2016-07-05 65 views
1

我只是想執行一個非常簡單的Spring安全示例項目,但我得到404錯誤。請幫助在這裏找到問題。Spring安全問題 - 404錯誤

project structure

控制器:

package mypack; 

import org.springframework.stereotype.Controller; 
import org.springframework.web.bind.annotation.RequestMapping; 
import org.springframework.web.bind.annotation.RequestMethod; 
import org.springframework.web.servlet.ModelAndView; 

@Controller 
public class SecurityController { 

@RequestMapping(value = { "/", "/welcome**" }, method = RequestMethod.GET) 
public ModelAndView welcomePage() { 

    ModelAndView model = new ModelAndView(); 
    model.addObject("title", "Spring Security Hello World"); 
    model.addObject("message", "This is welcome page!"); 
    model.setViewName("hello"); 
    return model; 

} 

@RequestMapping(value = "/admin**", method = RequestMethod.GET) 
public ModelAndView adminPage() { 

    ModelAndView model = new ModelAndView(); 
    model.addObject("title", "Spring Security Hello World"); 
    model.addObject("message", "This is protected page!"); 
    model.setViewName("admin"); 

    return model; 

} 

} 

彈簧servlet.xml中

<beans xmlns="http://www.springframework.org/schema/beans" 
xmlns:context="http://www.springframework.org/schema/context" 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
xsi:schemaLocation=" 
    http://www.springframework.org/schema/beans  
    http://www.springframework.org/schema/beans/spring-beans-3.0.xsd 
    http://www.springframework.org/schema/context 
    http://www.springframework.org/schema/context/spring-context-3.0.xsd"> 

<context:component-scan base-package="mypack" /> 

<bean 
    class="org.springframework.web.servlet.view.InternalResourceViewResolver"> 
    <property name="prefix"> 
    <value>/WEB-INF/views/</value> 
    </property> 
    <property name="suffix"> 
    <value>.jsp</value> 
    </property> 
</bean> 

彈簧的security.xml

<beans:beans xmlns="http://www.springframework.org/schema/security" 
xmlns:beans="http://www.springframework.org/schema/beans" 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
xsi:schemaLocation="http://www.springframework.org/schema/beans 
http://www.springframework.org/schema/beans/spring-beans-3.0.xsd 
http://www.springframework.org/schema/security 
http://www.springframework.org/schema/security/spring-security-3.2.xsd"> 

<http auto-config="true"> 
    <intercept-url pattern="/admin**" access="ROLE_USER" /> 
</http> 

<authentication-manager> 
    <authentication-provider> 
    <user-service> 
    <user name="user" password="123456" authorities="ROLE_USER" /> 
    </user-service> 
    </authentication-provider> 
</authentication-manager> 

的web.xml

<web-app id="WebApp_ID" version="2.4" 
xmlns="http://java.sun.com/xml/ns/j2ee" 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
xsi:schemaLocation="http://java.sun.com/xml/ns/j2ee 
http://java.sun.com/xml/ns/j2ee/web-app_2_4.xsd"> 

<display-name>Spring MVC Application</display-name> 

<!-- Spring MVC --> 
<servlet> 
    <servlet-name>spring</servlet-name> 
    <servlet-class>org.springframework.web.servlet.DispatcherServlet 
    </servlet-class> 
    <load-on-startup>1</load-on-startup> 
</servlet> 
<servlet-mapping> 
    <servlet-name>spring</servlet-name> 
    <url-pattern>/</url-pattern> 
</servlet-mapping> 

<listener> 
    <listener-class>org.springframework.web.context.ContextLoaderListener 
    </listener-class> 
</listener> 

    <!-- Loads Spring Security config file --> 
<context-param> 
    <param-name>contextConfigLocation</param-name> 
    <param-value> 
     /WEB-INF/spring-security.xml 
    </param-value> 
</context-param> 

<!-- Spring Security --> 
<filter> 
    <filter-name>springSecurityFilterChain</filter-name> 
    <filter-class>org.springframework.web.filter.DelegatingFilterProxy 
    </filter-class> 
</filter> 

<filter-mapping> 
    <filter-name>springSecurityFilterChain</filter-name> 
    <url-pattern>/*</url-pattern> 
</filter-mapping> 

admin.jsp

<%@taglib prefix="c" uri="http://java.sun.com/jsp/jstl/core"%> 
<%@page session="true"%> 
<html> 
<body> 
<h1>Title : ${title}</h1> 
<h1>Message : ${message}</h1> 

<c:if test="${pageContext.request.userPrincipal.name != null}"> 
    <h2>Welcome : ${pageContext.request.userPrincipal.name} 
     | <a href="<c:url value="/j_spring_security_logout" />" > Logout</a></h2> 
</c:if> 

的hello.jsp

<%@page session="false"%> 
<html> 
<body> 
<h1>Title : ${title}</h1> 
<h1>Message : ${message}</h1> 

+0

組件掃描以掃描控制器的註釋組件將解決問題 – Gopinathan

+0

存在於spring-servlet.xml中。對不起,它在代碼片段中不可見。現在編輯它。 – SRR

+0

一旦我包含彈簧安全配置,我開始得到404錯誤。如果我評論web.xml中的spring security配置,項目工作正常。請注意,我沒有包含登錄頁面。我期待春季提供的默認登錄頁面。 – SRR

回答

0

嘗試下面的代碼在你的春季安全XML file.Also改變按您的需求量的作用。

<http auto-config="true" use-expressions="true"> 
     <intercept-url pattern="/signin" access="permitAll"></intercept-url> 
     <intercept-url pattern="/logout" access="permitAll"></intercept-url> 
     <intercept-url pattern="/accessdenied" access="permitAll"></intercept-url>   
     <intercept-url method="GET" pattern="/**" 
      access="hasRole('USER') 
      or hasRole('ADMIN')"></intercept-url> 

     <form-login login-page="/signin" default-target-url="/index" 
      authentication-failure-url="/accessdenied" always-use-default-target="true" 
      username-parameter="username" password-parameter="password"></form-login> 
     <logout logout-success-url="/logout"></logout> 
    </http> 
0

正如你已經在你的web.xml配置servlet映射到URL模式爲「/」的servlet映射。因此調度程序servlet將查找名爲index.html/jsp的文件。

要配置控制器必須添加組件掃描到您的servlet.xml中

添加下面一行

<context:component-scan base-package="mypack" /> 
+0

存在於spring-servlet.xml中。對不起,它在代碼片段中不可見。現在編輯它。 – SRR

0

您必須對過濾器定義的路徑:

<intercept-url pattern="/" access="permitAll" /> 
<intercept-url pattern="/welcome" access="permitAll" /> 

因此,在這種情況下,沒有角色(匿名)的用戶可以訪問「/」和「/ welcome **」。