Pārlūkot izejas kodu

禁用frame配置

欧阳劲驰 2 mēneši atpakaļ
vecāks
revīzija
aa95733f6b

+ 3 - 1
src/main/java/com/shkpr/service/alambizplugin/configuration/WebSecurityConfiguration.java

@@ -55,7 +55,9 @@ public class WebSecurityConfiguration extends WebSecurityConfigurerAdapter {
                 .anyRequest().permitAll()                                                                                          //所有其他请求需要身份认证
                 .and()
                 .addFilterBefore(new ApiJWTBizFilterMgr(ApiURI.URI_ALL_BUSI_XXX, authenticationManager()),
-                        UsernamePasswordAuthenticationFilter.class);
+                        UsernamePasswordAuthenticationFilter.class)
+                //禁用frame
+                .headers().frameOptions().disable();
                 /*.addFilterBefore(new ServerStatusMonitorFilter(ThirdApiURI.URI_HGAS_MONITOR_XXX, authenticationManager()),
                         UsernamePasswordAuthenticationFilter.class);*/