I tried to use SpEL to pass a userId parameter in an mvcMatchers method to an access() method.
This is based on the tutorial Spring Security 4.1 and Beyond
@Override
protected void configure(HttpSecurity http) throws Exception {
http.csrf()
.disable()
.authorizeRequests()
.mvcMatchers(HttpMethod.GET, "/", "/home").permitAll()
.mvcMatchers("/users/{userId}").access("@authz.check(#userId,principal)")
.mvcMatchers(HttpMethod.POST, SIGN_UP_URL).permitAll()
.mvcMatchers("/admin").denyAll()
.anyRequest().authenticated()
.and()
.logout().permitAll()
.and()
.addFilter(new JWTAuthenticationFilter(authenticationManager()))
.addFilter(new JWTAuthorizationFilter(authenticationManager()));
}
As I understood {userId} in mvcMatchers() should become a variable, which can be passed to access.
This way throws an exception: Cannot resolve variable userId.
I am fairly new to Spring (Boot) and completely new to SpEL.
I hope someone can help me out here.