【发布时间】:2015-03-12 18:19:47
【问题描述】:
我正在使用 Spring Security 3.2.5。 Bellow 是我的安全配置类:
@Configuration
@EnableGlobalMethodSecurity(prePostEnabled = true)
@EnableWebMvcSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {
@Autowired
private AuthenticationProvider ap;
@Autowired
private UsernamePasswordAuthenticationFilter myFilter;
@Override
protected void configure(HttpSecurity http) throws Exception {
http.authorizeRequests()
.anyRequest().authenticated()
.and()
.formLogin()
.permitAll()
.and()
.httpBasic();
http.addFilterAfter(myFilter, UsernamePasswordAuthenticationFilter.class);
}
@Autowired
public void configureGlobal(AuthenticationProvider ap, AuthenticationManagerBuilder amb) throws Exception {
amb.authenticationProvider(ap);
}
}
这是我声明的一些 bean:
@Bean
public UsernamePasswordAuthenticationFilter restApiAuthenticationFilter() {
UsernamePasswordAuthenticationFilter filter = new UsernamePasswordAuthenticationFilter();
filter.setAuthenticationManager(authenticationManager());
filter.setRequiresAuthenticationRequestMatcher(new AntPathRequestMatcher("/login", "POST"));
return filter;
}
@Bean
public AuthenticationManager authenticationManager() {
List<AuthenticationProvider> providers = new LinkedList<AuthenticationProvider>();
providers.add(daoAuthenticationProvider());
ProviderManager pm = new ProviderManager(providers);
return pm;
}
现在的问题是,如果我将UsernamePasswordAuthenticationFilter添加到spring security,则authentication会失败,否则就可以了。关于这个问题有什么建议吗?
我在日志文件中得到了这个:
2015-01-14 16:03:55,548 [io-8080-exec-54] DEBUG ProviderManager - 使用 org.springframework.security.authentication.dao.DaoAuthenticationProvider 进行身份验证尝试
2015-01-14 16:03:55,557 [io-8080-exec-54] 调试 EntityManagerInvocationHandler - 为共享 EntityManager 调用创建新的 EntityManager
2015-01-14 16:03:55,672 [io-8080-exec-54] 调试 EntityManagerFactoryUtils - 关闭 JPA EntityManager
2015-01-14 16:03:55,772 [io-8080-exec-54] 调试 DaoAuthenticationProvider - 找不到用户“”
【问题讨论】:
-
@M.Deinum 删除了您链接的那个。这篇文章解决了这两个问题。