【问题标题】:Authentication fails when add UsernamePasswordAuthenticationFilter添加 UsernamePasswordAuthenticationFilter 时身份验证失败
【发布时间】:2015-03-12 18:19:47
【问题描述】:

我正在使用 Spring Security 3.2.5。 Bellow 是我的安全配置类:


@Configuration
@EnableGlobalMethodSecurity(prePostEnabled = true)
@EnableWebMvcSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Autowired
    private AuthenticationProvider ap;
    @Autowired
    private UsernamePasswordAuthenticationFilter myFilter;


    @Override
    protected void configure(HttpSecurity http) throws Exception {
            http.authorizeRequests()
                    .anyRequest().authenticated()
                    .and()
                    .formLogin()
                    .permitAll()
                    .and()
            .httpBasic();
        http.addFilterAfter(myFilter, UsernamePasswordAuthenticationFilter.class);
    }

    @Autowired
    public void configureGlobal(AuthenticationProvider ap, AuthenticationManagerBuilder amb) throws Exception {
        amb.authenticationProvider(ap);
    }

}

这是我声明的一些 bean:

@Bean
public UsernamePasswordAuthenticationFilter restApiAuthenticationFilter() {
    UsernamePasswordAuthenticationFilter filter = new UsernamePasswordAuthenticationFilter();
    filter.setAuthenticationManager(authenticationManager());
    filter.setRequiresAuthenticationRequestMatcher(new AntPathRequestMatcher("/login", "POST"));
    return filter;
}

@Bean
public AuthenticationManager authenticationManager() {
    List<AuthenticationProvider> providers = new LinkedList<AuthenticationProvider>();
    providers.add(daoAuthenticationProvider());
    ProviderManager pm = new ProviderManager(providers);
    return pm;
}

现在的问题是,如果我将UsernamePasswordAuthenticationFilter添加到spring security,则authentication会失败,否则就可以了。关于这个问题有什么建议吗? 我在日志文件中得到了这个:

2015-01-14 16:03:55,548 [io-8080-exec-54] DEBUG ProviderManager - 使用 org.springframework.security.authentication.dao.DaoAuthenticationProvider 进行身份验证尝试

2015-01-14 16:03:55,557 [io-8080-exec-54] 调试 EntityManagerInvocationHandler - 为共享 EntityManager 调用创建新的 EntityManager

2015-01-14 16:03:55,672 [io-8080-exec-54] 调试 EntityManagerFactoryUtils - 关闭 JPA EntityManager

2015-01-14 16:03:55,772 [io-8080-exec-54] 调试 DaoAuthenticationProvider - 找不到用户“”

【问题讨论】:

标签: spring spring-security


【解决方案1】:

问题在于我的用户名和密码参数。我这样声明了 UsernamePasswordAuthenticationFilter bean,问题就解决了:

@Bean
public UsernamePasswordAuthenticationFilter restApiAuthenticationFilter() {
    UsernamePasswordAuthenticationFilter filter = new UsernamePasswordAuthenticationFilter();
    filter.setAuthenticationManager(authenticationManager());
    filter.setUsernameParameter("username");
    filter.setPasswordParameter("password");
    filter.setRequiresAuthenticationRequestMatcher(new AntPathRequestMatcher("/login", "POST"));
    return filter;
}

【讨论】:

  • 你为什么不直接使用formLogin呢?有什么区别,为什么需要 2 UsernamePasswordAuthenticationFilter。您当前的配置与 formLogin 所做的相同。
  • 我需要一个自定义的UsernamePasswordAuthenticaionFilter。只是为了简化而尝试过。谢谢。
猜你喜欢
  • 1970-01-01
  • 2018-11-02
  • 2020-09-23
  • 2014-01-24
  • 2016-09-05
  • 2017-11-27
  • 1970-01-01
相关资源
最近更新 更多