|
@@ -18,18 +18,24 @@
|
|
-->
|
|
-->
|
|
</global-method-security>
|
|
</global-method-security>
|
|
|
|
|
|
- <http auto-config="true">
|
|
|
|
- <intercept-url pattern="/secure/extreme/**" access="ROLE_SUPERVISOR"/>
|
|
|
|
- <intercept-url pattern="/secure/**" access="IS_AUTHENTICATED_REMEMBERED" />
|
|
|
|
|
|
+ <http>
|
|
|
|
+ <intercept-url pattern="/secure/extreme/**" access="ROLE_SUPERVISOR" requires-channel="https"/>
|
|
|
|
+ <intercept-url pattern="/secure/**" access="IS_AUTHENTICATED_REMEMBERED" requires-channel="https"/>
|
|
<!-- Disable web URI authorization, as we're using <global-method-security> and have @Secured the services layer instead
|
|
<!-- Disable web URI authorization, as we're using <global-method-security> and have @Secured the services layer instead
|
|
<intercept-url pattern="/listAccounts.html" access="IS_AUTHENTICATED_REMEMBERED" />
|
|
<intercept-url pattern="/listAccounts.html" access="IS_AUTHENTICATED_REMEMBERED" />
|
|
<intercept-url pattern="/post.html" access="ROLE_TELLER" />
|
|
<intercept-url pattern="/post.html" access="ROLE_TELLER" />
|
|
-->
|
|
-->
|
|
<intercept-url pattern="/**" access="IS_AUTHENTICATED_ANONYMOUSLY" />
|
|
<intercept-url pattern="/**" access="IS_AUTHENTICATED_ANONYMOUSLY" />
|
|
<!--
|
|
<!--
|
|
- Uncomment to enable X509 client authentication support
|
|
|
|
- <x509 />
|
|
|
|
--->
|
|
|
|
|
|
+ Uncomment to enable X509 client authentication support -->
|
|
|
|
+ <x509 />
|
|
|
|
+ <anonymous />
|
|
|
|
+ <logout />
|
|
|
|
+<!--
|
|
|
|
+ <port-mappings>
|
|
|
|
+ <port-mapping http="8080" https="8443"/>
|
|
|
|
+ </port-mappings>
|
|
|
|
+ -->
|
|
|
|
|
|
<!-- All of this is unnecessary if auto-config="true"
|
|
<!-- All of this is unnecessary if auto-config="true"
|
|
<form-login />
|
|
<form-login />
|