Securing static resources in a Spring Boot App












0















I want to secure all content in the 'static' folder of a Spring Boot app.



I have tried all sorts of combinations in my security config including:



.antMatchers("/resources/**").authenticated()
.antMatchers("/resources/static/**").authenticated()
.antMatchers("/static/**").authenticated()


None of these work. What is the correct way to do this?










share|improve this question























  • Those folders are served, but they're not actually within the path of any web request, so they don't match to anything. A proper solution would be to put your static resources within folders, eg. src/main/resources/static/css/mystyle.css and to add matchers to those, eg. .antMatchers("/css/**").authenticated().

    – g00glen00b
    Nov 21 '18 at 14:27











  • Thanks but, I have tried that and it doesn't work.

    – SME
    Nov 21 '18 at 14:52






  • 1





    I'm using Spring Boot 1.5.1.RELEASE and my static resources are in src/main/resources/static. I want to prevent unauthorized users downloading certain javascript files.

    – SME
    Nov 21 '18 at 15:33











  • Show your complete configuration class with all anotations.

    – dur
    Nov 22 '18 at 21:24











  • It's ok. I have a work around. I created a folder call app-js and moved all the JavaScript I wanted to secure into this folder and that works.

    – SME
    Nov 22 '18 at 22:15
















0















I want to secure all content in the 'static' folder of a Spring Boot app.



I have tried all sorts of combinations in my security config including:



.antMatchers("/resources/**").authenticated()
.antMatchers("/resources/static/**").authenticated()
.antMatchers("/static/**").authenticated()


None of these work. What is the correct way to do this?










share|improve this question























  • Those folders are served, but they're not actually within the path of any web request, so they don't match to anything. A proper solution would be to put your static resources within folders, eg. src/main/resources/static/css/mystyle.css and to add matchers to those, eg. .antMatchers("/css/**").authenticated().

    – g00glen00b
    Nov 21 '18 at 14:27











  • Thanks but, I have tried that and it doesn't work.

    – SME
    Nov 21 '18 at 14:52






  • 1





    I'm using Spring Boot 1.5.1.RELEASE and my static resources are in src/main/resources/static. I want to prevent unauthorized users downloading certain javascript files.

    – SME
    Nov 21 '18 at 15:33











  • Show your complete configuration class with all anotations.

    – dur
    Nov 22 '18 at 21:24











  • It's ok. I have a work around. I created a folder call app-js and moved all the JavaScript I wanted to secure into this folder and that works.

    – SME
    Nov 22 '18 at 22:15














0












0








0








I want to secure all content in the 'static' folder of a Spring Boot app.



I have tried all sorts of combinations in my security config including:



.antMatchers("/resources/**").authenticated()
.antMatchers("/resources/static/**").authenticated()
.antMatchers("/static/**").authenticated()


None of these work. What is the correct way to do this?










share|improve this question














I want to secure all content in the 'static' folder of a Spring Boot app.



I have tried all sorts of combinations in my security config including:



.antMatchers("/resources/**").authenticated()
.antMatchers("/resources/static/**").authenticated()
.antMatchers("/static/**").authenticated()


None of these work. What is the correct way to do this?







spring-boot spring-security






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Nov 21 '18 at 14:24









SMESME

57112




57112













  • Those folders are served, but they're not actually within the path of any web request, so they don't match to anything. A proper solution would be to put your static resources within folders, eg. src/main/resources/static/css/mystyle.css and to add matchers to those, eg. .antMatchers("/css/**").authenticated().

    – g00glen00b
    Nov 21 '18 at 14:27











  • Thanks but, I have tried that and it doesn't work.

    – SME
    Nov 21 '18 at 14:52






  • 1





    I'm using Spring Boot 1.5.1.RELEASE and my static resources are in src/main/resources/static. I want to prevent unauthorized users downloading certain javascript files.

    – SME
    Nov 21 '18 at 15:33











  • Show your complete configuration class with all anotations.

    – dur
    Nov 22 '18 at 21:24











  • It's ok. I have a work around. I created a folder call app-js and moved all the JavaScript I wanted to secure into this folder and that works.

    – SME
    Nov 22 '18 at 22:15



















  • Those folders are served, but they're not actually within the path of any web request, so they don't match to anything. A proper solution would be to put your static resources within folders, eg. src/main/resources/static/css/mystyle.css and to add matchers to those, eg. .antMatchers("/css/**").authenticated().

