代码之家  ›  专栏  ›  技术社区  ›  vector

403-验证后拒绝访问

  •  18
  • vector  · 技术社区  · 17 年前

    当我尝试对我现有的数据库进行身份验证时,我得到了身份验证,但我得到了403页。如果我只是尝试了一个错误的密码,我会收到预期的“错误凭据”消息。 我试着对SpringSecurity附带的每个示例应用程序进行身份验证,效果很好。

    security-context.xml:

    <?xml version="1.0" encoding="UTF-8"?>
    <beans:beans
        xmlns="http://www.springframework.org/schema/security"
        xmlns:beans="http://www.springframework.org/schema/beans"
        xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    
        xsi:schemaLocation="
            http://www.springframework.org/schema/beans
            http://www.springframework.org/schema/beans/spring-beans-2.0.xsd
            http://www.springframework.org/schema/security
            http://www.springframework.org/schema/security/spring-security-2.0.1.xsd">
    
        <global-method-security secured-annotations="enabled"></global-method-security>
    
        <http auto-config="true" >
            <intercept-url pattern="/admin/**" access="ROLE_TEST" />
            <intercept-url pattern="/**" access="IS_AUTHENTICATED_ANONYMOUSLY" />
    
            <form-login
                login-page="/login/index.jsp"
                default-target-url="/admin/test.jsp"
                authentication-failure-url="/login/index.jsp?login_error=1" />  
        </http>
    
        <authentication-provider user-service-ref="jdbcUserService">      
            <password-encoder ref="passwordEncoder">
                    <salt-source system-wide="n103df"/>
            </password-encoder>        
        </authentication-provider>
    
    
        <beans:bean id="jdbcUserService"  class="org.springframework.security.userdetails.jdbc.JdbcDaoImpl">
            <beans:property name="rolePrefix" value="" />
            <beans:property name="dataSource" ref="dataSource" />
            <beans:property name="enableAuthorities" value="true"/>
            <beans:property name="enableGroups" value="false"/>
            <beans:property name="authoritiesByUsernameQuery" value="SELECT username,authority FROM authorities WHERE username = ?" />
            <beans:property name="usersByUsernameQuery" value="SELECT username,password,enabled as enabled FROM users WHERE username = ?" />
            <beans:property name="groupAuthoritiesByUsernameQuery" value="" />
    
        </beans:bean>
    
    <beans:bean id="passwordEncoder" class="org.springframework.security.providers.encoding.Md5PasswordEncoder"/>
    

    提前谢谢!

    2 回复  |  直到 14 年前
        1
  •  41
  •   rodrigoap    10 年前

    如果您获得403代码,则表示该用户没有所需的角色。所以,没有感觉不是问题,是授权。
    知道发生了什么的唯一方法是将日志级别设置为调试,应该有更多信息。把它贴在这里。
    您的角色是否有“角色”前缀?

        2
  •  2
  •   vector    17 年前

    [DEBUG,AbstractSecurityInterceptor,http-8084-7] Secure object: FilterInvocation: URL: /admin/test.jsp; ConfigAttributes: [ROLE_TEST]
    [DEBUG,AbstractSecurityInterceptor,http-8084-7] Previously Authenticated: org.springframework.security.providers.UsernamePasswordAuthenticationToken@af840ed7: Principal: org.springframework.security.userdetails.User@3ec100: Username: testUser; Password: [PROTECTED]; Enabled: true; AccountNonExpired: true; credentialsNonExpired: true; AccountNonLocked: true; Granted Authorities: ROLE_SUPERVISOR; Password: [PROTECTED]; Authenticated: true; Details: org.springframework.security.ui.WebAuthenticationDetails@1c07a: RemoteIpAddress: 127.0.0.1; SessionId: 350B260FAFDDBF04D5CB4AAAB7B8A441; Granted Authorities: ROLE_SUPERVISOR
    [DEBUG,ExceptionTranslationFilter,http-8084-7] Access is denied (user is not anonymous); delegating to AccessDeniedHandler
    org.springframework.security.AccessDeniedException: Access is denied
            at org.springframework.security.vote.AffirmativeBased.decide(AffirmativeBased.java:68)
    

    ... 现在我很好奇,为什么? 因此,在将配置文件中的ROLE_TEST更改为ROLE_SUPERVISOR之后,所有这些都按预期工作。

    推荐文章