I want to make a config file to configure TLS and Oauth2 in my SecureConfig.java
The tls config:
@Override protected void configure(HttpSecurity http) throws Exception { http.authorizeRequests().anyRequest().authenticated().and().sessionManagement() .sessionCreationPolicy(SessionCreationPolicy.NEVER); } The Oauth2.0 config:
@Override protected void configure(HttpSecurity http) throws Exception { http.csrf().disable() .requiresChannel() .anyRequest() .requiresSecure(); } What is the better way to use these two in the same config file and method? Does the and() work fine?
Like that:
@Override protected void configure(HttpSecurity http) throws Exception { http.csrf().disable().authorizeRequests().anyRequest().authenticated().and().sessionManagement().sessionCreationPolicy(SessionCreationPolicy.NEVER).and() .requiresChannel() .anyRequest() .requiresSecure(); }