From 2da14a85e29cc1a0a36ccd0ed1537cd1bac69b83 Mon Sep 17 00:00:00 2001 From: Tim <135014430+nagisa77@users.noreply.github.com> Date: Wed, 9 Jul 2025 14:05:24 +0800 Subject: [PATCH] Allow public access to user profile --- src/main/java/com/openisle/config/SecurityConfig.java | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/main/java/com/openisle/config/SecurityConfig.java b/src/main/java/com/openisle/config/SecurityConfig.java index 3d6f5faaf..e9fe79ad6 100644 --- a/src/main/java/com/openisle/config/SecurityConfig.java +++ b/src/main/java/com/openisle/config/SecurityConfig.java @@ -88,6 +88,7 @@ public class SecurityConfig { .requestMatchers(HttpMethod.GET, "/api/categories/**").permitAll() .requestMatchers(HttpMethod.GET, "/api/tags/**").permitAll() .requestMatchers(HttpMethod.GET, "/api/search/**").permitAll() + .requestMatchers(HttpMethod.GET, "/api/users/**").permitAll() .requestMatchers(HttpMethod.POST, "/api/categories/**").hasAuthority("ADMIN") .requestMatchers(HttpMethod.POST, "/api/tags/**").hasAuthority("ADMIN") .requestMatchers(HttpMethod.DELETE, "/api/categories/**").hasAuthority("ADMIN") @@ -110,7 +111,7 @@ public class SecurityConfig { boolean publicGet = "GET".equalsIgnoreCase(request.getMethod()) && (uri.startsWith("/api/posts") || uri.startsWith("/api/comments") || uri.startsWith("/api/categories") || uri.startsWith("/api/tags") || - uri.startsWith("/api/search")); + uri.startsWith("/api/search") || uri.startsWith("/api/users")); if (authHeader != null && authHeader.startsWith("Bearer ")) { String token = authHeader.substring(7);