  7. 5 9
      servlet/java-configuration/authentication/preauth/src/main/java/example/SecurityConfiguration.java
  8. 2 2
      servlet/java-configuration/authentication/remember-me/src/main/java/example/SecurityConfiguration.java
  9. 1 1
      servlet/java-configuration/authentication/username-password/form/src/main/java/example/SecurityConfiguration.java
  10. 2 3
      servlet/java-configuration/authentication/x509/src/main/java/example/SecurityConfiguration.java
  11. 5 5
      servlet/java-configuration/hello-mvc-security/src/main/java/example/SecurityConfiguration.java
  12. 5 5
      servlet/java-configuration/hello-security-explicit/src/main/java/example/SecurityConfiguration.java
  13. 1 1
      servlet/java-configuration/max-sessions/src/main/java/example/SecurityConfiguration.java
  14. 20 13
      servlet/spring-boot/java/authentication/username-password/mfa/src/main/java/example/SecurityConfig.java
  15. 1 1
      servlet/spring-boot/java/hello-security-explicit/src/main/java/example/SecurityConfiguration.java
  16. 4 1
      servlet/spring-boot/java/jwt/login/src/main/java/example/RestConfig.java
  17. 3 1
      servlet/spring-boot/java/oauth2/authorization-server/src/main/java/example/OAuth2AuthorizationServerSecurityConfiguration.java
  18. 3 7
      servlet/spring-boot/java/oauth2/login/src/integTest/java/example/OAuth2LoginApplicationTests.java
  19. 4 5
      servlet/spring-boot/java/oauth2/resource-server/hello-security/src/main/java/example/OAuth2ResourceServerSecurityConfiguration.java
  20. 4 8
      servlet/spring-boot/java/oauth2/resource-server/jwe/src/main/java/example/OAuth2ResourceServerSecurityConfiguration.java
  21. 2 2
      servlet/spring-boot/java/oauth2/resource-server/multi-tenancy/src/main/java/example/OAuth2ResourceServerSecurityConfiguration.java
  22. 9 9
      servlet/spring-boot/java/oauth2/resource-server/opaque/src/main/java/example/OAuth2ResourceServerSecurityConfiguration.java
  23. 5 7
      servlet/spring-boot/java/oauth2/resource-server/static/src/main/java/example/OAuth2ResourceServerSecurityConfiguration.java
  24. 3 3
      servlet/spring-boot/java/oauth2/webclient/src/main/java/example/SecurityConfiguration.java
  25. 5 5
      servlet/spring-boot/java/saml2/login-single-tenant/src/main/java/example/SecurityConfiguration.java
  26. 5 5
      servlet/spring-boot/java/saml2/login/src/main/java/example/SecurityConfiguration.java
  27. 3 1
      servlet/spring-boot/java/saml2/refreshable-metadata/src/main/java/example/SecurityConfiguration.java

+ 1 - 1
reactive/webflux/java/authentication/username-password/form/src/main/java/example/WebfluxFormSecurityConfiguration.java

@@ -53,7 +53,7 @@ public class WebfluxFormSecurityConfiguration {
 	SecurityWebFilterChain springSecurityFilterChain(ServerHttpSecurity http) {
 		// @formatter:off
 		http
-			.authorizeExchange((exchanges) -> exchanges
+			.authorizeExchange((authorize) -> authorize
 				.pathMatchers("/login").permitAll()
 				.anyExchange().authenticated()
 			)

+ 1 - 1
reactive/webflux/java/authentication/x509/src/main/java/example/WebfluxX509Application.java

@@ -53,7 +53,7 @@ public class WebfluxX509Application {
 		// @formatter:off
 		http
 			.x509(withDefaults())
-			.authorizeExchange((exchanges) -> exchanges
+			.authorizeExchange((authorize) -> authorize
 				.anyExchange().authenticated()
 			);
 		// @formatter:on

+ 1 - 1
reactive/webflux/java/hello-security-explicit/src/main/java/example/SecurityConfiguration.java

