代码之家  ›  专栏  ›  技术社区  ›  simon

如何使用springsecurity实现登录页面,使其与springwebflow一起工作?

  •  18
  • simon  · 技术社区  · 16 年前

    
    <beans:bean id="customizedFormLoginFilter"
        class="org.springframework.security.ui.webapp.AuthenticationProcessingFilter">
        <custom-filter position="AUTHENTICATION_PROCESSING_FILTER" />
        <beans:property name="defaultTargetUrl" value="/index.do" />
        <beans:property name="authenticationFailureUrl" value="/login.do?error=true" />
        <beans:property name="authenticationManager" ref="customAuthenticationManager" />
        <beans:property name="allowSessionCreation" value="true" />
    </beans:bean>
    
    <beans:bean id="customAuthenticationManager"
        class="com.sevenp.mobile.samplemgmt.web.security.CustomAuthenticationManager">
        <beans:property name="authenticateUrlWs" value="${WS_ENDPOINT_ADDRESS}" />
    </beans:bean>
    

    身份验证管理器类:

    
    public class CustomAuthenticationManager implements AuthenticationManager, ApplicationContextAware {
    
        @Transactional
        @Override
        public Authentication authenticate(Authentication authentication) throws AuthenticationException {
    
                    //authentication logic
    
            return new UsernamePasswordAuthenticationToken(principal, authentication.getCredentials(),
                    grantedAuthorityArray);
        }
    

    
    <c:url value="/j_spring_security_check" var="formUrlSecurityCheck"/>
    <form method="post" action="${formUrlSecurityCheck}">
        <div id="errorArea" class="errorBox"> 
           <c:if test="${not empty param.error}">
              ${sessionScope["SPRING_SECURITY_LAST_EXCEPTION"].message}
          </c:if>
      </div>
        <label for="loginName">
            Username:           
            <input style="width:125px;" tabindex="1" id="login" name="j_username" />
        </label>
    
        <label for="password">
            Password:           
            <input style="width:125px;" tabindex="2" id="password" name="j_password" type="password" />
        </label>
        <input type="submit" tabindex="3" name="login" class="formButton" value="Login" />
    </form>
    

    现在的问题是应用程序应该使用 Spring Web Flow . 将应用程序配置为使用SpringWebFlow后,登录将不再工作-表单操作“/j\u Spring\u security\u check”将导致一个没有错误消息的空白页。调整现有登录过程以使其与springwebflow一起工作的最佳方法是什么?

    编辑: 没有错误信息,只是显示了一个空白页。现在起作用了-问题是网站.xml缺少条目

    
    <filter>
        <filter-name>springSecurityFilterChain</filter-name>
        <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
    </filter>
    
    <filter-mapping>
        <filter-name>springSecurityFilterChain</filter-name>
        <url-pattern>/*</url-pattern>
    </filter-mapping>
    

    虽然问题解决了,但我不能取消赏金,所以赏金将授予最有见地的答案或链接,这将有助于其他人配置Spring安全和webflow来协同工作。

    4 回复  |  直到 16 年前
        1
  •  2
  •   mdma    16 年前

    下面的文档描述了为什么需要“springSecurityFilterChain”。

    springSecurityFilterChain筛选器不是显式创建的,而是由 <http> 应用程序上下文中的spring安全架构元素

    <http auto-config="false" session-fixation-protection="none">
        <form-login login-page="/login.jsp" default-target-url="/home.htm" />
    </http>
    

    <authentication-provider>
       <user-service id="userDetailsService">
          <user password="password" name="username" authorities="ROLE_USER" />
       </user-service>
    </authentication-provider
    

    有了这些更改(包括编辑问题中描述的安全过滤器的配置),页面将正确呈现,并且配置的安全堆栈将在提供服务的每个页面上就位。

    A aimple web application with Spring Security - part 13 .

    参考文档描述了设置 springSecurityFilterChain 作为配置的第一部分网站.xml: Security Namespace Configuration - Getting Started . here .)

        2
  •  1
  •   Georgy Bolyuba    16 年前

    从您的代码中不清楚您是否有Spring安全配置。我想你没有。

    • 您必须在配置中添加安全名称空间。像这样的

      
      <beans xmlns="http://www.springframework.org/schema/beans" ... skipped ...
          xmlns:security="http://www.springframework.org/schema/security"
          xsi:schemaLocation="
          http://www.springframework.org/schema/beans
          http://www.springframework.org/schema/beans/spring-beans-2.5.xsd
          ... skipped ...
          http://www.springframework.org/schema/security
          http://www.springframework.org/schema/security/spring-security-2.0.4.xsd">
      
    • 
      <security:http once-per-request="false" auto-config="false">
          <security:form-login login-page="path/to/your/login.jsp"/>
      </security:http>
      
    • 这可能足以让它“正常工作”,但我认为您应该考虑一下实现 AuthenticationProvider 而不是AuthenticationManager。在这种情况下,您需要类似于以下内容的配置:

      
      <bean class="my.company.project.MyAuthProvider"
            autowire="byType">
          <security:custom-authentication-provider/>
      </bean>
      
        3
  •  0
  •   Justin    16 年前

        4
  •  0
  •   reevesy onejigtwojig    13 年前

    你的应用程序配置成使用springwebflow了吗 Securing Flows Spring Web Flow Reference Guide ?

    推荐文章