    – g00glen00b
    Nov 21 '18 at 14:27











  • Thanks but, I have tried that and it doesn't work.

    – SME
    Nov 21 '18 at 14:52






  • 1





    I'm using Spring Boot 1.5.1.RELEASE and my static resources are in src/main/resources/static. I want to prevent unauthorized users downloading certain javascript files.

    – SME
    Nov 21 '18 at 15:33











  • Show your complete configuration class with all anotations.

    – dur
    Nov 22 '18 at 21:24











  • It's ok. I have a work around. I created a folder call app-js and moved all the JavaScript I wanted to secure into this folder and that works.

    – SME
    Nov 22 '18 at 22:15

















Those folders are served, but they're not actually within the path of any web request, so they don't match to anything. A proper solution would be to put your static resources within folders, eg. src/main/resources/static/css/mystyle.css and to add matchers to those, eg. .antMatchers("/css/**").authenticated().

– g00glen00b
Nov 21 '18 at 14:27





Those folders are served, but they're not actually within the path of any web request, so they don't match to anything. A proper solution would be to put your static resources within folders, eg. src/main/resources/static/css/mystyle.css and to add matchers to those, eg. .antMatchers("/css/**").authenticated().

– g00glen00b
Nov 21 '18 at 14:27













Thanks but, I have tried that and it doesn't work.

– SME
Nov 21 '18 at 14:52





Thanks but, I have tried that and it doesn't work.

– SME
Nov 21 '18 at 14:52




1




1





I'm using Spring Boot 1.5.1.RELEASE and my static resources are in src/main/resources/static. I want to prevent unauthorized users downloading certain javascript files.

– SME
Nov 21 '18 at 15:33





I'm using Spring Boot 1.5.1.RELEASE and my static resources are in src/main/resources/static. I want to prevent unauthorized users downloading certain javascript files.

– SME
Nov 21 '18 at 15:33













Show your complete configuration class with all anotations.

– dur
Nov 22 '18 at 21:24





Show your complete configuration class with all anotations.

– dur
Nov 22 '18 at 21:24













It's ok. I have a work around. I created a folder call app-js and moved all the JavaScript I wanted to secure into this folder and that works.

– SME
Nov 22 '18 at 22:15





It's ok. I have a work around. I created a folder call app-js and moved all the JavaScript I wanted to secure into this folder and that works.

– SME
Nov 22 '18 at 22:15












1 Answer
1






active

oldest

votes


















0














Disable the default spring-boot resource mappings with



spring.resources.add-mappings=false


to



application.properties





share|improve this answer























    Your Answer






    StackExchange.ifUsing("editor", function () {
    StackExchange.using("externalEditor", function () {
    StackExchange.using("snippets", function () {
    StackExchange.snippets.init();
    });
    });
    }, "code-snippets");

    StackExchange.ready(function() {
    var channelOptions = {
    tags: "".split(" "),
    id: "1"
    };
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function() {
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled) {
    StackExchange.using("snippets", function() {
    createEditor();
    });
    }
    else {
    createEditor();
    }
    });

    function createEditor() {
    StackExchange.prepareEditor({
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader: {
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    },
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    });


    }
    });














    draft saved

    draft discarded


















    StackExchange.ready(
    function () {
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53414209%2fsecuring-static-resources-in-a-spring-boot-app%23new-answer', 'question_page');
    }
    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    0














    Disable the default spring-boot resource mappings with



    spring.resources.add-mappings=false


    to



    application.properties





    share|improve this answer




























      0














      Disable the default spring-boot resource mappings with



      spring.resources.add-mappings=false


      to



      application.properties





      share|improve this answer


























        0












        0








        0







        Disable the default spring-boot resource mappings with



        spring.resources.add-mappings=false


        to



        application.properties





        share|improve this answer













        Disable the default spring-boot resource mappings with



        spring.resources.add-mappings=false


        to



        application.properties






        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered Nov 21 '18 at 14:33









        AlexBAlexB

        1875




        1875
































            draft saved

            draft discarded




















































            Thanks for contributing an answer to Stack Overflow!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid



            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.


            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function () {
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53414209%2fsecuring-static-resources-in-a-spring-boot-app%23new-answer', 'question_page');
            }
            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            這個網誌中的熱門文章

            Xamarin.form Move up view when keyboard appear

            Post-Redirect-Get with Spring WebFlux and Thymeleaf

            Anylogic : not able to use stopDelay()