antMatchers hasRole throwing 403 access denied using spring cloud gateway

Viewed 36

Initially I'm using zuul for gateway operations, now migrated to spring cloud gateway. After migrating getting access denied error with the below code.

@Bean
public SecurityWebFilterChain springSecurityFilterChain(ServerHttpSecurity http) {
    DelegatingServerLogoutHandler logoutHandler = new DelegatingServerLogoutHandler(
            new CsrfServerLogoutHandler(csrfTokenRepository()),
            new SecurityContextServerLogoutHandler(),
            new WebSessionServerLogoutHandler(),
            new HeaderWriterServerLogoutHandler(new ClearSiteDataServerHttpHeadersWriter(ClearSiteDataServerHttpHeadersWriter.Directive.ALL))
    );

    http
            .oauth2Login().and()
            .authorizeExchange()
            .pathMatchers("/somePath/**").hasRole("SuperAdmin")
            .pathMatchers("/somePathSquare/**").hasRole("SuperAdmin")
            .pathMatchers("/somePathCube/**").hasRole("SuperAdmin")
            .csrf().requireCsrfProtectionMatcher(createDefaultRequestMacher()).and()

            .csrf(csrf -> csrf.csrfTokenRepository(csrfTokenRepository())) 
            .addFilterAfter(csrfFilter,  SecurityWebFiltersOrder.CSRF) 
            .logout()
            .logoutHandler(logoutHandler)
            .logoutSuccessHandler(logoutSuccessHandler())
            .and()
            .authorizeExchange().anyExchange().permitAll()
    ;

    return http.build();
}

Also tried changing the hasRole("SuperAdmin") to hasRole("ROLE_SuperAdmin") & hasAuthority("SuperAdmin") & hasAuthority("ROLE_SuperAdmin"). Getting same error access denied in all the cases.

Can anyone share your thoughts and workarounds on how to fix this?

0 Answers
Related