2016-06-11 152 views
0

我創建了全新的Grails項目,然後使用grails s2-quickstart命令獲取LoginController和User/UserRole類。一切工作正常,我有一個登錄頁面。然後,我通過選擇「生成控制器和視圖」在GTS中創建用戶控制器。產生的UserController的如下所示:Grails簡單註冊/登錄表格

import static org.springframework.http.HttpStatus.* 
import grails.transaction.Transactional 

@Transactional(readOnly = true) 
class UserController { 

static allowedMethods = [save: "POST", update: "PUT", delete: "DELETE"] 

def index(Integer max) { 
    params.max = Math.min(max ?: 10, 100) 
    respond User.list(params), model:[userInstanceCount: User.count()] 
} 

def show(User userInstance) { 
    respond userInstance 
} 

def create() { 
    respond new User(params) 
} 

@Transactional 
def save(User userInstance) { 
    if (userInstance == null) { 
     notFound() 
     return 
    } 

    if (userInstance.hasErrors()) { 
     respond userInstance.errors, view:'create' 
     return 
    } 

    userInstance.save flush:true 

    request.withFormat { 
     form multipartForm { 
      flash.message = message(code: 'default.created.message', args: [message(code: 'user.label', default: 'User'), userInstance.id]) 
      redirect userInstance 
     } 
     '*' { respond userInstance, [status: CREATED] } 
    } 
} 

def edit(User userInstance) { 
    respond userInstance 
} 

@Transactional 
def update(User userInstance) { 
    if (userInstance == null) { 
     notFound() 
     return 
    } 

    if (userInstance.hasErrors()) { 
     respond userInstance.errors, view:'edit' 
     return 
    } 

    userInstance.save flush:true 

    request.withFormat { 
     form multipartForm { 
      flash.message = message(code: 'default.updated.message', args: [message(code: 'User.label', default: 'User'), userInstance.id]) 
      redirect userInstance 
     } 
     '*'{ respond userInstance, [status: OK] } 
    } 
} 

@Transactional 
def delete(User userInstance) { 

    if (userInstance == null) { 
     notFound() 
     return 
    } 

    userInstance.delete flush:true 

    request.withFormat { 
     form multipartForm { 
      flash.message = message(code: 'default.deleted.message', args: [message(code: 'User.label', default: 'User'), userInstance.id]) 
      redirect action:"index", method:"GET" 
     } 
     '*'{ render status: NO_CONTENT } 
    } 
} 

protected void notFound() { 
    request.withFormat { 
     form multipartForm { 
      flash.message = message(code: 'default.not.found.message', args: [message(code: 'user.label', default: 'User'), params.id]) 
      redirect action: "index", method: "GET" 
     } 
     '*'{ render status: NOT_FOUND } 
    } 
} 

}

現在,當我想去/用戶/索引頁轉發我到登錄頁面... 如何改變這種狀況?如果這個問題很微不足道,我對於Grails來說是全新的。

回答

0

您需要通過在配置文件中指定spring security controller註釋靜態規則或在控制器上使用Secured註釋來爲特定角色提供對用戶/索引的訪問。

參考:http://grails-plugins.github.io/grails-spring-security-core/v3/index.html#secured-annotation

http://grails-plugins.github.io/grails-spring-security-core/v3/index.html#pessimistic-lockdown

+0

好吧,但我想任何人,沒有登錄的用戶不具有一個角色訪問這個UserController的。我應該添加ROLE_ANONYMOUS。? – user2455862

+0

將它添加到您的靜態規則中,並遵循您的application.groovy中的現有規則permitAll @ user2455862 – Vahid