【问题标题】:Spring Boot 2 OAuth2 not serving static contentSpring Boot 2 OAuth2 不提供静态内容
【发布时间】:2019-03-30 19:17:20
【问题描述】:

我创建了两个应用程序,App-Server 和 App-Client。

App Server 是 Spring Boot 2 和 Spring Security OAuth2。

App-Client 是 Angular JS 6。

当我分别运行这两个应用程序时,它们工作正常,但是当我尝试使用 App-Server 来提供静态内容(应用程序客户端)时,它就不起作用了。

我正在使用以下代码将静态文件添加到 App-Server。

<build>
    <plugins>
        <plugin>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-maven-plugin</artifactId>
        </plugin>
        <plugin>
            <artifactId>maven-resources-plugin</artifactId>
            <executions>
                  <execution>
                      <id>copy-resources</id>
                      <phase>validate</phase>
                      <goals><goal>copy-resources</goal></goals>
                      <configuration>
                          <outputDirectory>${basedir}/target/classes/static/</outputDirectory>
                          <resources>
                              <resource>
                                  <directory>${basedir}/../app-client/dist/app-client</directory >
                              </resource>
                          </resources>
                      </configuration>
                  </execution>
            </executions>
        </plugin>
    </plugins>
</build>

我的网络安全看起来像

@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {
@Override
    @Order(Ordered.HIGHEST_PRECEDENCE)
    protected void configure(HttpSecurity http) throws Exception {
        http
        .sessionManagement()
        .sessionCreationPolicy(SessionCreationPolicy.STATELESS)
        .and()
        .csrf().disable()
        .authorizeRequests()
        .antMatchers("/about","/signup","/oauth/token","/users/otp").permitAll()
        .anyRequest().authenticated()
        .and().logout().logoutSuccessUrl("/").permitAll()
        .and()
        .httpBasic()
            .realmName(REALM);
    }
//Some other code .....
}

我的任何 ResourceServerConfig 如下所示

    @Configuration
    @EnableResourceServer
    public class ResourceServerConfig extends ResourceServerConfigurerAdapter

 {

    @Autowired
    private TokenStore tokenStore;

    @Override
    public void configure(ResourceServerSecurityConfigurer resources)throws Exception{
        resources.resourceId("app-server-api").tokenStore(tokenStore);
    }

    @Override
    public void configure(HttpSecurity http) throws Exception {
        http.authorizeRequests()
        .antMatchers("/","/users/otp", "/index.html","/resources/**","/images/**")
        .permitAll()
        .antMatchers("/v1/**")
        .authenticated();
    }

}

当我尝试点击任何静态文件时,我没有任何回应。

但是在本地,我可以看到

未找到包含 URI [/api/index.html] 的 HTTP 请求的映射 名称为“dispatcherServlet”的 DispatcherServlet

...

【问题讨论】:

标签: spring angular spring-boot spring-security-oauth2


【解决方案1】:

我做了一些更改,首先,我检查了 jar(通过 unjaring),发现没有可用于静态内容的文件。

经过几次试用和运行,我发现在 pom.xml 中,我需要正确映射来自 app-client 的 ui 内容。我做了以下。

<plugin>
            <artifactId>maven-resources-plugin</artifactId>
            <executions>
                  <execution>
                      <id>copy-resources</id>
                      <phase>validate</phase>
                      <goals><goal>copy-resources</goal></goals>
                      <configuration>
                          <outputDirectory>${basedir}/target/classes/static/</outputDirectory>
                          <resources>
                              <resource>
                                  <directory>${basedir}/../app-client/dist</directory >
                              </resource>
                          </resources>
                      </configuration>
                  </execution>
            </executions>
        </plugin>

请注意,我们需要在&lt;directory&gt;标签下使用..来匹配目录结构。

希望这对某人有所帮助。

【讨论】:

    猜你喜欢
    • 2019-09-20
    • 2016-07-14
    • 1970-01-01
    • 2015-05-24
    • 1970-01-01
    • 2015-06-21
    • 2023-03-08
    相关资源
    最近更新 更多