> 项目推荐: Spring Cloud 、Spring Security OAuth2的RBAC权限管理系统 欢迎关注
Lambda DSL概述
Spring Security 5.2 对 Lambda DSL 语法的增强,允许使用lambda配置HttpSecurity、ServerHttpSecurity
重要提醒,之前的配置方法仍然有效。lambda的添加旨在提供更大的灵活性,但是用法是可选的。让我们看一下HttpSecurity的lambda配置与以前的配置样式相比。
HttpSecurity
使用lambdas配置
1@EnableWebSecurity 2public class SecurityConfig extends WebSecurityConfigurerAdapter { 3 4 @Override 5 protected void configure(HttpSecurity http) throws Exception { 6 http 7 .authorizeRequests(authorizeRequests -> 8 authorizeRequests 9 .antMatchers("/blog/**").permitAll() 10 .anyRequest().authenticated() 11 ) 12 .formLogin(formLogin -> 13 formLogin 14 .loginPage("/login") 15 .permitAll() 16 ) 17 .rememberMe(withDefaults()); 18 } 19}
等效配置,不使用lambda
1@EnableWebSecurity 2public class SecurityConfig extends WebSecurityConfigurerAdapter { 3 4 @Override 5 protected void configure(HttpSecurity http) throws Exception { 6 http 7 .authorizeRequests() 8 .antMatchers("/blog/**").permitAll() 9 .anyRequest().authenticated() 10 .and() 11 .formLogin() 12 .loginPage("/login") 13 .permitAll() 14 .and() 15 .rememberMe(); 16 } 17}
默认情况
Lambda DSL配置技巧 比较上面的两个样本时,您会注意到一些关键差异:
在Lambda DSL中,无需使用.and()方法链接配置选项。HttpSecurity调用Lambda方法之后实例自动返回进行进一步的配置。
Spring Security WebFlux
1@EnableWebFluxSecurity 2public class SecurityConfig { 3 4 @Bean 5 SecurityWebFilterChain springSecurityFilterChain(ServerHttpSecurity http) { 6 http 7 .authorizeExchange(exchanges -> 8 exchanges 9 .pathMatchers("/blog/**").permitAll() 10 .anyExchange().authenticated() 11 ) 12 .httpBasic(withDefaults()) //使用提供的默认值启用安全功能 13 .formLogin(formLogin -> 14 formLogin 15 .loginPage("/login") 16 ); 17 return http.build(); 18 } 19}
总结
Spring SecurityLambda DSL 自动缩进使配置更具可读性、不需要使用链接配置选项.and()。 Spring Security DSL与其他Spring DSL(例如Spring Integration和Spring Cloud Gateway)具有类似的配置方法。