Skip to content

refactor(WebSecurityConfig): Streamline Spring Security filter chain - #359

Merged
hirokiterashima merged 1 commit into
developfrom
refactor/modernize-security-config
Sep 30, 2026
Merged

hirokiterashima merged 1 commit into
developfrom
refactor/modernize-security-config

Conversation

@hirokiterashima

@hirokiterashima hirokiterashima commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Summary

Following the upgrade to Spring Boot 3.4 this PR modernizes WebSecurityConfig by adopting idiomatic Spring Security 6 patterns, switching from field injection to constructor injection, and adding missing authorization test coverage for user impersonation.

Changes

1. WebSecurityConfig.java Modernization

  • Constructor Injection: Replaced field-level @Autowired on UserDetailsService with constructor injection (private final UserDetailsService userDetailsService).
  • Cleaned Up Unused Imports: Removed org.springframework.beans.factory.annotation.Autowired.
  • Streamlined .authorizeHttpRequests(...) Matchers:
    • Removed 30+ redundant new AntPathRequestMatcher(...) wrapper instantiations in favor of Spring Security 6's native string varargs .requestMatchers(...).
    • Cleanly grouped endpoints by role and access tier (ADMINISTRATOR, RESEARCHER, TEACHER, STUDENT, permitAll()).
    • Preserved exact route rule evaluation ordering (e.g. keeping /api/student/forgot/** and registration endpoints ahead of /api/teacher/**, and /student/account/info ahead of /student/**).

2. Authorization Test Coverage (WebSecurityConfigAuthorizationTest.java)

Added test coverage for the /api/login/impersonate endpoint:

  • administratorAndResearcher_impersonate_shouldBeAuthorized: Verifies that ADMINISTRATOR and RESEARCHER roles can access the impersonation endpoint.
  • teacherAndStudent_impersonate_shouldBeForbidden: Verifies that unauthorized roles (TEACHER and STUDENT) receive 403 Forbidden.
  • unauthenticated_protectedEndpoints_shouldBeDenied: Verifies anonymous requests to /api/login/impersonate are intercepted and redirected to /login.

Affected Files

  • src/main/java/org/wise/portal/spring/impl/WebSecurityConfig.java
  • src/test/java/org/wise/portal/spring/impl/WebSecurityConfigAuthorizationTest.java

Verification

  • mvn compile and mvn test-compile succeeded with zero warnings/errors.
  • Unit test suite verified and passing cleanly.

@hirokiterashima hirokiterashima changed the title refactor(WebSecurityConfig): Streamline Spring Security Filter Chain and add impersonate authorization tests refactor(WebSecurityConfig): Streamline Spring Security filter chain Sep 30, 2026
@hirokiterashima
hirokiterashima force-pushed the refactor/modernize-security-config branch from dd02b57 to 2127e9e Compare September 30, 2026 00:42
@hirokiterashima hirokiterashima self-assigned this Sep 30, 2026
@hirokiterashima
hirokiterashima merged commit b454a38 into develop Sep 30, 2026
2 checks passed
@hirokiterashima
hirokiterashima deleted the refactor/modernize-security-config branch September 30, 2026 01:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant