【问题标题】:Use spring security in jsf project在jsf项目中使用spring security
【发布时间】:2015-03-29 19:39:21
【问题描述】:

我想在我的 jsf 项目中使用 Spring Security,但使用最少的 xml 配置。但是当我使用基于注释的配置时:

@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {

@Autowired
public void configureGlobal(AuthenticationManagerBuilder auth) throws Exception {
    auth.inMemoryAuthentication().withUser("user").password("123456").roles("USER");
}

@Override
protected void configure(HttpSecurity http) throws Exception {

    http.authorizeRequests()
        .anyRequest().access("hasRole('ROLE_USER')")
        .and()
            .formLogin()
            .and()
            .httpBasic();

}
}

我收到此错误:

org.springframework.context.ApplicationContextException: Custom context class [com.spring.SecurityConfig] is not of type [org.springframework.web.context.ConfigurableWebApplicationContext]

安全配置类应该实现 ConfigurableWebApplicationContext 吗?如果是的话怎么做?如果没有,解决办法是什么?

根据 spring 教程,spring security 只需要 2 个类,一个是我在上面粘贴的,另一个是:

public class SecurityWebApplicationInitializer extends
    AbstractSecurityWebApplicationInitializer {

public SecurityWebApplicationInitializer() {
    super(SecurityConfig.class);
}
}

还有我的 web.xml:

<?xml version="1.0" encoding="UTF-8"?>
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://java.sun.com/xml/ns/javaee"
xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_3_0.xsd"
id="WebApp_ID" version="3.0">
<display-name>OnlineLibrary</display-name>
<servlet>
    <servlet-name>Faces Servlet</servlet-name>
    <servlet-class>javax.faces.webapp.FacesServlet</servlet-class>
    <load-on-startup>1</load-on-startup>
</servlet>

<servlet-mapping>
    <servlet-name>Faces Servlet</servlet-name>
    <url-pattern>*.html</url-pattern>
    <url-pattern>*.xhtml</url-pattern>
</servlet-mapping>
<welcome-file-list>
    <welcome-file>index.html</welcome-file>
    <welcome-file>index.htm</welcome-file>
    <welcome-file>index.jsp</welcome-file>
    <welcome-file>default.html</welcome-file>
    <welcome-file>default.htm</welcome-file>
    <welcome-file>default.jsp</welcome-file>
</welcome-file-list>


<filter>
    <filter-name>springSecurityFilterChain</filter-name>
    <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
</filter>

<filter-mapping>
    <filter-name>springSecurityFilterChain</filter-name>
    <url-pattern>/*</url-pattern>
</filter-mapping>

<listener>
    <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class>
</listener>
<context-param>
    <param-name>contextClass</param-name>
    <param-value>com.spring.SecurityConfig</param-value>
</context-param>
</web-app>

我将这些库用于我的项目: jsf 2.2

spring-security-3.2.4.RELEASE

还有其他 Spring 所需的库,我在 tomcat 7 上运行我的项目。 感谢您提供有用的答案。

【问题讨论】:

    标签: jsf spring-security


    【解决方案1】:

    可能是,您忘记创建一个必须定义的新类:

    @EnableWebMvc
    @Configuration
    @Import({ SecurityConfig.class })
    public class AppConfig {
    
        @Bean
        public InternalResourceViewResolver viewResolver() {
            ...
        }
    }
    

    因为你不使用 spring mvc,所以这个链接可能对你有帮助: http://laabidi-raissi.blogspot.fr/2013/07/jsf-2-spring-security-integration-with.html 他在 applicationContext.xml 中定义了 bean,但您可以通过一些提示找到丢失的部分。

    【讨论】:

    • 但是我不需要Spring web mvc,因为我使用的是jsf。我唯一想做的就是为 jsf 项目添加 spring 安全功能。还有一个例外是关于 SecurityConfig 类,据说它应该实现 org.springframework.web.context.ConfigurableWebApplicationContext 接口。
    • 你能显示你的 pom.xml 和你的主要配置类吗?
    • Web 应用程序上下文是您在 Web 应用程序中加载 Spring bean 所需要的东西。我的错,如果我的解决方案不好。但是您搜索的解决方案是“如何加载我的安全配置”,因此搜索的方式可能在您的 web.xml 中,可能缺少侦听器或类似的东西。如果我有更多信息,我会完成我的回答
    猜你喜欢
    • 2018-12-06
    • 2014-11-17
    • 2012-11-26
    • 1970-01-01
    • 2019-12-24
    • 2019-12-22
    • 2015-01-28
    • 2014-11-29
    • 2016-09-01
    相关资源
    最近更新 更多