【问题标题】:Spring Security - AngularJS - Protect Angular static contentSpring Security - AngularJS - 保护 Angular 静态内容
【发布时间】:2017-03-08 14:03:29
【问题描述】:

长话短说,我正在尝试使用 Spring Security 保护一些遗留的 Angular 应用程序。 整个 Angular 静态的东西都在

下
src/main/resources/static

所有应该受到保护的东西都在

src/main/resources/static/protected-stuff

这是我的配置(它是整个 Spring Boot 应用程序配置的一部分):

  @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.formLogin()
                .loginPage("/login.html").permitAll()
                .loginProcessingUrl("/dologin")
                .failureForwardUrl("/login.html?isError=true")
                .failureUrl("/login.html?isError=true")
                .defaultSuccessUrl("/protected-stuff/index.html")
                .and()
                .authorizeRequests()
                .antMatchers(HttpMethod.GET, "/", "/index.html", "/home.html", "/login/**").permitAll()
                .antMatchers("/protected-stuff/**").authenticated()
                .and()
                .csrf().disable();
    }

现在,对我来说有问题的部分是:

                    .antMatchers("/protected-stuff/**").authenticated()

在错误登录时重定向、处理登录请求(它命中 AuthenticationProvider)等工作,但在成功验证后重定向到受保护的内容会导致重定向回登录页面。现在我怀疑资源过滤器和 Spring Sec 拦截器(好吧,过滤器)相互冲突,但我不能确定是否有可能克服这种情况?

欢迎和感谢任何帮助/建议。

【问题讨论】:

    标签: angularjs spring spring-security spring-boot


    【解决方案1】:

    通过 Spring Security 和 Spring Boot 进行调试,我已经设法确定了实际问题。实际上它是 Spring Boot 加载的配置的排序。 Spring Security 本身没有任何内容。所以基本上它只是为了给 Spring Sec 的配置最高的顺序。

    【讨论】:

      猜你喜欢
      • 2011-02-26
      • 2019-10-20
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2014-12-01
      • 1970-01-01
      • 2019-03-04
      • 2018-02-18
      相关资源
      最近更新 更多