【发布时间】:2021-11-20 06:53:48
【问题描述】:
我想在我的家庭控制器中使用下面箭头指示的行中使用 Spring Boot 安全性以编程方式注销。
我尝试过的事情: 我在看this 文章,我不清楚 /logout 是如何以及何时调用的?我不希望用户使用按钮注销或转到注销端点。
我还观看了 YT 视频 here,但它再次使用了 /logout 的表单操作。它使用注销 URL 和注销成功 URL。
我可以使用 logoutSuccessHandler 清除 cookie,但我不知道如何以编程方式调用注销,然后调用 logoutSuccesHandler。
@RequestMapping("/")
public String index(Principal principal) throws IsimConnectionException {
Authentication authentication = (Authentication) principal;
if ((authentication.getPrincipal() != null) && (authentication.isAuthenticated())) {
String shortname = (String)authentication.getPrincipal();
sessionScopedLdapUser.shortname(shortname);
if (isimConn.hasid()) {
**** ---> here I would like to logout and clear cookies
return "hasid";
} else {
return "needsLinking";
}
}
return "index";
}
这是我的网络安全配置类:
@Configuration
@EnableWebSecurity
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
private static final Logger log = LoggerFactory.getLogger(WebSecurityConfig.class);
@Autowired
private LdapAuthenticationProvider authProvider;
/**
* Defines the web based security configuration.
*
* @param http It allows configuring web based security for specific http requests.
* @throws Exception
*/
@Override
protected void configure(HttpSecurity http) throws Exception {
http
.authorizeRequests()
.antMatchers("/css/**", "/js/**", "/images/**", "/sw.js").permitAll()
.anyRequest().fullyAuthenticated()
.and()
.formLogin()
.loginPage("/login") //custom login page
.permitAll() // permit everyone the /login page
.and()
.logout()
.permitAll()
.logoutSuccessHandler(new HttpStatusReturningLogoutSuccessHandler(HttpStatus.OK));
}
/**
* Sets a custom authentication provider.
*
* @param auth SecurityBuilder used to create an AuthenticationManager.
* @throws Exception
*/
@Override
protected void configure(AuthenticationManagerBuilder auth) throws Exception {
auth.authenticationProvider(authProvider);
}
}
【问题讨论】:
-
嗨@Toerktumlare,正如我在上面的代码中在我的问题中描述的那样,根据我的家庭控制器中的业务逻辑,我决定何时注销用户并使所有cookies无效。