forbid camp registration without profile, see #25
This commit is contained in:
@@ -34,8 +34,8 @@ public class SecurityConfiguration {
|
||||
// @formatter:off
|
||||
.oauth2Login(o -> o.defaultSuccessUrl("/"))
|
||||
.logout(o -> o.logoutSuccessHandler(new OidcClientInitiatedLogoutSuccessHandler(crr)))
|
||||
.authorizeHttpRequests(o -> o.requestMatchers("/dashboard/**", "/business/**", "/confirmation/**","/userlogin/**").authenticated()
|
||||
.anyRequest().permitAll())
|
||||
.authorizeHttpRequests(o -> o.requestMatchers("/", "/impressum", "/datenschutz", "/allgemeines", "/reports/**", "/nachruf", "/verein", "/vereinsmitglieder", "/kontakt", "/css/**", "/js/**", "/images/**", "/fonts/**", "/font-awesome/**", "/webjars/**", "/ical/**").permitAll()
|
||||
.anyRequest().authenticated())
|
||||
.oauth2ResourceServer(o -> o.jwt(Customizer.withDefaults()))
|
||||
.sessionManagement(o -> o.init(sec));
|
||||
// @formatter:on
|
||||
|
||||
Reference in New Issue
Block a user