【问题标题】:spring-boot strange exceptions when using EnableGlobalMethodSecurity with spring-jpa将 EnableGlobalMethodSecurity 与 spring-jpa 一起使用时 spring-boot 出现奇怪的异常
【发布时间】:2014-09-03 20:51:08
【问题描述】:

当我在没有 @EnableGlobalMethodSecurity 注释的情况下运行我的应用程序时,它工作得很好。但是,我想添加对 @Secured 注释的支持,所以我想添加它。当我这样做时(如图所示),我立即开始在我的测试中获得这些异常。

@ComponentScan("ltistarter")
@Configuration
@EnableAutoConfiguration
@EnableTransactionManagement // enables TX management and @Transaction
@EnableCaching // enables caching and @Cache* tags
@EnableWebMvcSecurity // enable spring security and web mvc hooks
@EnableGlobalMethodSecurity(securedEnabled = true, proxyTargetClass = true) // allows @Secured flag
public class Application extends WebMvcConfigurerAdapter {

    public static void main(String[] args) {
        SpringApplication.run(Application.class, args);
    }
...

这个异常(或类似的东西)出现在我的测试和启动时(如果我强制跳过测试):

testJPARelations(ltistarter.ApplicationTests) 经过时间:0.007 秒

它所指的类在这里:

@Transactional
public interface LtiKeyRepository extends PagingAndSortingRepository<LtiKeyEntity, Long> {
    /**
     * @param key the unique key
     * @return the LtiKeyEntity OR null if there is no entity matching this key
     */
    LtiKeyEntity findByKeyKey(String key);

    /**
     * @param key the unique key
     * @return the number of keys removed (0 or 1)
     */
    int deleteByKeyKey(String key);
}

那个类实际上不是一个类,它是一个接口,根据这里的 spring-boot JPA 指南:http://spring.io/guides/gs/accessing-data-jpa/

我怀疑这可能是这里的问题,但如果是这样,我怎样才能让 spring-jpa 和 spring-security 在 spring-boot 中一起玩得很好?

【问题讨论】:

  • 试试using aspectj AOP mode .. 或者你可能在注释无效的项目(例如:尝试注释真正的类而不是接口)
  • 不关注你 - 我可以通过删除 proxyTargetClass = true 来解决这个问题,但我还没有将任何东西注释为 Secured 所以我认为这不是问题

标签: spring-boot spring-security spring-data-jpa


【解决方案1】:

我通过从@EnableGlobalMethodSecurity 中删除proxyTargetClass = true 来解决这个问题,如下所示:

@ComponentScan("ltistarter")
@Configuration
@EnableAutoConfiguration
@EnableTransactionManagement // enables TX management and @Transaction
@EnableCaching // enables caching and @Cache* tags
@EnableWebMvcSecurity // enable spring security and web mvc hooks
@EnableGlobalMethodSecurity(prePostEnabled = true, securedEnabled = true)
// allows @Secured flag - proxyTargetClass = true causes this to die
public class Application extends WebMvcConfigurerAdapter {
...

您可以在此处查看代码:

https://github.com/azeckoski/lti_starter

【讨论】:

    【解决方案2】:

    您可能在 Spring Security 中遇到了这个问题:https://jira.spring.io/browse/SEC-2661。目前最好的解决方法是不要对UserDetailsService 使用JPA(有人会说UserDetailsService 是一个非常简单的接口,无论如何它并不真正保证使用JPA)。您还可以通过其他方式拯救应用程序(例如,将配置分解成更小的部分,使用GlobalAuthenticationConfigurerAdapter,不要使用@EnableGlobalMethodSecurity,将安全配置推送到父项目中)。

    更新:尽管 Spring Security 中存在这个问题, 仍然可以通过 @EnableGlobalMethodSecurity 使用 JPA 获取用户详细信息(参见此处,例如:https://github.com/scratches/jpa-method-security-sample)。因此,通过一些调整,您的应用可能也可以正常工作。

    【讨论】:

    • 这取决于 - 问题与 JPA 没有真正的关系,只是使用 JPA 是一种容易陷入麻烦的方法。查看示例(上面的示例和以“method-security”结尾的 Spring Boot 示例)并尝试将它们复制到配置结构中。或者发布一个重现问题的最小项目的链接,我可以看看。
    • 这非常小:github.com/azeckoski/lti_starter 我现在通过删除 proxyTargetClass = true 解决了这个问题,但这只是一个 hack
    • 该应用程序对我来说启动良好。我该如何打破它?
    猜你喜欢
    • 2013-10-04
    • 1970-01-01
    • 2015-06-13
    • 1970-01-01
    • 1970-01-01
    • 2017-09-02
    • 2014-10-21
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多