【问题标题】:How do I add an Access Denied Handler in spring-security-javaconfig如何在 spring-security-javaconfig 中添加拒绝访问处理程序
【发布时间】:2013-08-11 20:50:14
【问题描述】:

我正在使用 spring-security-javaconfig 库来实现 spring 安全性。如果我使用的是 xml 配置文件,我会使用类似这样的东西来定义一个自定义的拒绝访问页面:

<http auto-config="true">
    <intercept-url pattern="/admin*" access="ROLE_ADMIN" />
    <access-denied-handler ref="accessDeniedHandler"/>
</http>

到目前为止,这是我的安全配置类:

@Configuration
@EnableWebSecurity
public class SecurityConfigurator extends WebSecurityConfigurerAdapter {

    @Override
    protected void registerAuthentication(AuthenticationManagerBuilder auth)
            throws Exception {
        auth.inMemoryAuthentication().withUser("user").password("password").roles("USER");
        auth.inMemoryAuthentication().withUser("admin").password("password").roles("ADMIN");

    }

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.authorizeUrls().antMatchers( "/admin").hasRole("ADMIN");
    }
}

【问题讨论】:

  • 请注意,多次调用 inMemoryAuthentication() 实际上是创建多个 InMemoryUserDetailsManager 实例。如果您不想将所有内容都链接起来,则可以将对 auth.inMemoryAuthentication() 的调用存储在变量中。或者您可以使用方法链接作为示例github.com/SpringSource/spring-security-javaconfig/blob/master/… 的大纲

标签: java spring-security spring-java-config


【解决方案1】:

我想这应该可以解决问题:

HttpSecurity http = ...
http.exceptionHandling().accessDeniedHandler(myAccessDeniedHandler);

【讨论】:

    猜你喜欢
    • 2013-10-31
    • 2011-12-26
    • 2015-08-07
    • 2012-02-29
    • 1970-01-01
    • 1970-01-01
    • 2013-04-29
    • 1970-01-01
    • 2015-11-13
    相关资源
    最近更新 更多