2016-11-15 69 views
0

我有彈簧MVC項目,它在添加自動生成的登錄身份驗證篩選器之前給出輸出。但添加過濾器後,我沒有得到輸出?它給資源沒有發現404錯誤。我的代碼有什麼問題。其實我想添加這個認證,如果URL是/書。以下是我的項目的相關文件。在春天MVC自動生成的登錄身份驗證不起作用

的web.xml

<?xml version="1.0" encoding="UTF-8"?> 
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
    xmlns="http://java.sun.com/xml/ns/javaee" 
    xmlns:web="http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd" 
    xsi:schemaLocation="http://java.sun.com/xml/ns/javaee  

    http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd" 
    id="WebApp_ID" version="2.5"> 
<servlet> 
    <servlet-name>SpringMVC</servlet-name> 
    <servlet-class>org.springframework.web.servlet.DispatcherServlet</servlet-class> 
    <load-on-startup>1</load-on-startup> 
</servlet> 

<servlet-mapping> 
    <servlet-name>SpringMVC</servlet-name> 
    <url-pattern>/</url-pattern> 
</servlet-mapping> 


<listener> 
    <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class> 
</listener> 

<context-param> 
    <param-name>contextConfigLocation</param-name> 
    <param-value>/WEB-INF/securityconfig.xml</param-value> 
</context-param> 

<filter> 
    <filter-name>springSecurityFilterChain</filter-name> 
    <filter-class>org.springFramework.web.filter.DelegationFilterProxy</filter-class> 
</filter> 

<filter-mapping> 
    <filter-name>springSecurityFilterChain</filter-name> 
    <url-pattern>/*</url-pattern> 
</filter-mapping> 

securityconfig.xml

<?xml version="1.0" encoding="UTF-8"?> 
<beans xmlns="http://www.springframework.org/schema/beans" 
xmlns:sec="http://www.springframework.org/schema/security" 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
xsi:schemaLocation="http://www.springframework.org/schema/beans 
    http://www.springframework.org/schema/beans/spring-beans-4.1.xsd 
    http://www.springframework.org/schema/security 
    http://www.springframework.org/schema/security/spring-security-4.0.xsd"> 

<sec:http auto-config="true" use-expressions="true"> 
    <sec:intercept-url pattern="/books" access="ROLE_USER"/> 
    <sec:form-login/> 
    <sec:logout logout-url="/j_security_logout"/> 
</sec:http> 

<sec:authentication-manager> 
    <sec:authentication-provider> 
     <sec:user-service> 
      <sec:user name="test" password="123" authorities="ROLE_USER, ROLE_ADMIN"/> 
      <sec:user name="bob" password="mypassword" authorities="ROLE_USER"/> 
     </sec:user-service> 
    </sec:authentication-provider> 
</sec:authentication-manager> 

春季安全依賴關係:

<dependency> 
     <groupId>org.springframework.security</groupId> 
     <artifactId>spring-security-web</artifactId> 
     <version>4.1.0.RELEASE</version> 
    </dependency> 
    <dependency> 
     <groupId>org.springframework.security</groupId> 
     <artifactId>spring-security-taglibs</artifactId> 
     <version>4.1.0.RELEASE</version> 
    </dependency> 
    <dependency> 
     <groupId>org.springframework.security</groupId> 
     <artifactId>spring-security-config</artifactId> 
     <version>4.1.0.RELEASE</version> 
    </dependency> 
    <!-- security also needs the following to be present --> 
    <dependency> 
     <groupId>org.springframework</groupId> 
     <artifactId>spring-tx</artifactId> 
     <version>4.1.6.RELEASE</version> 
    </dependency> 
    <dependency> 
     <groupId>org.springframework</groupId> 
     <artifactId>spring-jdbc</artifactId> 
     <version>4.1.6.RELEASE</version> 
    </dependency> 

書控制器是:

@Controller 
public class BookController { 

    @RequestMapping("/") 
    public String redirectRoot() { 
     return "redirect:/books"; 
    } 

    @RequestMapping(value = "/books", method = RequestMethod.GET) 
    public String getAll(Model model) { 
     model.addAttribute("books", bookDao.getAll()); 
     return "bookList"; 
    } 
} 
+0

您的安全登錄頁面如何?你有任何控制器嗎? – jlumietu

+0

不,我認爲不需要登錄控制器,因爲它是自動的。我對嗎? –

+0

好吧,您正在使用自動生成的登錄表單。請檢查我的答案並嘗試 – jlumietu

回答

0

嘗試這樣的。您已將use-expressions配置爲true,因此您不能簡單地在訪問屬性中添加請求的角色:

<sec:http auto-config="true" use-expressions="true"> 
    <sec:intercept-url pattern="/books" access="hasRole('ROLE_USER')"/> 
    <sec:form-login/> 
    <sec:logout logout-url="/j_security_logout"/> 
</sec:http>