【问题标题】:Spring Security Method Security Interceptor not picking up authenticationManagerSpring Security Method Security Interceptor 没有获取 authenticationManager
【发布时间】:2012-02-03 19:03:03
【问题描述】:

我正在尝试编写自定义方法安全拦截器。但是,它没有使用我在安全上下文中添加到 bean 属性的身份验证管理器,并且在我检查身份验证管理器是否存在时返回 null。谁能解释为什么不使用身份验证管理器 bean 属性?我在 WebSphere 7.0 上使用 spring security 3.0.5

这是包含方法拦截器的bean

<beans:bean id="methodInterceptor"
    class="bigbank.security.CustomMethodSecInterceptor">
    <beans:property name="authenticationManager" ref="authenticationManager" />
    <beans:property name="accessDecisionManager" ref="universalAccessDecisionManager" />
    <beans:property name="securityMetadataSource" ref="tspmMethodSecurityMetaData" />

这是我的方法安全拦截器

public class CustomMethodSecInterceptor extends MethodSecurityInterceptor {

private static final Log logger = LogFactory
        .getLog(WebSphere2SpringSecurityPropagationInterceptor.class);
private AuthenticationManager authenticationManager = null;
private AuthenticationDetailsSource authenticationDetailsSource = new WebSpherePreAuthenticatedAuthenticationDetailsSource();
private final WASUsernameAndGroupsExtractor wasHelper;

public CustomMethodSecInterceptor() {
    wasHelper = new DefaultWASUsernameAndGroupsExtractor();
}

@Override
public Object invoke(MethodInvocation mi) throws Throwable {
    try {
        logger.debug("Performing Spring Security authentication with WebSphere credentials");
        System.out.println("@@going through ss authentication");
        authenticateSpringSecurityWithWASCredentials();
        InterceptorStatusToken token = super.beforeInvocation(mi);

        logger.debug("Proceeding with method invocation");
        Object result = mi.proceed();
        return super.afterInvocation(token, result);

    } finally {
        logger.debug("Clearing Spring Security security context");
        SecurityContextHolder.clearContext();
    }
}

private void authenticateSpringSecurityWithWASCredentials() {
    Assert.notNull(authenticationManager); // This is where the error is coming up
    Assert.notNull(authenticationDetailsSource);

    String userName = wasHelper.getCurrentUserName();
    if (logger.isDebugEnabled()) {
        logger.debug("Creating authentication request for user " + userName);
    }
    PreAuthenticatedAuthenticationToken authRequest = new PreAuthenticatedAuthenticationToken(
            userName, "N/A");
    authRequest.setDetails(authenticationDetailsSource.buildDetails(null));
    if (logger.isDebugEnabled()) {
        logger.debug("Authentication request for user " + userName + ": "
                + authRequest);
    }
    Authentication authResponse = authenticationManager
            .authenticate(authRequest);
    if (logger.isDebugEnabled()) {
        logger.debug("Authentication response for user " + userName + ": "
                + authResponse);
    }
    SecurityContextHolder.getContext().setAuthentication(authResponse);
}

public void setAuthenticationManager(
        AuthenticationManager authenticationManager) {
    this.authenticationManager = authenticationManager;
}

}

这是错误:

Caused by: java.lang.IllegalArgumentException: An AuthenticationManager is required
at org.springframework.util.Assert.notNull(Assert.java:112)
at org.springframework.security.access.intercept.AbstractSecurityInterceptor.afterPropertiesSet(AbstractSecurityInterceptor.java:118)
at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.invokeInitMethods(AbstractAutowireCapableBeanFactory.java:1469)
at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.initializeBean(AbstractAutowireCapableBeanFactory.java:1409)
... 119 more

【问题讨论】:

    标签: authentication spring-security websphere-7


    【解决方案1】:

    你已经重写了setAuthenticationManager方法,所以当它被Spring调用注入AuthenticationManager时,它并没有在AbstractSecurityInterceptor中设置相应的字段。

    由于基类包含此属性的 getter,因此您最好删除字段和 setter 方法,并仅使用 getter 访问代码中的身份验证管理器。

    【讨论】:

      猜你喜欢
      • 2011-01-20
      • 2015-12-28
      • 2015-05-30
      • 2020-04-29
      • 2022-06-13
      • 2011-12-15
      • 1970-01-01
      • 2020-10-27
      • 2015-09-30
      相关资源
      最近更新 更多