@@ -39,7 +39,7 @@ public class SecurityConfiguration {
 	SecurityWebFilterChain springWebFilterChain(ServerHttpSecurity http) {
 		// @formatter:off
 		http
-			.authorizeExchange((exchanges) -> exchanges
+			.authorizeExchange((authorize) -> authorize
 				.anyExchange().authenticated()
 			)
 			.formLogin(withDefaults());

+ 1 - 1
reactive/webflux/java/method/src/main/java/example/SecurityConfiguration.java

@@ -45,7 +45,7 @@ public class SecurityConfiguration {
 		http
 			// Demonstrate that method security works
 			// Best practice to use both for defense in depth
-			.authorizeExchange((exchanges) -> exchanges
+			.authorizeExchange((authorize) -> authorize
 				.anyExchange().permitAll()
 			)
 			.httpBasic(withDefaults());

+ 1 - 1
reactive/webflux/java/oauth2/resource-server/src/main/java/example/SecurityConfiguration.java

@@ -37,7 +37,7 @@ public class SecurityConfiguration {
 	SecurityWebFilterChain springSecurityFilterChain(ServerHttpSecurity http) {
 		// @formatter:off
 		http
-			.authorizeExchange((exchanges) -> exchanges
+			.authorizeExchange((authorize) -> authorize
 				.pathMatchers(HttpMethod.GET, "/message/**").hasAuthority("SCOPE_message:read")
 				.pathMatchers(HttpMethod.POST, "/message/**").hasAuthority("SCOPE_message:write")
 				.anyExchange().authenticated()

+ 1 - 1
reactive/webflux/java/oauth2/webclient/src/main/java/example/SecurityConfiguration.java

@@ -37,7 +37,7 @@ public class SecurityConfiguration {
 	SecurityWebFilterChain configure(ServerHttpSecurity http) {
 		// @formatter:off
 		http
-			.authorizeExchange((exchanges) -> exchanges
+			.authorizeExchange((authorize) -> authorize
 				.pathMatchers("/", "/public/**").permitAll()
 				.anyExchange().authenticated()
 			)

+ 5 - 9
servlet/java-configuration/authentication/preauth/src/main/java/example/SecurityConfiguration.java

@@ -31,15 +31,11 @@ public class SecurityConfiguration extends WebSecurityConfigurerAdapter {
 	@Override
 	protected void configure(HttpSecurity http) throws Exception {
 		http
-				.authorizeRequests((authorizeRequests) ->
-						authorizeRequests
-								.antMatchers("/login", "/resources/**").permitAll()
-								.anyRequest().authenticated()
-				)
-				.jee((jee) ->
-						jee
-								.mappableRoles("USER", "ADMIN")
-				);
+			.authorizeRequests((authorize) -> authorize
+				.antMatchers("/login", "/resources/**").permitAll()
+				.anyRequest().authenticated()
+			)
+			.jee((jee) -> jee.mappableRoles("USER", "ADMIN"));
 	}
 	// @formatter:on
 

+ 2 - 2
servlet/java-configuration/authentication/remember-me/src/main/java/example/SecurityConfiguration.java

@@ -33,8 +33,8 @@ public class SecurityConfiguration extends WebSecurityConfigurerAdapter {
 	// @formatter:off
 	protected void configure(HttpSecurity http) throws Exception {
 		http
-			.authorizeRequests((requests) -> requests
-					.anyRequest().authenticated()
+			.authorizeRequests((authorize) -> authorize
+				.anyRequest().authenticated()
 			)
 			.formLogin((form) -> form
 				.loginPage("/login")

+ 1 - 1
servlet/java-configuration/authentication/username-password/form/src/main/java/example/SecurityConfiguration.java

@@ -31,7 +31,7 @@ public class SecurityConfiguration extends WebSecurityConfigurerAdapter {
 	// @formatter:off
 	protected void configure(HttpSecurity http) throws Exception {
 		http
-			.authorizeRequests((requests) -> requests
+			.authorizeRequests((authorize) -> authorize
 				.anyRequest().authenticated()
 			)
 			.formLogin((form) -> form

