Skip to content

Commit 291a97d

Browse files
committed
feat: 리소스 접근 제어 수정
- 인증이 필요하지 않은 접근은 모두 허용해 불필요한 권한 검사를 피함
1 parent a045d9c commit 291a97d

File tree

1 file changed

+1
-2
lines changed

1 file changed

+1
-2
lines changed

src/main/java/dmu/dasom/api/global/auth/config/SecurityConfig.java

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -50,8 +50,7 @@ public SecurityFilterChain filterChain(final HttpSecurity http, final Authentica
5050
.authorizeHttpRequests(auth -> auth
5151
.requestMatchers("/api/admin/**").hasRole(Role.ROLE_ADMIN.getName())
5252
.requestMatchers("/api/auth/logout").authenticated()
53-
.requestMatchers("/api/**", "/swagger-ui/**", "/v3/api-docs/**").permitAll()
54-
.anyRequest().authenticated())
53+
.anyRequest().permitAll())
5554
.addFilterBefore(jwtFilter, CustomAuthenticationFilter.class)
5655
.addFilterAt(customAuthenticationFilter, UsernamePasswordAuthenticationFilter.class)
5756
.addFilterAfter(new CustomLogoutFilter(jwtUtil), JwtFilter.class)

0 commit comments

Comments
 (0)