【问题标题】:grails and spring security core plugin - authenticateion from clientgrails 和 spring 安全核心插件 - 来自客户端的身份验证
【发布时间】:2011-12-17 01:32:55
【问题描述】:

我开始使用带有 grails 的 spring-security-core-1.1.3 插件。 我的身份验证应用程序向服务器发送请求:

def authSomeAction = {
    def req = ...//http requet here
    if(req.contains("yes")){
       render "There is such user"
    }else{
       render "There is no such user"
    }
}

只有在客户端创建了用户时,我才能使用 SpringSecurityUtils.reauthenticate(username, password) 方法成功进行身份验证

任何人都可以详细帮助我了解我必须如何实施 插件在客户端工作(没有数据库)...?

【问题讨论】:

    标签: grails spring-security grails-plugin


    【解决方案1】:

    我对 Grails 很陌生,所以我显然可能不太了解,但我怀疑您的问题可能与您在创建用户时对密码进行编码的方式有关。当您使用“客户端”创建用户时,您的做法是否与您使用的其他方法相同?

    例如,当我第一次开始使用 spring-security-ui 插件时,我使用捆绑的实用程序创建了用户,他们都无法登录。如果我理解正确,spring-security-core 是从spring-security-ui,它将控制器中的密码编码需求转移到了用户本身。例如,在该插件附带的 spring-security-ui UserController.save() 中,会发生这种情况:

    if (params.password) {
        String salt = saltSource instanceof NullSaltSource ? null : params.username
        user.password = springSecurityService.encodePassword(params.password, salt)
    }
    

    但是我的 User 类有这个(直接来自 s2 插件示例)

    def beforeInsert() {
        encodePassword()
    }
    
    def beforeUpdate() {
        if (isDirty('password')) {
            encodePassword()
        }
    }
    
    protected void encodePassword() {
        password = springSecurityService.encodePassword(password)
    }
    

    由于我的 User 类自己管理编码,因此进行了双重编码,导致使用它创建的登录失败。您的应用程序中是否会发生类似的情况?当您在客户端以外的地方创建用户时,您的编码方式是否相同?

    【讨论】:

    • Dave Shuck 感谢您的回复...是的,我在“客户端”编码密码我对密码编码没有问题,我只考虑如何在客户端组织插件工作..
    猜你喜欢
    • 2013-01-08
    • 2012-11-30
    • 2015-01-10
    • 2016-04-16
    • 2012-03-18
    • 1970-01-01
    • 2013-08-19
    • 2013-07-20
    • 2015-01-10
    相关资源
    最近更新 更多