2016-11-15 67 views
0

我有弹簧MVC项目,它在添加自动生成的登录身份验证筛选器之前给出输出。但添加过滤器后,我没有得到输出?它给资源没有发现404错误。我的代码有什么问题。其实我想添加这个认证,如果URL是/书。以下是我的项目的相关文件。在春天MVC自动生成的登录身份验证不起作用

的web.xml

<?xml version="1.0" encoding="UTF-8"?> 
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
    xmlns="http://java.sun.com/xml/ns/javaee" 
    xmlns:web="http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd" 
    xsi:schemaLocation="http://java.sun.com/xml/ns/javaee  

    http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd" 
    id="WebApp_ID" version="2.5"> 
<servlet> 
    <servlet-name>SpringMVC</servlet-name> 
    <servlet-class>org.springframework.web.servlet.DispatcherServlet</servlet-class> 
    <load-on-startup>1</load-on-startup> 
</servlet> 

<servlet-mapping> 
    <servlet-name>SpringMVC</servlet-name> 
    <url-pattern>/</url-pattern> 
</servlet-mapping> 


<listener> 
    <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class> 
</listener> 

<context-param> 
    <param-name>contextConfigLocation</param-name> 
    <param-value>/WEB-INF/securityconfig.xml</param-value> 
</context-param> 

<filter> 
    <filter-name>springSecurityFilterChain</filter-name> 
    <filter-class>org.springFramework.web.filter.DelegationFilterProxy</filter-class> 
</filter> 

<filter-mapping> 
    <filter-name>springSecurityFilterChain</filter-name> 
    <url-pattern>/*</url-pattern> 
</filter-mapping> 

securityconfig.xml

<?xml version="1.0" encoding="UTF-8"?> 
<beans xmlns="http://www.springframework.org/schema/beans" 
xmlns:sec="http://www.springframework.org/schema/security" 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
xsi:schemaLocation="http://www.springframework.org/schema/beans 
    http://www.springframework.org/schema/beans/spring-beans-4.1.xsd 
    http://www.springframework.org/schema/security 
    http://www.springframework.org/schema/security/spring-security-4.0.xsd"> 

<sec:http auto-config="true" use-expressions="true"> 
    <sec:intercept-url pattern="/books" access="ROLE_USER"/> 
    <sec:form-login/> 
    <sec:logout logout-url="/j_security_logout"/> 
</sec:http> 

<sec:authentication-manager> 
    <sec:authentication-provider> 
     <sec:user-service> 
      <sec:user name="test" password="123" authorities="ROLE_USER, ROLE_ADMIN"/> 
      <sec:user name="bob" password="mypassword" authorities="ROLE_USER"/> 
     </sec:user-service> 
    </sec:authentication-provider> 
</sec:authentication-manager> 

春季安全依赖关系:

<dependency> 
     <groupId>org.springframework.security</groupId> 
     <artifactId>spring-security-web</artifactId> 
     <version>4.1.0.RELEASE</version> 
    </dependency> 
    <dependency> 
     <groupId>org.springframework.security</groupId> 
     <artifactId>spring-security-taglibs</artifactId> 
     <version>4.1.0.RELEASE</version> 
    </dependency> 
    <dependency> 
     <groupId>org.springframework.security</groupId> 
     <artifactId>spring-security-config</artifactId> 
     <version>4.1.0.RELEASE</version> 
    </dependency> 
    <!-- security also needs the following to be present --> 
    <dependency> 
     <groupId>org.springframework</groupId> 
     <artifactId>spring-tx</artifactId> 
     <version>4.1.6.RELEASE</version> 
    </dependency> 
    <dependency> 
     <groupId>org.springframework</groupId> 
     <artifactId>spring-jdbc</artifactId> 
     <version>4.1.6.RELEASE</version> 
    </dependency> 

书控制器是:

@Controller 
public class BookController { 

    @RequestMapping("/") 
    public String redirectRoot() { 
     return "redirect:/books"; 
    } 

    @RequestMapping(value = "/books", method = RequestMethod.GET) 
    public String getAll(Model model) { 
     model.addAttribute("books", bookDao.getAll()); 
     return "bookList"; 
    } 
} 
+0

您的安全登录页面如何?你有任何控制器吗? – jlumietu

+0

不,我认为不需要登录控制器,因为它是自动的。我对吗? –

+0

好吧,您正在使用自动生成的登录表单。请检查我的答案并尝试 – jlumietu

回答

0

尝试这样的。您已将use-expressions配置为true,因此您不能简单地在访问属性中添加请求的角色:

<sec:http auto-config="true" use-expressions="true"> 
    <sec:intercept-url pattern="/books" access="hasRole('ROLE_USER')"/> 
    <sec:form-login/> 
    <sec:logout logout-url="/j_security_logout"/> 
</sec:http>