Spring Security 2.x正在攔截http:servername/webAppName
。根據我的理解,filter="none"
應該丟棄任何不需要訪問角色的URL的Spring Security篩選器鏈。任何人都知道爲什麼這個設置攔截所有未聲明的URL(/listing
,/load
),包括基本URL?Spring Security url-interceptor leak at/*
<http auto-config="true" entry-point-ref="entryPoint" session-fixation-protection="none">
<intercept-url pattern="/listing/pages/*" filters="none"/>
<intercept-url pattern="/load/page/*" filters="none"/>
<intercept-url pattern="/admin/*" access="ROLE_USER"/>
<intercept-url pattern="/secret/*" access="ROLE_USER"/>
<intercept-url pattern="/**" filters="none"/>
<http-basic/>
</http>
看看http://stackoverflow.com/questions/10513688/apply-security-none-to-context-root-and-static-resources-spring-security-versi – dur
謝謝。會看看我是否可以有類似的東西。該鏈接涵蓋了spring安全3.1 – MAXStack