+ 2 - 3
servlet/java-configuration/authentication/x509/src/main/java/example/SecurityConfiguration.java

@@ -33,9 +33,8 @@ public class SecurityConfiguration extends WebSecurityConfigurerAdapter {
 	// @formatter:off
 	protected void configure(HttpSecurity http) throws Exception {
 		http
-			.authorizeRequests((authorizeRequests) ->
-					authorizeRequests
-							.anyRequest().authenticated()
+			.authorizeRequests((authorize) -> authorize
+				.anyRequest().authenticated()
 			)
 			.x509(withDefaults());
 	}

+ 5 - 5
servlet/java-configuration/hello-mvc-security/src/main/java/example/SecurityConfiguration.java

@@ -33,11 +33,11 @@ public class SecurityConfiguration extends WebSecurityConfigurerAdapter {
 	// @formatter:off
 	protected void configure(HttpSecurity http) throws Exception {
 		http
-				.authorizeRequests((requests) -> requests
-						.anyRequest().authenticated()
-				)
-				.httpBasic(withDefaults())
-				.formLogin(withDefaults());
+			.authorizeRequests((authorize) -> authorize
+				.anyRequest().authenticated()
+			)
+			.httpBasic(withDefaults())
+			.formLogin(withDefaults());
 	}
 	// @formatter:on
 

+ 5 - 5
servlet/java-configuration/hello-security-explicit/src/main/java/example/SecurityConfiguration.java

@@ -33,11 +33,11 @@ public class SecurityConfiguration extends WebSecurityConfigurerAdapter {
 	// @formatter:off
 	protected void configure(HttpSecurity http) throws Exception {
 		http
-				.authorizeRequests((requests) -> requests
-						.anyRequest().authenticated()
-				)
-				.httpBasic(withDefaults())
-				.formLogin(withDefaults());
+			.authorizeRequests((authorize) -> authorize
+				.anyRequest().authenticated()
+			)
+			.httpBasic(withDefaults())
+			.formLogin(withDefaults());
 	}
 	// @formatter:on
 

+ 1 - 1
servlet/java-configuration/max-sessions/src/main/java/example/SecurityConfiguration.java

@@ -48,7 +48,7 @@ public class SecurityConfiguration extends WebSecurityConfigurerAdapter {
 	@Override
 	protected void configure(HttpSecurity http) throws Exception {
 		http
-			.authorizeRequests((requests) -> requests
+			.authorizeRequests((authorize) -> authorize
 				.anyRequest().authenticated()
 			)
 			.formLogin(withDefaults())

+ 20 - 13
servlet/spring-boot/java/authentication/username-password/mfa/src/main/java/example/SecurityConfig.java

@@ -44,19 +44,26 @@ public class SecurityConfig {
 	SecurityFilterChain web(HttpSecurity http,
 			AuthorizationManager<RequestAuthorizationContext> mfaAuthorizationManager) throws Exception {
 		MfaAuthenticationHandler mfaAuthenticationHandler = new MfaAuthenticationHandler("/second-factor");
-		http.authorizeHttpRequests((authz) -> authz.mvcMatchers("/second-factor", "/third-factor")
-				.access(mfaAuthorizationManager).anyRequest().authenticated())
-				.formLogin((form) -> form.successHandler(mfaAuthenticationHandler)
-						.failureHandler(mfaAuthenticationHandler))
-				.exceptionHandling((exceptions) -> exceptions
-						.withObjectPostProcessor(new ObjectPostProcessor<ExceptionTranslationFilter>() {
-							@Override
-							public <O extends ExceptionTranslationFilter> O postProcess(O filter) {
-								filter.setAuthenticationTrustResolver(new MfaTrustResolver());
-								return filter;
-							}
-						}));
-
+		// @formatter:off
+		http
+			.authorizeHttpRequests((authorize) -> authorize
+				.mvcMatchers("/second-factor", "/third-factor").access(mfaAuthorizationManager)
+				.anyRequest().authenticated()
+			)
+			.formLogin((form) -> form
+				.successHandler(mfaAuthenticationHandler)
+				.failureHandler(mfaAuthenticationHandler)
+			)
+			.exceptionHandling((exceptions) -> exceptions
+				.withObjectPostProcessor(new ObjectPostProcessor<ExceptionTranslationFilter>() {
+					@Override
+					public <O extends ExceptionTranslationFilter> O postProcess(O filter) {
+						filter.setAuthenticationTrustResolver(new MfaTrustResolver());
+						return filter;
+					}
+				})
+			);
+		// @formatter:on
 		return http.build();
 	}
 

