【问题标题】:"401: Bad credentials" Basic authentication through url in Spring Boot“401:错误凭据”通过 Spring Boot 中的 url 进行基本身份验证
【发布时间】:2017-07-27 19:11:17
【问题描述】:

我正在尝试使用 Spring 安全性进行基本身份验证。我也想通过网址(用户名:密码@mysite.com)。当我执行这样的 http 请求时,授权标头设置正确,这也是我的 SecurityConfig:

 12 @Configuration
 13 @EnableGlobalMethodSecurity(prePostEnabled = true)
 14 @EnableWebSecurity
 15 public class SecurityConfig extends WebSecurityConfigurerAdapter {
 16 
 17   @Override
 18   protected void configure(HttpSecurity http) throws Exception {
 19     http.authorizeRequests()
 20       .antMatchers("/login").permitAll()
 21       .antMatchers("/admin/**").hasRole("ADMIN")
 22       .anyRequest().authenticated();
 23     http.httpBasic();
 24     http.csrf().disable();
 25   }
 26 
 27   @Autowired
 28   public void configureGlobal(AuthenticationManagerBuilder auth) throws Exception {
 29     auth.inMemoryAuthentication()
 30         .withUser("user").password("pwd1").roles("USER").and()
 31         .withUser("admin").password("pwd2").roles("ADMIN", "USER");
 32   }
 33 
 34 }

这是我的 AdminController:

 24 @PreAuthorize("hasRole('ADMIN')")
 25 @RequestMapping(value="/admin")
 26 @Controller
 27 public class AdminController {
154   @RequestMapping(value="/", method=RequestMethod.GET)
155   public  String admin(Model model) {
156     return Constants.ADMIN_TEMPLATE;
157   }
177 }

当我尝试提出如下请求时:

admin:pwd2@localhost:3000/admin

我收到“401:错误凭据”。为什么会这样? (我也尝试通过 restclient 使用 Authorization 标头发出请求,结果相同)

谢谢。

【问题讨论】:

    标签: spring authentication spring-security basic-authentication


    【解决方案1】:

    删除http.httpBasic();然后再试一次

    【讨论】:

      猜你喜欢
      • 2018-04-18
      • 2018-01-02
      • 2014-09-22
      • 1970-01-01
      • 1970-01-01
      • 2012-03-06
      相关资源
      最近更新 更多