【问题标题】:Spring Security intercept URL not working with custom UserDetails objectSpring Security 拦截 URL 不适用于自定义 UserDetails 对象
【发布时间】:2017-01-31 01:54:13
【问题描述】:

我对 Spring Security 很陌生,所以请耐心等待。如果有人可以指导我,我愿意接受让这个问题更具体的建议。

我的问题是我在 Spring 安全性中有一个拦截 URL 配置,但即使用户具有必要的角色,它也总是重定向到拒绝访问页面。这是我的 Spring 安全配置:

<?xml version="1.0" encoding="UTF-8"?>
<beans:beans xmlns="http://www.springframework.org/schema/security"
    xmlns:beans="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="http://www.springframework.org/schema/beans
    http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
    http://www.springframework.org/schema/security
    http://www.springframework.org/schema/security/spring-security-4.1.xsd">

    <!-- enable use-expressions -->
    <http auto-config="true" use-expressions="true">

        <intercept-url pattern="/admin/**" access="hasRole('ROLE_ADMIN')" />

        <!-- access denied page -->
        <access-denied-handler error-page="/403" />

        <session-management invalid-session-url="/login"
            session-fixation-protection="newSession">
            <concurrency-control max-sessions="1"
                error-if-maximum-exceeded="true" />
        </session-management>

        <form-login login-page="/login" authentication-failure-url="/login?error"
            username-parameter="emailId" password-parameter="pwd" />
        <logout logout-success-url="/login?logout" delete-cookies="JSESSIONID" />
        <csrf token-repository-ref="tokenRepository" />
    </http>

    <authentication-manager>
        <authentication-provider ref="customAuthenticationProvider" />
    </authentication-manager>

</beans:beans>

通过我的研究,我觉得上述配置没有任何问题,但由于我使用的是自定义 UserDetails 对象,这可能是个问题。这是 POJO:

public class CustomUser implements UserDetails {

    private static final long serialVersionUID = 1L;
    private String userID;
    private String emailId;
    private String password;
    private boolean enabled = true;
    private boolean accountNonExpired = true;
    private boolean credentialsNonExpired = true;
    private boolean accountNonLocked = true;
    private List<Role> authorities;

    @Override
    public List<Role> getAuthorities() {
        return authorities;
    }
    //other setters and getters
}

角色类:

public class Role implements GrantedAuthority {

    private static final long serialVersionUID = 1L;
    private String name;

    public String getName() {
        return name;
    }

    public void setName(String name) {
        this.name = name;
    }

    public String getAuthority() {
        return this.name;
    }
}

我还有一个自定义 UserDAO 类,用于填充 CustomUser POJO,并且我已验证设置值没有问题。

这是我的原则(如日志中所写):

Principal: CustomUser [userID=user1, emailId=test@test.com, password=pwd, enabled=true, accountNonExpired=true, credentialsNonExpired=true, authorities=[Role [name=ADMIN]]];

页面总是被拒绝的原因是什么?

感谢您花时间阅读整篇文章:)

【问题讨论】:

    标签: java spring-mvc spring-security


    【解决方案1】:

    已更改

    <intercept-url pattern="/admin/**" access="hasRole('ROLE_ADMIN')" />
    

    到

    <intercept-url pattern="/admin/**" access="hasRole('ADMIN')" />
    

    编辑

    如果以前的解决方案不起作用,请尝试这种方式。

    在您的角色中查看它返回“ADMIN”并且您期望“ROLE_ADMIN”

    将角色名称更改为表格

    “ADMIN”到“ROLE_ADMIN”

    【讨论】:

    • "ROLE_" 是 Spring 安全添加到所有角色 AFAIK 的预定义前缀。但是,我确实尝试了您的建议,但没有帮助。问题依然存在。
    • 你是认真的吗?您更改了 3 次答案,第三次更改了我发布的答案。来吧,伙计!
    • 你知道吗?我将成为更大的人,给你这个答案并删除我的答案以避免冗余。如果这篇文章对其他人有帮助,那么答案是来自我还是你并不重要。享受您的新积分。
    猜你喜欢
    • 1970-01-01
    • 2012-01-29
    • 2014-12-14
    • 1970-01-01
    • 2012-08-15
    • 2013-06-04
    • 1970-01-01
    • 2011-07-12
    • 2019-08-22
    相关资源
    最近更新 更多