diff --git a/pom.xml b/pom.xml index 531ca08..5373598 100644 --- a/pom.xml +++ b/pom.xml @@ -178,6 +178,7 @@ exec-maven-plugin org.codehaus.mojo + 3.1.0 npm build the vue app diff --git a/src/main/java/de/avatic/lcc/controller/users/GroupController.java b/src/main/java/de/avatic/lcc/controller/users/GroupController.java index f466b0b..c36e741 100644 --- a/src/main/java/de/avatic/lcc/controller/users/GroupController.java +++ b/src/main/java/de/avatic/lcc/controller/users/GroupController.java @@ -5,6 +5,7 @@ import de.avatic.lcc.repositories.pagination.SearchQueryResult; import de.avatic.lcc.service.users.GroupService; import jakarta.validation.constraints.Min; import org.springframework.http.ResponseEntity; +import org.springframework.security.access.prepost.PreAuthorize; import org.springframework.web.bind.annotation.*; import java.util.List; @@ -32,6 +33,7 @@ public class GroupController { * @return A ResponseEntity containing the list of groups and pagination headers. */ @GetMapping({"/", ""}) + @PreAuthorize("hasRole('RIGHT-MANAGMENT')") public ResponseEntity> listGroups(@RequestParam(defaultValue = "20") @Min(1) int limit, @RequestParam(defaultValue = "1") @Min(1) int page) { diff --git a/src/main/java/de/avatic/lcc/controller/users/UserController.java b/src/main/java/de/avatic/lcc/controller/users/UserController.java index 0c90235..de2a1f6 100644 --- a/src/main/java/de/avatic/lcc/controller/users/UserController.java +++ b/src/main/java/de/avatic/lcc/controller/users/UserController.java @@ -6,6 +6,7 @@ import de.avatic.lcc.repositories.pagination.SearchQueryResult; import de.avatic.lcc.service.users.UserService; import jakarta.validation.constraints.Min; import org.springframework.http.ResponseEntity; +import org.springframework.security.access.prepost.PreAuthorize; import org.springframework.validation.annotation.Validated; import org.springframework.web.bind.annotation.*; @@ -35,6 +36,7 @@ public class UserController { * @return A ResponseEntity containing the list of users, along with pagination headers. */ @GetMapping({"/", ""}) + @PreAuthorize("hasRole('RIGHT-MANAGMENT')") public ResponseEntity> listUsers( @RequestParam(defaultValue = "20") @Min(1) int limit, @RequestParam(defaultValue = "1") @Min(1) int page) { @@ -57,6 +59,7 @@ public class UserController { * @return A ResponseEntity indicating the operation was successful. */ @PutMapping({"/", ""}) + @PreAuthorize("hasRole('RIGHT-MANAGMENT')") public ResponseEntity updateUser(UserDTO user) { userService.updateUser(user); return ResponseEntity.ok().build();