Filter chaineasy0-2 years

A security config has `requestMatchers("/api/**").authenticated()` followed by `requestMatchers("/api/admin/**").hasRole("ADMIN")`, and any signed-in user can call the admin endpoints. After reordering, admins get 403 too — their user records grant the authority `ADMIN`. What are the two bugs?

First: URL rules are evaluated in the order written, and the first match wins. /api/admin/users matches /api/** first, so the rule that applies is 'any authenticated user', and the admin rule below it is never reached. Specific patterns go first; the broad one, and finally anyRequest(), go last. Second: hasRole("ADMIN") checks for the authority ROLE_ADMIN; it adds the ROLE_ prefix for you. The users were granted ADMIN with no prefix, so the rule compares ROLE_ADMIN against ADMIN and never matches. Either grant roles as roles (roles("ADMIN") produces ROLE_ADMIN) or check the authority as it actually is (hasAuthority("ADMIN")).

The lesson behind it →
More on Filter chain