【问题标题】:How to disable spring security logging如何禁用弹簧安全日志记录
【发布时间】:2012-07-27 18:14:11
【问题描述】:

我将 Tomcat 用于 servlet 容器,我必须每天检查 catalina.out 日志以进行调试。但是当匿名用户尝试登录时,Spring Security 拦截器会抛出异常,它会淹没 catalina.out 日志文件。日志是这样的:

at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:603)
at java.lang.Thread.run(Thread.java:722)
Caused by: org.springframework.security.authentication.AuthenticationCredentialsNotFoundException: An Authentication object was not found in the SecurityContext
at org.springframework.security.access.intercept.AbstractSecurityInterceptor.credentialsNotFound(AbstractSecurityInterceptor.java:327)
at org.springframework.security.access.intercept.AbstractSecurityInterceptor.beforeInvocation(AbstractSecurityInterceptor.java:197)
at org.springframework.flex.security3.EndpointInterceptor.preProcess(EndpointInterceptor.java:97)
at org.springframework.flex.core.MessageInterceptionAdvice.invoke(MessageInterceptionAdvice.java:62)
at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:172)
at org.springframework.aop.framework.adapter.ThrowsAdviceInterceptor.invoke(ThrowsAdviceInterceptor.java:124)
... 52 more

如何在 Tomcat 中禁用 Spring Security 日志记录?

【问题讨论】:

    标签: tomcat logging spring-security


    【解决方案1】:

    当日志级别设置为 DEBUG 并且您的过滤器链中没有 AnonymousAuthenticationFilter 时,您将在日志中看到 AuthenticationCredentialsNotFoundException。

    见FAQ。

    所以我假设您在安全应用程序上下文中使用传统的 bean 配置,而不是命名空间配置。如果你想摆脱这个异常,你可以像documentation中描述的那样将anonymousAuthenticationFilter添加到你的应用程序上下文中。

    或者,您可以将日志级别设为

    org.springframework.security.level=INFO
    

    在这个question中提到的tomcat中。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2017-06-01
      • 2014-04-13
      • 2019-03-03
      • 2020-07-07
      • 2015-02-23
      • 2019-12-23
      • 1970-01-01
      相关资源
      最近更新 更多