+ 1 - 1
servlet/spring-boot/java/hello-security-explicit/src/main/java/example/SecurityConfiguration.java

@@ -40,7 +40,7 @@ public class SecurityConfiguration extends WebSecurityConfigurerAdapter {
 	// @formatter:off
 	protected void configure(HttpSecurity http) throws Exception {
 		http
-			.authorizeRequests((requests) -> requests
+			.authorizeRequests((authorize) -> authorize
 				.anyRequest().authenticated()
 			)
 			.httpBasic(withDefaults())

+ 4 - 1
servlet/spring-boot/java/jwt/login/src/main/java/example/RestConfig.java

@@ -61,7 +61,10 @@ public class RestConfig extends WebSecurityConfigurerAdapter {
 	@Override
 	protected void configure(HttpSecurity http) throws Exception {
 		// @formatter:off
-		http.authorizeRequests((authz) -> authz.anyRequest().authenticated())
+		http
+			.authorizeRequests((authorize) -> authorize
+				.anyRequest().authenticated()
+			)
 			.csrf((csrf) -> csrf.ignoringAntMatchers("/token"))
 			.httpBasic(Customizer.withDefaults())
 			.oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt)

+ 3 - 1
servlet/spring-boot/java/oauth2/authorization-server/src/main/java/example/OAuth2AuthorizationServerSecurityConfiguration.java

@@ -72,7 +72,9 @@ public class OAuth2AuthorizationServerSecurityConfiguration {
 	public SecurityFilterChain standardSecurityFilterChain(HttpSecurity http) throws Exception {
 		// @formatter:off
 		http
-			.authorizeRequests((requests) -> requests.anyRequest().authenticated())
+			.authorizeRequests((authorize) -> authorize
+				.anyRequest().authenticated()
+			)
 			.formLogin(Customizer.withDefaults());
 		// @formatter:on
 

+ 3 - 7
servlet/spring-boot/java/oauth2/login/src/integTest/java/example/OAuth2LoginApplicationTests.java

@@ -334,16 +334,12 @@ public class OAuth2LoginApplicationTests {
 		@Override
 		protected void configure(HttpSecurity http) throws Exception {
 			http
-				.authorizeRequests((requests) -> requests
+				.authorizeRequests((authorize) -> authorize
 					.anyRequest().authenticated()
 				)
 				.oauth2Login((oauth2) -> oauth2
-					.tokenEndpoint((tokens) -> tokens
-						.accessTokenResponseClient(this.mockAccessTokenResponseClient())
-					)
-					.userInfoEndpoint((userInfo) -> userInfo
-						.userService(this.mockUserService())
-					)
+					.tokenEndpoint((token) -> token.accessTokenResponseClient(mockAccessTokenResponseClient()))
+					.userInfoEndpoint((userInfo) -> userInfo.userService(mockUserService()))
 				);
 		}
 		// @formatter:on

+ 4 - 5
servlet/spring-boot/java/oauth2/resource-server/hello-security/src/main/java/example/OAuth2ResourceServerSecurityConfiguration.java

