【问题标题】:inMemoryAuthentication with Spring Boot使用 Spring Boot 进行 inMemoryAuthentication
【发布时间】:2017-07-25 15:08:13
【问题描述】:

我使用 Spring Initializer、嵌入式 Tomcat、Thymeleaf 模板引擎生成了一个 Spring Boot Web 应用程序,并将其打包为可执行 JAR 文件。

使用的技术:

Spring Boot 1.4.2.RELEASE、Spring 4.3.4.RELEASE、Thymeleaf 2.1.5.RELEASE、Tomcat 嵌入 8.5.6、Maven 3、Java 8

这是我的安全配置类:

@Configuration
@EnableWebSecurity
@PropertySource("classpath:/com/tdk/iot/config/app-${APP-KEY}.properties")
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Value("${securityConfig.formLogin.loginPage}")
    private String loginPage;

    @Override
    protected void configure(HttpSecurity http) throws Exception {

        http
            .formLogin()
                .loginPage(loginPage)
                .permitAll()
                .loginProcessingUrl("/login")
                .failureUrl("/login.html?error=true")
                .defaultSuccessUrl("/books/list")
                .and()
            .exceptionHandling()
                .accessDeniedPage("/denied")
                .and()
            .authorizeRequests()
                .antMatchers("/mockup/**").permitAll()
                .antMatchers("/books/**").permitAll()
                .antMatchers("/welcome/**").authenticated()
                .and()
            .logout()
                .permitAll()
                .logoutSuccessUrl("/index.html");
    }

    @Autowired
    public void configureGlobal(AuthenticationManagerBuilder auth) throws Exception {
        auth
            .inMemoryAuthentication()
                .passwordEncoder(new StandardPasswordEncoder())
                .withUser("test1").password("test1").roles("ADMIN").and()
                .withUser("test2").password("test2").roles("USER").and()
                .withUser("test3").password("test3").roles("SUPERADMIN");
    }

    @Bean
    public  static PropertySourcesPlaceholderConfigurer propertyDefaultConfig() {
        return new PropertySourcesPlaceholderConfigurer();
    }   
}

这里是登录控制器

 @Controller
 public class LoginController {

     @RequestMapping(value={ "/", "/tdk/login"}, method = { RequestMethod.POST,RequestMethod.GET})
     public String welcome(Map<String, Object> model) {
         return "tdk/login";
     }
 }

和模板:

<!DOCTYPE HTML>
<html xmlns:th="http://www.thymeleaf.org">
<head>

<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
</head>
<body>

<div class="wrap">
    <div class="login">
        <div class="logo"></div>

            <form th:action="@{/login.html}" method="post">

                <p th:if="${loginError}" class="error">Wrong user or password</p>

                <div class="input_label"><i class="fa fa-user"></i><input type="text" name="user" placeholder="User" /></div>
                <div class="input_label"><i class="fa fa-key"></i><input type="password" name="pass" placeholder="Password" /></div>
                <input type="submit" value="LOGIN" />
             </form>
        <div class="forget">
           <!--  <a href="#">Do you forgot your password?</a><br/> -->
            <br/>            
        </div>          
    </div>
</div>

</body>
</html>

但是当我使用 test1 / test1 访问时,我得到了这个错误:

白标错误页面

此应用程序没有显式映射 /error,因此您将其视为后备。

2017 年 3 月 5 日星期日 20:16:11 CET 出现意外错误(类型=不允许的方法,状态=405)。 不支持请求方法“POST”

【问题讨论】:

标签: spring spring-mvc authentication spring-boot spring-security


【解决方案1】:

试试这个代码

.failureUrl("/tdk/login?error=true")

控制器

@Controller
 public class LoginController {

     @RequestMapping(value={ "/", "/tdk/login"},params = {"error"},method=RequestMethod.POST)
     public String welcome(@RequestParam(value = "error", required = false) int error , ModelMap model) {
if (error == 1) {
            model.addAttribute("msg", "Invalid Username or Password");
            return "tdk/login";
        }
else{
                return "redirect:home";

}

     }
 }

【讨论】:

    【解决方案2】:

    您的登录页面使用 HTTP POST 调用 /login.html,但您的服务器不提供这样的请求映射。

    Spring Security 配置中配置的 URL:

    .loginProcessingUrl("/login")
    

    与您登录页面中的 URL 不匹配:

    <form th:action="@{/login.html}" method="post">
    

    另见AbstractAuthenticationFilterConfigurer#loginProcessingUrl:

    指定验证凭据的 URL。

    【讨论】:

      【解决方案3】:

      @RequestMapping 的默认方法控制器是 GET,而不是 POST。

      您需要在@requestMapping 上指定方法。

      @RequestMapping(value={ "/", "/tdk/login"}, method = RequestMethod.POST)
      

      【讨论】:

      • 我知道了,然后:o.s.web.servlet.PageNotFound : 不支持请求方法 'GET'
      猜你喜欢
      • 2018-05-06
      • 1970-01-01
      • 2019-08-12
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2016-07-01
      • 2020-06-03
      • 2016-09-24
      相关资源
      最近更新 更多