Security Config
@Configuration
@EnableWebSecurity
@EnableMethodSecurity(prePostEnabled = true )
Application Security configuration.
Enforces DPoP for DPoP-bound tokens by placing DPoPValidationFilter before JWT authentication.
Requires authentication for all endpoints except explicit allow-list (docs, auth, websockets, JWKS).
Enables CORS with credentialed requests only for refresh/logout; HSTS and a minimal CSP are applied.
Functions
Link copied to clipboard
@Bean
@Primary
Link copied to clipboard
@Bean
@ConditionalOnMissingBean(value = [CorsConfigurationSource::class ] )
Link copied to clipboard