@@ -40,11 +40,10 @@ public class OAuth2ResourceServerSecurityConfiguration extends WebSecurityConfig
 	protected void configure(HttpSecurity http) throws Exception {
 		// @formatter:off
 		http
-			.authorizeRequests((requests) ->
-				requests
-					.antMatchers(HttpMethod.GET, "/message/**").hasAuthority("SCOPE_message:read")
-					.antMatchers(HttpMethod.POST, "/message/**").hasAuthority("SCOPE_message:write")
-					.anyRequest().authenticated()
+			.authorizeRequests((authorize) -> authorize
+				.antMatchers(HttpMethod.GET, "/message/**").hasAuthority("SCOPE_message:read")
+				.antMatchers(HttpMethod.POST, "/message/**").hasAuthority("SCOPE_message:write")
+				.anyRequest().authenticated()
 			)
 			.oauth2ResourceServer(OAuth2ResourceServerConfigurer::jwt);
 		// @formatter:on

+ 4 - 8
servlet/spring-boot/java/oauth2/resource-server/jwe/src/main/java/example/OAuth2ResourceServerSecurityConfiguration.java

@@ -72,15 +72,11 @@ public class OAuth2ResourceServerSecurityConfiguration extends WebSecurityConfig
 	protected void configure(HttpSecurity http) throws Exception {
 		// @formatter:off
 		http
-			.authorizeRequests((requests) ->
-				requests
-					.antMatchers("/message/**").hasAuthority("SCOPE_message:read")
-					.anyRequest().authenticated()
+			.authorizeRequests((authorize) -> authorize
+				.antMatchers("/message/**").hasAuthority("SCOPE_message:read")
+				.anyRequest().authenticated()
 			)
-			.oauth2ResourceServer((resourceServer) ->
-				resourceServer
-					.jwt(withDefaults())
-			);
+			.oauth2ResourceServer((oauth2) -> oauth2.jwt(withDefaults()));
 		// @formatter:on
 	}
 

+ 2 - 2
servlet/spring-boot/java/oauth2/resource-server/multi-tenancy/src/main/java/example/OAuth2ResourceServerSecurityConfiguration.java

@@ -47,11 +47,11 @@ public class OAuth2ResourceServerSecurityConfiguration {
 			AuthenticationManagerResolver<HttpServletRequest> authenticationManagerResolver) throws Exception {
 		// @formatter:off
 		http
-			.authorizeRequests((requests) -> requests
+			.authorizeRequests((authorize) -> authorize
 				.mvcMatchers("/**/message/**").hasAuthority("SCOPE_message:read")
 				.anyRequest().authenticated()
 			)
-			.oauth2ResourceServer((resourceServer) -> resourceServer
+			.oauth2ResourceServer((oauth2) -> oauth2
 				.authenticationManagerResolver(authenticationManagerResolver)
 			);
 		// @formatter:on

+ 9 - 9
servlet/spring-boot/java/oauth2/resource-server/opaque/src/main/java/example/OAuth2ResourceServerSecurityConfiguration.java

@@ -42,16 +42,16 @@ public class OAuth2ResourceServerSecurityConfiguration extends WebSecurityConfig
 	protected void configure(HttpSecurity http) throws Exception {
 		// @formatter:off
 		http
-			.authorizeRequests((requests) -> requests
-					.mvcMatchers(HttpMethod.GET, "/message/**").hasAuthority("SCOPE_message:read")
-					.mvcMatchers(HttpMethod.POST, "/message/**").hasAuthority("SCOPE_message:write")
-					.anyRequest().authenticated()
+			.authorizeRequests((authorize) -> authorize
+				.mvcMatchers(HttpMethod.GET, "/message/**").hasAuthority("SCOPE_message:read")
+				.mvcMatchers(HttpMethod.POST, "/message/**").hasAuthority("SCOPE_message:write")
+				.anyRequest().authenticated()
 			)
-			.oauth2ResourceServer((resourceServer) -> resourceServer
-					.opaqueToken((opaqueToken) -> opaqueToken
-						.introspectionUri(this.introspectionUri)
-						.introspectionClientCredentials(this.clientId, this.clientSecret)
-					)
+			.oauth2ResourceServer((oauth2) -> oauth2
+				.opaqueToken((opaque) -> opaque
+					.introspectionUri(this.introspectionUri)
+					.introspectionClientCredentials(this.clientId, this.clientSecret)
+				)
 			);
 		// @formatter:on
 	}

