【问题标题】:Spring MVC - How to support both http and https at the same time in Spring MVC web projectSpring MVC - 如何在 Spring MVC web 项目中同时支持 http 和 https
【发布时间】:2017-07-19 09:21:51
【问题描述】:

如何在部署在 tomcat7(和 8)上的 Spring MVC Web 项目中同时支持 HTTP 和 https。我已经在 Tomcat 级别配置了所有东西。

如果我通过扩展 WebSecurityConfigurerAdapter 使用以下代码,HTTPS 就可以工作

.and().requiresChannel().anyRequest().requiresSecure()

但它不允许 HTTP,我需要 同时支持 HTTP 和 HTTPS 相同的端点 示例:

http://example.com/hello-world
https://example.com/hello-world

【问题讨论】:

  • 看here
  • 我同意@Zico:在反向代理级别完成 HTTPS 处理的正确方法。这样一来,HTTP 和 HTTPS 都默认接受所有内容。如果你只想对一些更敏感的 URL 要求 HTTPS,你可以看看我的这个post。

标签: java spring spring-mvc ssl


【解决方案1】:

将您的 https 配置从 .anyRequest() 更改为特定的安全 URL,例如。 http.requiresChannel().antMatchers("/secure*").requiresSecure(); 并将其余部分设为 Insecure 如下http.requiresChannel().anyRequest().requiresInsecure(); 将解决该问题。

这指示 Spring 对所有未明确配置为使用 HTTPS 的请求使用 HTTP。

【讨论】:

  • 其实我想同时支持http和https的同一个端点
  • 我认为这在逻辑上是不可能的,如果你创建一个端点requireSecure(),它就不能被不安全地访问(即通过http)。
猜你喜欢
  • 2016-05-13
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2014-11-29
  • 2011-08-19
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多