I'm facing problem with enabling user log-in page - 404 not found.
This is tutorial that I'm using as base of my application security.
That's how configure function looks like:
@Override
protected void configure(HttpSecurity http) throws Exception {
http.cors().and().csrf().disable().authorizeRequests()
.antMatchers(HttpMethod.POST, SIGN_UP_URL).permitAll()
.anyRequest().authenticated()
.and()
.addFilter(new JWTAuthenticationFilter(authenticationManager()))
.addFilter(new JWTAuthorizationFilter(authenticationManager()))
// this disables session creation on Spring Security
.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS);
}
I have tried to simply add here:
.and()
.formLogin()
.loginPage("/login")
.permitAll();
and changing .addFilter to .addFilterAfter() i still get 404.
As you can see in the tutorial, that's how login function is accessed:
curl -i -H "Content-Type: application/json" -X POST -d '{
"username": "admin",
"password": "password"
}' http://localhost:8080/login
Is it even possible to enable built-in login form for this purpose?
And if not, what's the sollution there? Do i have to create /login endpoint in controller, and then POST data to http://localhost:8080/login?
And what about added authenticationFilter. Does changes have to be made there?