在Spring Security:春季安全,访问= “ROLE_ADMIN论” 与接入=“hasAnyRole( 'ROLE_ADMIN')
<sec:http pattern="/api/**" create-session="never"
entry-point-ref="oauthAuthenticationEntryPoint"
access-decision-manager-ref="accessDecisionManager"
xmlns="http://www.springframework.org/schema/security">
<anonymous enabled="false" />
<intercept-url pattern="/api/**" access="ROLE_ADMIN" />
<custom-filter ref="resourceServerFilter" before="PRE_AUTH_FILTER" />
<access-denied-handler ref="oauthAccessDeniedHandler" />
</sec:http>
在这一行
<intercept-url pattern="/api/**" access="ROLE_ADMIN" />
有什么区别的意思,如果我写的:
<intercept-url pattern="/api/**" access="hasRole('ROLE_ADMIN')" />
或:
<intercept-url pattern="/api/**" access="hasAnyRole('ROLE_ADMIN')" />