What I want is a way to configure antMatchers in HttpSecurity via external file in easy-to-understand format (so it can be edited by someone who knows nothing about app). Only the matchers (!) part.
@Override
protected void configure(HttpSecurity http) throws Exception {
http.authorizeRequests()
.antMatchers(HttpMethod.POST, "/some/url").hasRole("ROLE01")
.antMatchers(HttpMethod.GET, "/some/other/url").hasRole("ROLE02")
.antMatchers("/some/public-urls/*").permitAll()
.anyRequest().denyAll();
}
I know that you can set up a bean via xml, but this is not the most intuitive format for the unfamiliar person.
The only option I see now is to make my own file in custom format, read it on startup and use it to configure HttpSecurity. But this turns out to be a reinvention of the wheel.
So, maybe I'm missing something and there is some other way available out of the box or de facto some standard to solve this problem?