【问题标题】:Spring security logout handlingSpring安全注销处理
【发布时间】:2015-06-14 10:37:51
【问题描述】:

根据Spring Security 4.0.0文档:

4.2.4 注销处理

logout 元素通过导航到 特定的网址。 默认注销 URL 为 /logout,但您可以设置它 使用 logout-url 属性到其他东西。更多信息 其他可用属性可以在命名空间附录中找到。

但是,在文档中遵循安全设置后,URL /logout 不会显示注销页面。相反,它显示

相反,URL /login 可以正常工作。

以下是我的设置:

Spring 框架 4.1.6
Spring Security 4.0.0

Web.xml

<?xml version="1.0" encoding="UTF-8"?>
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xmlns="http://java.sun.com/xml/ns/javaee"
    xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_3_0.xsd"
    version="3.0">
    <display-name>Test8</display-name>
    <welcome-file-list>
        <welcome-file>index.html</welcome-file>
        <welcome-file>index.htm</welcome-file>
        <welcome-file>index.jsp</welcome-file>
        <welcome-file>default.html</welcome-file>
        <welcome-file>default.htm</welcome-file>
        <welcome-file>default.jsp</welcome-file>
    </welcome-file-list>

    <filter>
        <filter-name>springSecurityFilterChain</filter-name>
        <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
    </filter>

    <filter-mapping>
        <filter-name>springSecurityFilterChain</filter-name>
        <url-pattern>/*</url-pattern>
    </filter-mapping>

    <listener>
        <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class>
    </listener>

    <context-param>
        <param-name>contextConfigLocation</param-name>
        <param-value>/WEB-INF/security-config.xml</param-value>
    </context-param>


</web-app>

安全配置.xml

<?xml version="1.0" encoding="UTF-8"?>
<beans:beans xmlns="http://www.springframework.org/schema/security"
    xmlns:beans="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="http://www.springframework.org/schema/beans
           http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
           http://www.springframework.org/schema/security
           http://www.springframework.org/schema/security/spring-security.xsd">
    <http>
        <intercept-url pattern="/**" access="hasRole('USER')" />
        <form-login />
        <logout />
    </http>

    <authentication-manager>
        <authentication-provider>
            <user-service>
                <user name="aaa" password="111" authorities="ROLE_USER, ROLE_ADMIN" />
                <user name="bbb" password="222" authorities="ROLE_USER" />
            </user-service>
        </authentication-provider>
    </authentication-manager>

</beans:beans>

【问题讨论】:

标签: spring spring-security


【解决方案1】:

Spring security 自动启用 csrf,它会自动禁用 GET 注销。 您可以通过在 &lt;http&gt; 中设置 &lt;csrf disabled="true"/&gt; 或仅使用 POST 来禁用 csrf 保护来解决此问题。

见http://docs.spring.io/spring-security/site/docs/4.0.1.RELEASE/reference/htmlsingle/#csrf-logout

【讨论】:

    【解决方案2】:

    简单的,把下面的代码放到你想要注销的jsp中-

    <c:url var="logoutUrl" value="/j_spring_security_logout" />
        <form action="${logoutUrl}" id="logout" method="post">
            <input type="hidden" name="${_csrf.parameterName}"
                value="${_csrf.token}" />
        </form>
        <a href="#" onclick="document.getElementById('logout').submit();">Logout</a>
    

    bean配置文件中的对应入口-

    <security:logout logout-url="/j_spring_security_logout" logout-success-url="/whateverPageYouWant" invalidate-session="true" />
    

    -这对我来说适用于 spring-security-4.*

    【讨论】:

    • 您好,如果我要从 AngularJS 等任何 SPA 中注销用户,该怎么办?
    【解决方案3】:
    @Configuration
    @EnableWebSecurity
    public class SecurityConfig extends WebSecurityConfigurerAdapter {
    
      @Override
      protected void configure(HttpSecurity http) throws Exception {
       //...
       http.logout().logoutRequestMatcher(new AntPathRequestMatcher("/logout"));
      }
    }
    

    【讨论】:

      【解决方案4】:
      1. 注销 url 是“/j_spring_security_logout”,因此请相应地编辑您的视图
      2. CSRF 默认启用,这将要求每个 POST 请求(即注销)都有一个 CSRF 令牌。因此,要么禁用 CSRF(我不会推荐),要么在表单中使用上述注销 url 和带有 CSRF 令牌的隐藏输入框住注销

      【讨论】:

        【解决方案5】:

        请注意,没有“注销页面”。 /logout 是 Spring 的端点,它让 Spring 知道应用程序要求注销用户,因此它调用特定的处理程序。

        用户注销后,Spring 重定向到另一个页面,您可以在 XML 中配置“默认目标”。

        【讨论】:

          【解决方案6】:

          添加到 Spring Security:

          <logout
           logout-success-url="/anonymous.html"
           logout-url="/perform_logout"
           delete-cookies="JSESSIONID" />
          

          在http标签下

          【讨论】:

            【解决方案7】:

            使用 Spring security 4.2.13,我设法通过表单提交(POST 方法)而不是使用链接导航到注销 URL 来完成这项工作。

            我将&lt;p&gt;&lt;a href="&lt;c:url value='/logout'/&gt;"&gt;Log out&lt;/a&gt;&lt;/p&gt; 替换为

            <form name='f' action='${pageContext.request.contextPath}/logout' method='POST'>
            <input name="logout" type="submit" value="Log out" />
            <input name="${_csrf.parameterName}" type="hidden"
                value="${_csrf.token}" />
            </form>
            

            在我的视图层,这是一个 JSP 页面。这样,您将获得一个按钮而不是链接。 (在较早的 Spring 版本中,默认注销 URL 是“/j_spring_security_logout”。)

            【讨论】:

              猜你喜欢
              • 2014-08-23
              • 2015-10-05
              • 2014-05-01
              • 2023-04-05
              • 1970-01-01
              • 2011-10-19
              • 2011-03-07
              • 2011-06-13
              • 2014-11-11
              相关资源
              最近更新 更多