【发布时间】:2017-03-08 14:03:29
【问题描述】:
长话短说,我正在尝试使用 Spring Security 保护一些遗留的 Angular 应用程序。 整个 Angular 静态的东西都在
下src/main/resources/static
所有应该受到保护的东西都在
src/main/resources/static/protected-stuff
这是我的配置(它是整个 Spring Boot 应用程序配置的一部分):
@Override
protected void configure(HttpSecurity http) throws Exception {
http.formLogin()
.loginPage("/login.html").permitAll()
.loginProcessingUrl("/dologin")
.failureForwardUrl("/login.html?isError=true")
.failureUrl("/login.html?isError=true")
.defaultSuccessUrl("/protected-stuff/index.html")
.and()
.authorizeRequests()
.antMatchers(HttpMethod.GET, "/", "/index.html", "/home.html", "/login/**").permitAll()
.antMatchers("/protected-stuff/**").authenticated()
.and()
.csrf().disable();
}
现在,对我来说有问题的部分是:
.antMatchers("/protected-stuff/**").authenticated()
在错误登录时重定向、处理登录请求(它命中 AuthenticationProvider)等工作,但在成功验证后重定向到受保护的内容会导致重定向回登录页面。现在我怀疑资源过滤器和 Spring Sec 拦截器(好吧,过滤器)相互冲突,但我不能确定是否有可能克服这种情况?
欢迎和感谢任何帮助/建议。
【问题讨论】:
标签: angularjs spring spring-security spring-boot