Static resources problem:

Hi,

By overriding the FlowuiSecurityConfiguration provided by Jmix and doing http.securityMatcher("/icons/**") there you break the Jmix configuration because it stops processing requests to all other URLs.

You need register a new SpringSecurityFilterChain bean and set the order for it less than the order of default Jmix FlowUI security filter chain. For example:

@Configuration
public class MySecurityConfiguration  {

    @Bean
    @Order(JmixSecurityFilterChainOrder.FLOWUI - 10)
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http.securityMatcher("/icons/**")
                .authorizeHttpRequests((authorize) -> authorize.requestMatchers("/icons/**").permitAll());
        return http.build();
    }
}
1 Like