【发布时间】:2017-07-27 19:11:17
【问题描述】:
我正在尝试使用 Spring 安全性进行基本身份验证。我也想通过网址(用户名:密码@mysite.com)。当我执行这样的 http 请求时,授权标头设置正确,这也是我的 SecurityConfig:
12 @Configuration
13 @EnableGlobalMethodSecurity(prePostEnabled = true)
14 @EnableWebSecurity
15 public class SecurityConfig extends WebSecurityConfigurerAdapter {
16
17 @Override
18 protected void configure(HttpSecurity http) throws Exception {
19 http.authorizeRequests()
20 .antMatchers("/login").permitAll()
21 .antMatchers("/admin/**").hasRole("ADMIN")
22 .anyRequest().authenticated();
23 http.httpBasic();
24 http.csrf().disable();
25 }
26
27 @Autowired
28 public void configureGlobal(AuthenticationManagerBuilder auth) throws Exception {
29 auth.inMemoryAuthentication()
30 .withUser("user").password("pwd1").roles("USER").and()
31 .withUser("admin").password("pwd2").roles("ADMIN", "USER");
32 }
33
34 }
这是我的 AdminController:
24 @PreAuthorize("hasRole('ADMIN')")
25 @RequestMapping(value="/admin")
26 @Controller
27 public class AdminController {
154 @RequestMapping(value="/", method=RequestMethod.GET)
155 public String admin(Model model) {
156 return Constants.ADMIN_TEMPLATE;
157 }
177 }
当我尝试提出如下请求时:
admin:pwd2@localhost:3000/admin
我收到“401:错误凭据”。为什么会这样? (我也尝试通过 restclient 使用 Authorization 标头发出请求,结果相同)
谢谢。
【问题讨论】:
标签: spring authentication spring-security basic-authentication