Update SecurityConfig to require authentication for /api/app/** endpoints

This commit is contained in:
Vincent Guillet
2025-12-03 22:47:14 +01:00
parent 60593f6c11
commit ff8536b448

View File

@@ -46,7 +46,7 @@ public class SecurityConfig {
.requestMatchers(HttpMethod.OPTIONS, "/**").permitAll() // autoriser les preflight .requestMatchers(HttpMethod.OPTIONS, "/**").permitAll() // autoriser les preflight
.requestMatchers("/api/auth/**").permitAll() .requestMatchers("/api/auth/**").permitAll()
.requestMatchers("/api/users/**").authenticated() .requestMatchers("/api/users/**").authenticated()
.requestMatchers("/api/app/**").permitAll() .requestMatchers("/api/app/**").authenticated()
.anyRequest().permitAll() .anyRequest().permitAll()
) )
.sessionManagement(session -> session.sessionCreationPolicy(SessionCreationPolicy.STATELESS)) .sessionManagement(session -> session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))