added advertising
This commit is contained in:
@@ -12,6 +12,7 @@ import org.springframework.context.annotation.Configuration;
|
||||
import org.springframework.http.HttpMethod;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.MediaType;
|
||||
import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity;
|
||||
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
|
||||
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
|
||||
import org.springframework.security.config.annotation.web.configurers.AbstractHttpConfigurer;
|
||||
@@ -26,6 +27,7 @@ import org.springframework.web.cors.UrlBasedCorsConfigurationSource;
|
||||
|
||||
@Configuration
|
||||
@EnableWebSecurity
|
||||
@EnableMethodSecurity
|
||||
@RequiredArgsConstructor
|
||||
public class SecurityConfig {
|
||||
|
||||
@@ -49,6 +51,7 @@ public class SecurityConfig {
|
||||
.requestMatchers("/api/v1/auth/**").permitAll()
|
||||
.requestMatchers("/api/v1/test/**").permitAll()
|
||||
.requestMatchers(HttpMethod.GET, "/api/v1/files/**").permitAll()
|
||||
.requestMatchers(HttpMethod.GET, "/api/v1/ads-media/**").permitAll()
|
||||
.requestMatchers(HttpMethod.GET, "/api/v1/posts/**").permitAll()
|
||||
.requestMatchers(HttpMethod.GET, "/api/v1/reviews/**").permitAll()
|
||||
.requestMatchers("/files/**", "/uploads/**").permitAll()
|
||||
@@ -64,8 +67,15 @@ public class SecurityConfig {
|
||||
.requestMatchers(HttpMethod.PUT, "/api/v1/posts/**").authenticated()
|
||||
.requestMatchers(HttpMethod.DELETE, "/api/v1/posts/**").authenticated()
|
||||
|
||||
// реклама
|
||||
.requestMatchers(HttpMethod.GET, "/api/ads/next").permitAll()
|
||||
.requestMatchers(HttpMethod.POST, "/api/ads/impression").permitAll()
|
||||
.requestMatchers(HttpMethod.POST, "/api/ads/impression/beacon").permitAll()
|
||||
.requestMatchers(HttpMethod.POST, "/api/ads/click").permitAll()
|
||||
.requestMatchers(HttpMethod.GET, "/api/fullscreen-ad").permitAll()
|
||||
|
||||
// пример разграничения по ролям — раскомментировать и адаптировать под свои admin-эндпоинты
|
||||
// .requestMatchers("/api/v1/admin/**").hasRole("ADMIN")
|
||||
.requestMatchers("/api/v1/admin/**").hasRole("ADMIN")
|
||||
|
||||
.anyRequest().authenticated()
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user