+ 5 - 7
servlet/spring-boot/java/oauth2/resource-server/static/src/main/java/example/OAuth2ResourceServerSecurityConfiguration.java

@@ -40,14 +40,12 @@ public class OAuth2ResourceServerSecurityConfiguration extends WebSecurityConfig
 	protected void configure(HttpSecurity http) throws Exception {
 		// @formatter:off
 		http
-			.authorizeRequests((requests) -> requests
-					.mvcMatchers("/message/**").hasAuthority("SCOPE_message:read")
-					.anyRequest().authenticated()
+			.authorizeRequests((authorize) -> authorize
+				.mvcMatchers("/message/**").hasAuthority("SCOPE_message:read")
+				.anyRequest().authenticated()
 			)
-			.oauth2ResourceServer((resourceServer) -> resourceServer
-					.jwt((jwt) -> jwt
-							.decoder(jwtDecoder())
-					)
+			.oauth2ResourceServer((oauth2) -> oauth2
+				.jwt((jwt) -> jwt.decoder(jwtDecoder()))
 			);
 		// @formatter:on
 	}

+ 3 - 3
servlet/spring-boot/java/oauth2/webclient/src/main/java/example/SecurityConfiguration.java

@@ -38,9 +38,9 @@ public class SecurityConfiguration extends WebSecurityConfigurerAdapter {
 	protected void configure(HttpSecurity http) throws Exception {
 		// @formatter:off
 		http
-			.authorizeRequests((requests) -> requests
-					.mvcMatchers("/", "/public/**").permitAll()
-					.anyRequest().authenticated()
+			.authorizeRequests((authorize) -> authorize
+				.mvcMatchers("/", "/public/**").permitAll()
+				.anyRequest().authenticated()
 			)
 			.formLogin(withDefaults())
 			.oauth2Login(withDefaults())

+ 5 - 5
servlet/spring-boot/java/saml2/login-single-tenant/src/main/java/example/SecurityConfiguration.java

@@ -36,11 +36,11 @@ public class SecurityConfiguration {
 	SecurityFilterChain app(HttpSecurity http) throws Exception {
 		// @formatter:off
 		http
-				.authorizeRequests((authorize) -> authorize
-					.anyRequest().authenticated()
-				)
-				.saml2Login((saml2) -> saml2.loginProcessingUrl("/login/saml2/sso"))
-				.saml2Logout(Customizer.withDefaults());
+			.authorizeRequests((authorize) -> authorize
+				.anyRequest().authenticated()
+			)
+			.saml2Login((saml2) -> saml2.loginProcessingUrl("/login/saml2/sso"))
+			.saml2Logout(Customizer.withDefaults());
 		// @formatter:on
 
 		return http.build();

+ 5 - 5
servlet/spring-boot/java/saml2/login/src/main/java/example/SecurityConfiguration.java

@@ -35,11 +35,11 @@ public class SecurityConfiguration {
 	SecurityFilterChain app(HttpSecurity http) throws Exception {
 		// @formatter:off
 		http
-				.authorizeRequests((authorize) -> authorize
-					.anyRequest().authenticated()
-				)
-				.saml2Login(Customizer.withDefaults())
-				.saml2Logout(Customizer.withDefaults());
+			.authorizeRequests((authorize) -> authorize
+				.anyRequest().authenticated()
+			)
+			.saml2Login(Customizer.withDefaults())
+			.saml2Logout(Customizer.withDefaults());
 		// @formatter:on
 
 		return http.build();

+ 3 - 1
servlet/spring-boot/java/saml2/refreshable-metadata/src/main/java/example/SecurityConfiguration.java

@@ -30,7 +30,9 @@ public class SecurityConfiguration {
 	SecurityFilterChain app(HttpSecurity http) throws Exception {
 		// @formatter:off
 		http
-			.authorizeRequests((authorize) -> authorize.anyRequest().authenticated())
+			.authorizeRequests((authorize) -> authorize
+				.anyRequest().authenticated()
+			)
 			.saml2Login(withDefaults())
 			.saml2Logout(withDefaults());
 		// @formatter:on