Initially I'm using zuul for gateway operations, now migrated to spring cloud gateway. After migrating getting access denied error with the below code.
@Bean
public SecurityWebFilterChain springSecurityFilterChain(ServerHttpSecurity http) {
DelegatingServerLogoutHandler logoutHandler = new DelegatingServerLogoutHandler(
new CsrfServerLogoutHandler(csrfTokenRepository()),
new SecurityContextServerLogoutHandler(),
new WebSessionServerLogoutHandler(),
new HeaderWriterServerLogoutHandler(new ClearSiteDataServerHttpHeadersWriter(ClearSiteDataServerHttpHeadersWriter.Directive.ALL))
);
http
.oauth2Login().and()
.authorizeExchange()
.pathMatchers("/somePath/**").hasRole("SuperAdmin")
.pathMatchers("/somePathSquare/**").hasRole("SuperAdmin")
.pathMatchers("/somePathCube/**").hasRole("SuperAdmin")
.csrf().requireCsrfProtectionMatcher(createDefaultRequestMacher()).and()
.csrf(csrf -> csrf.csrfTokenRepository(csrfTokenRepository()))
.addFilterAfter(csrfFilter, SecurityWebFiltersOrder.CSRF)
.logout()
.logoutHandler(logoutHandler)
.logoutSuccessHandler(logoutSuccessHandler())
.and()
.authorizeExchange().anyExchange().permitAll()
;
return http.build();
}
Also tried changing the hasRole("SuperAdmin") to hasRole("ROLE_SuperAdmin") & hasAuthority("SuperAdmin") & hasAuthority("ROLE_SuperAdmin").
Getting same error access denied in all the cases.
Can anyone share your thoughts and workarounds on how to fix this?