【问题标题】:Spring in-memory-authentication not workingSpring内存身份验证不起作用
【发布时间】:2015-09-09 01:59:04
【问题描述】:

我是 Spring 新手,并试图通过参考 docs.spring.io/spring-security/site/docs/4.0.1.RELEASE/reference/htmlsingle 来学习。但我遇到了问题。当我进入

用户名(鲍勃)

和

密码(bobspassword)

身份验证失败。

<?xml version="1.0" encoding="UTF-8"?>
<beans:beans xmlns="http://www.springframework.org/schema/security"
    xmlns:beans="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="http://www.springframework.org/schema/beans
           http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
           http://www.springframework.org/schema/security
           http://www.springframework.org/schema/security/spring-security-4.0.xsd">
    <http pattern="/css/**" security="none" />
    <http pattern="/app/login*" security="none"/>

    <http auto-config="true" use-expressions="true">
        <intercept-url pattern="/**" access="hasRole('ROLE_USER')" />
        <form-login login-page="/app/login" default-target-url="/home.htm"
            authentication-failure-url="/app/login?error" 

            always-use-default-target="true"
            username-parameter="username" password-parameter="password" />
        <logout logout-success-url="/app/login?logout"/>
        <csrf disabled="true"/>
    </http>

    <authentication-manager>
        <authentication-provider>
            <user-service>
                <user name="jimi"  password="password" authorities="ROLE_USER, ROLE_ADMIN" />
                <user name="bob" password="bobspassword" authorities="ROLE_USER" />
            </user-service>
        </authentication-provider>
    </authentication-manager>

</beans:beans>

登录页面的来源如下。

<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<%@ taglib uri="http://java.sun.com/jsp/jstl/core" prefix="c" %>
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Insert title here</title>
</head>
<body>

    <c:url value="/login" var="postUrl" />
    <form action="${postUrl}" method="post" enctype="multipart/form-data">
        <c:if test="${param.error != null}">     
        <p>Invalid username and password.</p>
        </c:if>
        <c:if test="${param.logout != null}">  
        <p>You have been logged out.</p>
        </c:if>
        <p>
            <label for="username">Username</label>
             <input type="text"
                id="username" name="username" /> 
        </p>
        <p>
            <label for="password">Password</label> <input type="password"
                id="password" name="password" /> 
        </p>

        <input type="text" 
        name="${_csrf.parameterName}"
            value="${_csrf.token}" />

        <button type="submit" class="btn">Log in</button>
    </form>
</body>
</html>

我正在使用 spring security 4.0.1.RELEASE,CSRF 被禁用。

【问题讨论】:

  • 你为什么提交表单为multipart/form-data而不是普通表单?
  • 你能用'jimi'用户名登录吗?
  • 谢谢你,Denium,由于其他一些错误,我进行了更改,忘记删除它。现在它正在工作

标签: java spring spring-mvc spring-security


【解决方案1】:

改变了

<form action="${postUrl}" method="post" enctype="multipart/form-data">

到

<form action="${postUrl}" method="post">

感谢M.Deinum 指出错误。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2019-07-18
    • 2017-02-13
    • 2012-10-04
    • 2021-12-19
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多