代码之家  ›  专栏  ›  技术社区  ›  JeanValjean

在WebSecurityConfigurerAdapter中正确使用WebSecurity

  •  17
  • JeanValjean  · 技术社区  · 11 年前

    在我的 弹簧防尘套 基于版本的应用程序 1.3.0.构建快照 ,我在 static 下的文件夹 resources .

    我看到一些与安全配置相关的示例,如下所示:

    @Configuration
    @EnableWebSecurity
    public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
    
        @Override
        public void configure(final WebSecurity web) throws Exception {
            web.ignoring()
               .antMatchers("/static/**");
        }
    }
    

    这个例子正确吗? 效果应该是什么? 如何验证它是否有效(例如向 localhost:8080/something ? 我能用什么酷的东西 WebSecurity ?

    2 回复  |  直到 10 年前
        1
  •  31
  •   informatik01 Viswanath Lekshmanan    7 年前

    您的示例意味着Spring(Web)Security ignoring 与您定义的表达式匹配的URL模式 ("/static/**") 。此URL被Spring Security跳过,因此不安全。

    允许添加SpringSecurity应该忽略的RequestMatcher实例。Spring Security提供的Web安全(包括SecurityContext)在匹配的HttpServletRequest上不可用。通常,注册的请求应该是静态资源的请求。对于动态请求,请考虑将请求映射为允许所有用户。

    看见 WebSecurity 有关更多信息,请参阅API文档。

    您可以根据需要设置任意多个安全或不安全的URL模式。
    有了Spring Security 身份验证 和 访问控制 应用程序的web层的功能。您还可以限制具有指定角色的用户访问特定URL等。

    阅读Spring Security参考以了解更多详细信息:
    http://docs.spring.io/spring-security/site/docs/current/reference/html/


    URL模式的排序优先级

    当将指定模式与传入请求进行匹配时,将按照元素声明的顺序进行匹配。因此,最具体的匹配模式应该排在第一位,最一般的应该排在最后。

    http有多个子级。authorizeRequests()方法 每一位选手都是按照他们被宣布的顺序来考虑的。

    模式总是按照定义的顺序进行计算。因此,在列表中定义更具体的模式比定义不太具体的模式更重要。

    阅读此处了解更多详细信息:
    http://docs.spring.io/spring-security/site/docs/current/reference/htmlsingle/#filter-security-interceptor


    示例1

    WebSecurity的一般使用 ignoring() 方法省略了Spring Security,并且Spring Security的任何特性都不可用。 WebSecurity基于HttpSecurity之上
    (在XML配置中,可以编写以下内容: <http pattern="/resources/**" security="none"/> ).

    @Override
    public void configure(WebSecurity web) throws Exception {
        web
            .ignoring()
            .antMatchers("/resources/**")
            .antMatchers("/publics/**");
    }
    
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .authorizeRequests()
            .antMatchers("/admin/**").hasRole("ADMIN")
            .antMatchers("/publics/**").hasRole("USER") // no effect
            .anyRequest().authenticated();
    }
    

    上面示例中的WebSecurity允许Spring忽略 /resources/** 和 /publics/** 因此 .antMatchers("/publics/**").hasRole("USER") HttpSecurity中的错误。

    这将从安全过滤器链中完全省略请求模式。 请注意,匹配此路径的任何内容都不会应用任何身份验证或授权服务,并且可以自由访问。


    示例2

    始终计算模式 整齐 。以下匹配无效,因为第一个匹配每个请求,并且永远不会应用第二个匹配:

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .authorizeRequests()
            .antMatchers("/**").hasRole("USER")
            .antMatchers("/admin/**").hasRole("ADMIN"):
    }
    
        2
  •  0
  •   JeanValjean    11 年前

    在您共享的代码中,如果您将静态文件(即CSS/JS等)放在名为static的文件夹中,那么所有静态资源都将添加到页面中,而如果您忽略了

    web.ignoring()
        .antMatchers("/static/**");
    

    不会加载任何静态资源。

    Spring Security非常强大,Spring有很好的文档,所以您应该去阅读它,充分欣赏/理解它。

    这里有一个 link