รักษาความปลอดภัยให้ปลายทางด้วยกฎการเข้าถึงแบบกำหนดเอง
ก้าวข้ามการตรวจสอบบทบาทแบบง่าย ๆ ด้วยการเขียนตรรกะการกำหนดสิทธิ์แบบกำหนดเองใน Spring Security 6 โดยใช้ AuthorizationManager นิพจน์ SpEL และตัวจับคู่คำขอ
รักษาความปลอดภัยให้ปลายทางด้วยกฎการเข้าถึงแบบกำหนดเอง เป็นบทเรียน Spring Security 6 & JWT Authentication ฟรีบน CoddyKit นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Spring Security 6 & JWT Authentication และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Spring Security 6 & JWT Authentication มีบทเรียนทั้งหมด 4 บทเรียน
บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ
Why Custom Access Rules?
Roles and methods cover most cases, but real apps need finer control: only the owner of a resource may edit it, or access depends on the time of day or a feature flag.
Spring Security 6 lets you express these rules declaratively or programmatically.
The authorizeHttpRequests DSL
In Spring Security 6 the modern way to secure URLs is authorizeHttpRequests. Each matcher maps a request pattern to an access rule.
http.authorizeHttpRequests(auth -> auth
.requestMatchers('/public/**').permitAll()
.requestMatchers('/admin/**').hasRole('ADMIN')
.anyRequest().authenticated());Matching by HTTP Method
You can scope rules to a specific HTTP method, so reads and writes have different requirements.
http.authorizeHttpRequests(auth -> auth
.requestMatchers(HttpMethod.GET, '/api/orders/**').authenticated()
.requestMatchers(HttpMethod.POST, '/api/orders/**').hasRole('MANAGER'));SpEL with access()
The access() rule takes a Spring Expression Language (SpEL) condition for dynamic logic that plain matchers cannot express.
http.authorizeHttpRequests(auth -> auth
.requestMatchers('/reports/**')
.access(new WebExpressionAuthorizationManager(
"hasRole('ANALYST') and request.getHeader('X-Region') == 'EU'")));The AuthorizationManager Interface
For full control, implement AuthorizationManager. It returns an AuthorizationDecision that grants or denies access based on the authentication and the request.
public interface AuthorizationManager<T> {
AuthorizationDecision check(Supplier<Authentication> auth, T object);
}Writing a Custom AuthorizationManager
Here is a manager that only allows access during business hours. The supplier gives the current user; the object holds request context.
AuthorizationManager<RequestAuthorizationContext> businessHours =
(auth, ctx) -> {
int hour = LocalTime.now().getHour();
boolean ok = hour >= 9 && hour < 18;
return new AuthorizationDecision(ok);
};Plugging It In
Attach your custom manager to a matcher with access(). Any request to the path is now evaluated by your logic.
http.authorizeHttpRequests(auth -> auth
.requestMatchers('/maintenance/**').access(businessHours)
.anyRequest().authenticated());Owner-Based Access
A common rule: only the resource owner can modify it. You can read a path variable from the request context to compare against the logged-in user.
AuthorizationManager<RequestAuthorizationContext> ownerOnly =
(auth, ctx) -> {
String pathUser = ctx.getVariables().get('userId');
boolean same = auth.get().getName().equals(pathUser);
return new AuthorizationDecision(same);
};Combining Rules
Spring evaluates matchers top to bottom and stops at the first match. Order matters: put specific rules before broad ones, and always end with a catch-all like anyRequest().
Denying by Default
A secure baseline denies everything not explicitly allowed. Use denyAll() as the final rule when you want a strict allow-list.
http.authorizeHttpRequests(auth -> auth
.requestMatchers('/health').permitAll()
.anyRequest().denyAll());Testing Access Rules
Verify your rules with @WithMockUser and MockMvc. Assert that authorized users get 200 and unauthorized users get 403.
mockMvc.perform(get('/admin/dashboard'))
.andExpect(status().isForbidden());Quick Check
Test your understanding of custom access rules.
Recap
You learned to write custom authorization in Spring Security 6:
- Use the
authorizeHttpRequestsDSL with path and method matchers - Apply SpEL conditions via
access() - Implement
AuthorizationManagerfor dynamic, owner-based, or time-based rules - Order matters; end with a catch-all and prefer deny-by-default
These tools let you enforce business-specific security policies precisely.
คำถามที่พบบ่อย
บทเรียน “รักษาความปลอดภัยให้ปลายทางด้วยกฎการเข้าถึงแบบกำหนดเอง” ฟรีหรือไม่
ใช่ — ข้อความเต็มของ “รักษาความปลอดภัยให้ปลายทางด้วยกฎการเข้าถึงแบบกำหนดเอง” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Spring Security 6 & JWT Authentication ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Spring Security 6 & JWT Authentication มีบทเรียนทั้งหมด 4 บทเรียน
คุณจะเรียนรู้อะไรในบทเรียน “รักษาความปลอดภัยให้ปลายทางด้วยกฎการเข้าถึงแบบกำหนดเอง”
ก้าวข้ามการตรวจสอบบทบาทแบบง่าย ๆ ด้วยการเขียนตรรกะการกำหนดสิทธิ์แบบกำหนดเองใน Spring Security 6 โดยใช้ AuthorizationManager นิพจน์ SpEL และตัวจับคู่คำขอ คุณปฏิบัติ Spring Security 6 & JWT Authentication ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน
คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Spring Security 6 & JWT Authentication หรือไม่
ไม่จำเป็นต้องมีประสบการณ์มาก่อน Spring Security 6 & JWT Authentication บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน
บทเรียน “รักษาความปลอดภัยให้ปลายทางด้วยกฎการเข้าถึงแบบกำหนดเอง” ใช้เวลานานแค่ไหน
บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย
ฉันเขียนและรันโค้ดในบทเรียน Spring Security 6 & JWT Authentication นี้ได้ไหม
ได้ บทเรียน Spring Security 6 & JWT Authentication ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ
บทเรียนทั้งหมดในหลักสูตรนี้
- การควบคุมการเข้าถึงตามบทบาท (RBAC)
- การรักษาความปลอดภัยระดับเมธอดด้วยแอนโนเทชัน
- เจาะลึกการกำหนดค่า HttpSecurity
- รักษาความปลอดภัยให้ปลายทางด้วยกฎการเข้าถึงแบบกำหนดเอง