2013-12-14 58 views
6

我試圖用Spring安全性實現基於表單的身份驗證。重定向工作正常: 我的主網頁可以正常工作和http://localhost:8080/master/admin我重定向到登錄頁面(http://localhost:8080/master/login/):爲什麼j_spring_security_check 404?

<form action="j_spring_security_check" method="POST"> 
     <label for="username">User Name:</label> 
     <input id="username" name="j_username" type="text"/> 
     <label for="password">Password:</label> 
     <input id="password" name="j_password" type="password"/> 
     <input type="submit" value="Log In"/> 
     </form> 

but when I submit I get 404 on address: `http://localhost:8080/master/login/j_spring_security_check` 

這裏是我的配置的web.xml:

<context-param> 
     <param-name>contextConfigLocation</param-name> 
     <param-value>/WEB-INF/spring/root-context.xml</param-value> 
    </context-param> 
    <filter> 
     <filter-name>springSecurityFilterChain</filter-name> 
     <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class> 
    </filter> 
    <filter-mapping> 
     <filter-name>springSecurityFilterChain</filter-name> 
     <url-pattern>/*</url-pattern> 
    </filter-mapping> 

    <!-- Creates the Spring Container shared by all Servlets and Filters --> 
    <listener> 
     <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class> 
    </listener> 

    <!-- Processes application requests --> 
    <servlet> 
     <servlet-name>appServlet</servlet-name> 
     <servlet-class>org.springframework.web.servlet.DispatcherServlet</servlet-class> 
     <init-param> 
      <param-name>contextConfigLocation</param-name> 
      <param-value>/WEB-INF/spring/appServlet/servlet-context.xml</param-value> 
     </init-param> 
     <load-on-startup>1</load-on-startup> 
    </servlet> 
    <servlet-mapping> 
     <servlet-name>appServlet</servlet-name> 
     <url-pattern>/</url-pattern> 
    </servlet-mapping> 

我的根上下文.XML(我做了重定向到谷歌,讓我知道在上下文存在頁)

<sec:http auto-config="true"> 
    <sec:intercept-url pattern="/admin/**" access="ROLE_USER" /> 
    <sec:form-login login-page="/login/" 
     authentication-failure-url="http://www.google.com" default-target-url="http://www.google.com" /> 
    <sec:logout logout-success-url="/logout" /> 
</sec:http> 

<sec:authentication-manager> 
    <sec:authentication-provider> 
     <sec:user-service> 
      <sec:user name="test" password="test" authorities="ROLE_USER, ROLE_ADMIN" /> 
      <sec:user name="testuser" password="testuserpassword" 
       authorities="ROLE_USER" /> 
     </sec:user-service> 
    </sec:authentication-provider> 
</sec:authentication-manager> 

我已經失去了相當多的時間了,嘗試不同的組合,但沒有運氣。任何幫助表示讚賞!

回答

5

我認爲這可能是您的安全形式應指向

/master/j_spring_security_check 
+1

這裏其實是一些更多的信息,讓您更好地瞭解如何和爲什麼:http://stackoverflow.com/questions/15365477/彈簧3的安全-J-春季安全檢查 –