fix authentication
This commit is contained in:
@ -54,7 +54,7 @@ public class JwtRequestFilter extends OncePerRequestFilter {
|
||||
|
||||
private void isValidToken(HttpServletRequest request, String jwtToken) {
|
||||
String requestUrl = request.getRequestURI();
|
||||
String refreshTokenUrl = "/authentication-service/authentication/v1/refresh-token";
|
||||
String refreshTokenUrl = "/api/authentication/refresh-token";
|
||||
if (!refreshTokenUrl.equals(requestUrl)) {
|
||||
var isValid = isValidAuthenticateToken(jwtToken);
|
||||
if (!isValid) {
|
||||
|
@ -34,6 +34,7 @@ public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
|
||||
.csrf().disable();
|
||||
httpSecurity.authorizeRequests()
|
||||
.antMatchers("/api*/**").permitAll()
|
||||
.antMatchers("/api/authentication/*").permitAll()
|
||||
.antMatchers("/actuator/health").permitAll()
|
||||
.antMatchers("/swagger*/**").permitAll()
|
||||
.antMatchers("/v2*/**").permitAll()
|
||||
|
Reference in New Issue
Block a user