【问题标题】:Spring AOP and apache shiro configuration.Annotations not been scannedSpring AOP 和 apache shiro 配置。未扫描注释
【发布时间】:2011-10-15 02:58:31
【问题描述】:

我一直在努力解决需要 AOP 知识的配置。

我必须承认 AOP 是我试图获得一段时间但没有成功的那部分。 似乎我的 shiro 注释没有被扫描,因此被忽略了。

我尝试过使用 shiro 1.1.0+ maven3+spring 3.0.5.RELEASE,休眠 3.6.1.Final 和 ZK 5.0.6。 我让我的 hibernaterealm 工作,与数据库交谈,我让身份验证工作,我成功(我相信)加载了角色和权限。

所以为了测试授权方面,我的代码中有这样的地方:

  Subject currentUser = SecurityUtils.getSubject();
   if (!currentUser.isPermitted("businessaccount:list")) {
    throw new AuthorizationException("User not authorized");
  }

而且效果很好。
所以我知道我的权限已加载。我使用注释将它放在实现类中对我来说很方便,因为我不打算首先将接口与扩展 ZK GenericForwardController 的控制器类一起使用。

我已经看到了这个bug,并且我决定尝试使用一个带有@RequiresPersmissions on 方法的接口。

显然它仍然无法正常工作,因为它允许访问未经授权的主题。我的日志中没有错误。也许我做错了这里是代码的 sn-p:

@Component("layouteventhandler")
public class LayoutEventHandlerImpl extends GenericForwardComposer implements     LayoutEventHandler {

Logger logger = Logger.getLogger(LayoutEventHandlerImpl.class);
Menuitem logout;

//...


@Override
public void onClick$pAccounts() {
    try {
        execution.sendRedirect("/accounts/personal/list");
    } catch (Exception ex) {
        logger.info("Error redirecting to personal accounts", ex);
    }
}


@Override
public void onClick$bAccounts() {
  try {
        execution.sendRedirect("/accounts/business/list");
    } catch (Exception ex) {
        logger.info("Error redirecting to business accounts", ex);
    }
}
//.....
} 

它的界面吧:

public interface LayoutEventHandler {

@RequiresPermissions(value="personalaccount:list")
public void onClick$pAccounts();

@RequiresPermissions(value="businessaccount:list")
public void onClick$bAccounts();
//.....

 }

这是我的 shiro 应用程序上下文

<bean id="hibernateRealm" class="com.personal.project.admin.webapp.security.DatabaseRealm" />
<bean id="securityManager" class="org.apache.shiro.web.mgt.DefaultWebSecurityManager">
    <property name="realm" ref="hibernateRealm" />
</bean>

<bean id="lifecycleBeanPostProcessor" class="org.apache.shiro.spring.LifecycleBeanPostProcessor" />

<bean class="org.springframework.aop.framework.autoproxy.DefaultAdvisorAutoProxyCreator"
      depends-on="lifecycleBeanPostProcessor">
 <!--          <property name="proxyTargetClass" value="true" />-->
</bean>
<bean class="org.apache.shiro.spring.security.interceptor.AuthorizationAttributeSourceAdvisor">
    <property name="securityManager" ref="securityManager"/>
</bean>

<!-- Secure Spring remoting:  Ensure any Spring Remoting method invocations can be associated
     with a Subject for security checks. -->
<bean id="secureRemoteInvocationExecutor" class="org.apache.shiro.spring.remoting.SecureRemoteInvocationExecutor">
    <property name="securityManager" ref="securityManager"/>
</bean>
<!-- ... -->

里面有什么我应该做的吗?感谢您的阅读和帮助

【问题讨论】:

  • 您能提供更多信息吗?您的 Shiro 注释如何被忽略?它们在您将它们连接到的类中是否为空?
  • 您好,我已按您的要求添加了更多详细信息。谢谢
  • 这还有兴趣吗?您在使用中是否有其他 AOP 方面(例如事务处理)?
  • 是的,请在我的方法服务之上使用@transactional
  • 你知道了吗。我也有同样的问题

标签: spring spring-aop shiro


【解决方案1】:

我在运行两个 spring 上下文时遇到了类似的问题。有一个父根上下文定义了数据库、服务、安全和非 SpringMVC Web bean,还有一个 Spring MVC REST api 的子 Web 上下文,其中包含我要代理的控制器。每个上下文的配置是类路径扫描单独的包。

在这种情况下,请确保在子 Web 上下文中定义了 DefaultAdvisorAutoProxyCreator 和 AuthorizationAttributeSourceAdvisor bean(即扫描了类路径的 Rest Controller),因为在父上下文中定义它们不起作用(关于DefaultAdvisorAutoProxyCreate 事后对此非常清楚!)。

发布此内容以防其他人遇到相同问题。

【讨论】:

    【解决方案2】:

    要扩展 Ryan Stewart 的答案,您需要添加

    @Scope(proxyMode = ScopedProxyMode.TARGET_CLASS)
    

    到实现类(不是接口)并将 Shiro 注释移动到它。

    【讨论】:

      【解决方案3】:

      我不认识 Shiro,但我猜您已经在实现接口的 bean 类上添加了注释,然后您为安全、事务和/或其他东西代理它们。发生这种情况时,返回的对象是 JDK 动态代理,它不是 bean 的具体类的实例,只是它实现的接口的实例。因此,任何依赖于具体类中注解的注解扫描都不会找到它们。

      【讨论】:

        猜你喜欢
        • 2017-06-10
        • 2015-02-17
        • 1970-01-01
        • 1970-01-01
        • 2014-09-13
        • 2012-01-24
        • 2018-09-03
        • 2015-01-10
        • 1970-01-01
        相关资源
        最近更新 更多