AI接入 v0.1
This commit is contained in:
@@ -34,6 +34,22 @@ public class SecurityConfig {
|
||||
.cors(cors -> cors.configurationSource(corsConfigurationSource()))
|
||||
.sessionManagement(session -> session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
|
||||
.authorizeHttpRequests(auth -> auth
|
||||
// 授权只做一次,异步/错误派发不再重复鉴权。
|
||||
//
|
||||
// 背景:Spring Security 6 默认 filterAllDispatcherTypes = true,
|
||||
// 连 ASYNC(异步派发)和 ERROR(错误页派发)也要过 AuthorizationFilter。
|
||||
// 而这两种派发发生时 SecurityContextHolder 里已经没东西了(过滤器跳过了
|
||||
// 它们),于是被判定成匿名 → AccessDenied。
|
||||
//
|
||||
// 对普通接口这只是多打一行日志,但对 SSE 是致命的:/api/ai/chat 用
|
||||
// SseEmitter,emitter.complete() 会触发一次 ASYNC 派发,此时响应早已
|
||||
// 提交,Spring 写不了错误页,就抛出
|
||||
// 「Unable to handle the Spring Security Exception because the response
|
||||
// is already committed」,客户端拿到的流被异常截断。
|
||||
//
|
||||
// 关掉它是安全的:ASYNC/ERROR 都不是攻击者能凭空构造的派发类型,
|
||||
// 它们只是「已经通过鉴权的那次请求」的收尾阶段。
|
||||
.shouldFilterAllDispatcherTypes(false)
|
||||
.requestMatchers("/api/auth/**").permitAll()
|
||||
.requestMatchers("/api/gold-price/**").permitAll()
|
||||
.requestMatchers("/doc.html", "/swagger-ui/**", "/v3/api-docs/**", "/webjars/**").permitAll()
|
||||
|
||||
Reference in New Issue
Block a user