This commit is contained in:
Dominique Eifländer 2024-05-16 14:54:21 +02:00
parent 2a8196a69f
commit e11cb8149e

View File

@ -59,7 +59,11 @@ public class SecuredKeyCloakConfiguration {
http.anonymous().disable();
http.httpBasic().disable();
http.csrf().disable();
http.csrf(csrf -> csrf.ignoringRequestMatchers("/gs-guide-websocket/**"));
http.headers(headers -> headers
// allow same origin to frame our site to support iframe SockJS
.frameOptions(frameOptions -> frameOptions
.sameOrigin()));
http.oauth2ResourceServer(oauth2 -> oauth2.authenticationManagerResolver(tenantAuthenticationManagerResolver));
http.authorizeHttpRequests().anyRequest().authenticated();