Autoryzacja oparta na rolach z użyciem Granted Authorities
Po uwierzytelnieniu użytkowników na podstawie danych z bazy poznaj autoryzację z użyciem ról i uprawnień, zabezpieczającą endpointy i metody w Spring Security.
Autoryzacja oparta na rolach z użyciem Granted Authorities to bezpłatna lekcja Spring Security 6 & JWT Authentication na CoddyKit. To lekcja 4 z 4. Możesz przeczytać całą lekcję poniżej za darmo — a potem ćwiczyć ją interaktywnie w przeglądarce z wbudowanym edytorem kodu i tutorem AI dostępnym 24/7. To część ścieżki edukacyjnej Spring Security 6 & JWT Authentication, a Twój postęp synchronizuje się między webem a aplikacją CoddyKit. Kurs Spring Security 6 & JWT Authentication zawiera 4 lekcji w sumie.
Części tej lekcji nie zostały jeszcze przetłumaczone i są wyświetlane po angielsku.
Authentication vs Authorization
You can now load users from a database and verify passwords. That is authentication (who you are). The next question is authorization (what you may do), driven by roles and authorities.
Authorities and Roles
Spring represents permissions as GrantedAuthority objects. A role is just an authority with a ROLE_ prefix, e.g. ROLE_ADMIN.
Assigning Authorities to a User
When building your UserDetails, attach the authorities the user holds.
User.withUsername('alice')
.password(encoded)
.roles('ADMIN', 'USER')
.build();Securing URLs by Role
In the filter chain, restrict paths with hasRole. Spring adds the ROLE_ prefix for you here.
http.authorizeHttpRequests(a -> a
.requestMatchers('/admin/**').hasRole('ADMIN')
.anyRequest().authenticated());Requiring Specific Authorities
For finer control use hasAuthority, which matches the authority string exactly with no prefix added.
http.authorizeHttpRequests(a -> a
.requestMatchers('/reports/**').hasAuthority('REPORT_READ'));Multiple Allowed Roles
hasAnyRole permits access if the user has at least one of several roles.
http.authorizeHttpRequests(a -> a
.requestMatchers('/staff/**').hasAnyRole('ADMIN', 'MANAGER'));Method-Level Security
Enable annotation-based security to protect service methods, not just URLs.
@EnableMethodSecurity
@Configuration
public class SecurityConfig { }Using @PreAuthorize
@PreAuthorize runs a SpEL expression before the method executes, blocking unauthorized callers.
@PreAuthorize("hasRole('ADMIN')")
public void deleteUser(Long id) { }Checking the Current User
SpEL can reference the authenticated principal, e.g. to allow users to edit only their own data.
@PreAuthorize("#username == authentication.name")
public void updateProfile(String username) { }Mapping DB Roles to Authorities
In your UserDetailsService, convert role rows from the database into SimpleGrantedAuthority objects so authorization rules apply.
var auths = roles.stream()
.map(r -> new SimpleGrantedAuthority('ROLE_' + r))
.toList();Putting It Together
The full picture: authenticate from the DB, map roles to authorities, secure URLs with hasRole/hasAuthority, and protect methods with @PreAuthorize.
Quick Check
What is the difference between hasRole('ADMIN') and hasAuthority('ADMIN')?
Recap
You can now control what authenticated users may do:
- Roles are authorities with a
ROLE_prefix hasRole/hasAnyRolevs exacthasAuthority@EnableMethodSecurity+@PreAuthorizefor method-level rules- Map DB roles to
SimpleGrantedAuthorityin your UserDetailsService
Ucz się Java dzięki korepetycjom AI — za darmo
Pisz i uruchamiaj kod w przeglądarce, otrzymuj natychmiastową pomoc od korepetytora AI dostępnego 24/7 i kontynuuj naukę w sieci lub w aplikacji.
- Kursy
- 12
- Lekcje
- 48
Często zadawane pytania
Czy lekcja „Autoryzacja oparta na rolach z użyciem Granted Authorities” jest bezpłatna?
Tak — pełny tekst „Autoryzacja oparta na rolach z użyciem Granted Authorities” jest dostępny za darmo tutaj w sieci. Aby ćwiczyć ją interaktywnie (wbudowany edytor kodu i tutor AI dostępny 24/7) i odblokować resztę kursu Spring Security 6 & JWT Authentication, przejdź na CoddyKit PRO. Kurs Spring Security 6 & JWT Authentication zawiera 4 lekcji w sumie.
Co nauczysz się w „Autoryzacja oparta na rolach z użyciem Granted Authorities”?
Po uwierzytelnieniu użytkowników na podstawie danych z bazy poznaj autoryzację z użyciem ról i uprawnień, zabezpieczającą endpointy i metody w Spring Security. Ćwiczysz Spring Security 6 & JWT Authentication z praktycznym kodem, który uruchamiasz bezpośrednio w przeglądarce, a tutor AI dostępny 24/7 odpowiada na Twoje pytania podczas pracy nad lekcją.
Czy potrzebuję doświadczenia, aby zacząć Spring Security 6 & JWT Authentication?
Nie wymagamy żadnego doświadczenia. Spring Security 6 & JWT Authentication w CoddyKit jest strukturyzowany dla początkujących i zaawansowanych użytkowników, więc możesz zacząć tutaj lub od początku i uczyć się w swoim tempie. To lekcja 4 z 4.
Ile czasu zajmuje lekcja „Autoryzacja oparta na rolach z użyciem Granted Authorities”?
Większość lekcji CoddyKit trwa około 5–10 minut. Każda lekcja to mały, interaktywny krok, dzięki czemu robisz systematyczne postępy i zawsze wracasz dokładnie do tego samego miejsca — na webie i w aplikacji.
Czy mogę pisać i uruchamiać kod w tej lekcji Spring Security 6 & JWT Authentication?
Tak. Każda lekcja Spring Security 6 & JWT Authentication zawiera wbudowany edytor kodu, więc piszesz i uruchamiasz prawdziwy kod bezpośrednio w przeglądarce i od razu otrzymujesz sprzężenie zwrotne od AI — bez konfiguracji na komputerze.
Wszystkie lekcje w tym kursie
- Implementacja niestandardowego UserDetailsService
- Poznawanie koderów haseł
- Integracja zarządzania użytkownikami z bazą danych
- Autoryzacja oparta na rolach z użyciem Granted Authorities