由于csrf失败,Swagger没有显示控制器端点
在我的应用程序中,我添加了swagger,但它没有显示控制器apis。当我签入开发人员控制台时,它显示localhost:9000/和localhost:9000/csrf apis失败了。
下面是我的安全配置:
代码语言:javascript运行复制 @Override
protected void configure(AuthenticationManagerBuilder auth) {
auth.authenticationProvider(activeDirectoryLdapAuthenticationProvider());
}
@Bean
public AuthenticationProvider activeDirectoryLdapAuthenticationProvider() {
ActiveDirectoryLdapAuthenticationProvider authenticationProvider =
new ActiveDirectoryLdapAuthenticationProvider(ldapDomain, ldapUrl,ldapBase);
authenticationProvider.setConvertSubErrorCodesToExceptions(true);
authenticationProvider.setUseAuthenticationRequestCredentials(true);
authenticationProvider.setSearchFilter("(sAMAccountName={1})");
return authenticationProvider;
}
@Bean
@Override
public AuthenticationManager authenticationManagerBean() throws Exception {
return super.authenticationManagerBean();
}
@Override
protected void configure(HttpSecurity httpSecurity) throws Exception {
httpSecurity
.csrf()
.disable()
.exceptionHandling().authenticationEntryPoint(jwtUnAuthorizedResponseAuthenticationEntryPoint).and()
.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS).and()
.authorizeRequests()
.antMatchers("/v2/api-docs",
"/configuration/ui",
"/swagger-resources/**",
"/configuration/security",
"/swagger-ui.html",
"/webjars/**").permitAll()
.anyRequest().authenticated();
httpSecurity
.addFilterBefore(jwtAuthenticationTokenFilter, UsernamePasswordAuthenticationFilter.class);
httpSecurity
.headers()
.frameOptions().sameOrigin() //H2 Console Needs this setting
.cacheControl(); //disable caching
}
@Override
public void configure(WebSecurity webSecurity) throws Exception {
webSecurity
.ignoring()
.antMatchers(
HttpMethod.POST,
authenticationPath
)
.antMatchers(HttpMethod.OPTIONS, "/**")
.and()
.ignoring()
.antMatchers(
HttpMethod.GET,
"/" //Other Stuff You want to Ignore
)
.and()
.ignoring()
.antMatchers("/h2-console/**/**");//Should not be in Production!
}SwaggerConfig:
代码语言:javascript运行复制public static final String DEFAULT_INCLUDE_PATTERN = "/deployer/*.*";
@Bean
public Docket productApi() {
return new Docket(DocumentationType.SWAGGER_2).select()
.apis(RequestHandlerSelectors.basePackage("com.org.deployer.controller"))
.paths(PathSelectors.regex(DEFAULT_INCLUDE_PATTERN)).build().apiInfo(metaData())
.securityContexts(Lists.newArrayList(securityContext()))
.securitySchemes(Lists.newArrayList(apiKey()))
.useDefaultResponseMessages(false);
}
private ApiKey apiKey() {
return new ApiKey("JWT", AUTHORIZATION_HEADER, "header");
}
private SecurityContext securityContext() {
return SecurityContext.builder()
.securityReferences(defaultAuth())
.forPaths(PathSelectors.regex(DEFAULT_INCLUDE_PATTERN))
.build();
}
List
AuthorizationScope authorizationScope
= new AuthorizationScope("global", "accessEverything");
AuthorizationScope[] authorizationScopes = new AuthorizationScope[1];
authorizationScopes[0] = authorizationScope;
return Lists.newArrayList(
new SecurityReference("JWT", authorizationScopes));
}响应/v2/api-docs:
代码语言:javascript运行复制{
"swagger": "2.0",
"info": {
"description": "deployment Tool ",
"version": "1.0",
"title": " api",
"termsOfService": "Terms of service",
"contact": {
"name": "Support Team"
},
"license": {
}
},
"host": "localhost:9000",
"basePath": "/",
"securityDefinitions": {
"JWT": {
"type": "apiKey",
"name": "Authorization",
"in": "header"
}
}
}主计长:
代码语言:javascript运行复制package com.org.deployer.controller;
@RestController
@CrossOrigin(origins = "http://localhost:4200")
@Api(value = "package operations", description = "Operations pertaining to Package Schedule")
public class PackageScheduleController {
private static final Logger logger = LoggerFactory.getLogger(PackageScheduleController.class);
@Autowired
PackageScheduleService packageScheduleService;
@PostMapping("/schedule")
@ApiOperation(value = "This method is used to get the clients.")
public PackageScheduleResponse schedule(@RequestBody PackageScheduleRequest packageScheduleRequest){
try{
logger.info("Schedule Request received for {}",packageScheduleRequest.getName());
System.out.println(packageScheduleRequest.getScheduleTime().toLocalTime());
return packageScheduleService.schedule(packageScheduleRequest);
}
catch(Exception e){
logger.error("Exception occured",e);
throw new RuntimeException("Some Error Occured");
}
}
@GetMapping("/view-schedule")
public List
try{
logger.info("Request received for fetching upcoming schedule jobs");
return packageScheduleService.fetchAllScheudules();
}
catch(Exception e){
logger.error("Exception occured",e);
throw new RuntimeException("Some Error Occured");
}
}
}通过看到,我可以理解这是相关的csrf配置,但不确定如何解决它。