-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathResourceController.java
More file actions
65 lines (54 loc) · 1.95 KB
/
Copy pathResourceController.java
File metadata and controls
65 lines (54 loc) · 1.95 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
package com.github.spring.resource.controller;
import org.springframework.security.access.prepost.PreAuthorize;
import org.springframework.security.core.Authentication;
import org.springframework.security.core.context.SecurityContextHolder;
import org.springframework.security.oauth2.provider.authentication.OAuth2AuthenticationDetails;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RequestMethod;
import org.springframework.web.bind.annotation.RestController;
import com.github.spring.common.UserInfo;
@RestController
@RequestMapping(value = "/api")
public class ResourceController {
/**
* Endpoints accessible to user with Role ADMIN
*
* @return
*/
@PreAuthorize("hasRole('ADMIN')")
@RequestMapping(value = "/admin", method = RequestMethod.GET)
public String getAdmin() {
return "get admin success";
}
/**
* Endpoints accessible to user with Role USER
*
* @return
*/
@PreAuthorize("hasRole('USER')")
@RequestMapping(value = "/user", method = RequestMethod.GET)
public String getUser() {
return "get user success";
}
/**
* Endpoints accessible to user with any Role
*
* @return
*/
@RequestMapping(value = "/me", method = RequestMethod.GET)
public UserInfo me() {
Authentication authentication = SecurityContextHolder.getContext().getAuthentication();
OAuth2AuthenticationDetails detail = (OAuth2AuthenticationDetails) authentication.getDetails();
return (UserInfo) detail.getDecodedDetails();
}
/**
* Endpoints accessible to user with authorities "ROLE_ADMIN"
*
* @return
*/
@PreAuthorize("hasAuthority('ROLE_ADMIN')")
@RequestMapping(value = "/user", method = RequestMethod.DELETE)
public String deleteUser() {
return "delete user success";
}
}