Skip to content
Toggle navigation
P
Projects
G
Groups
S
Snippets
Help
Antonio Rueda
/
reserva-hoteles
This project
Loading...
Sign in
Toggle navigation
Go to a project
Project
Repository
Issues
0
Merge Requests
0
Pipelines
Wiki
Snippets
Settings
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Commit
155d77d1
authored
Dec 11, 2024
by
Antonio Rueda
Browse files
Options
_('Browse Files')
Download
Email Patches
Plain Diff
Corregidos algunos errores en la protección de los paths
parent
d1d9bbc6
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
3 additions
and
3 deletions
src/main/java/es/ujaen/dae/reservahoteles/seguridad/ServicioSeguridad.java
src/main/java/es/ujaen/dae/reservahoteles/seguridad/ServicioSeguridad.java
View file @
155d77d1
...
...
@@ -29,10 +29,10 @@ public class ServicioSeguridad {
.
httpBasic
(
httpBasic
->
httpBasic
.
realmName
(
"reservas"
))
.
authorizeHttpRequests
(
request
->
request
.
requestMatchers
(
HttpMethod
.
GET
,
"/reservas/usuarios/{email}"
)
.
access
(
new
WebExpressionAuthorizationManager
(
"hasRole('DIRECCION') or (hasRole('
USUARIO
') and #email == principal.username)"
))
.
access
(
new
WebExpressionAuthorizationManager
(
"hasRole('DIRECCION') or (hasRole('
CLIENTE
') and #email == principal.username)"
))
.
requestMatchers
(
HttpMethod
.
POST
,
"/reservas/hoteles"
).
hasRole
(
"DIRECCION"
)
.
requestMatchers
(
HttpMethod
.
POST
,
"/reservas/hoteles/{id}/reservas"
).
hasAnyRole
(
"DIRECCION"
,
"
USUARIO
"
)
.
requestMatchers
(
HttpMethod
.
POST
,
"/reservas/**"
).
permitAll
()
.
requestMatchers
(
HttpMethod
.
POST
,
"/reservas/hoteles/{id}/reservas"
).
hasAnyRole
(
"DIRECCION"
,
"
CLIENTE
"
)
.
requestMatchers
(
"/reservas/**"
).
permitAll
()
)
.
build
();
}
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment