更新1:我使用Spring Security 4.0.3,在Tomcat 7上运行.
问题是接近this question,也许SecurityContextHolder在response.redirect()中丢失,但答案没有帮助.
问题似乎接近this question,但答案对我来说没有意义.
这是我的配置:
- @Configuration
- @EnableWebSecurity
- @EnableGlobalMethodSecurity(securedEnabled = true)
- public class ProjectSecurityConfiguration extends WebSecurityConfigurerAdapter {
- @Override
- protected void configure(HttpSecurity http) throws Exception {
- http.csrf().disable();
- http.authorizeRequests().antMatchers("/login").anonymous();
- }
- @Override
- protected void configure(AuthenticationManagerBuilder auth) throws Exception {
- auth.inMemoryAuthentication().withUser(Constants.PROFIL_ADMIN).password(Constants.PROFIL_ADMIN).
- roles("ADMIN","TEST_SERVICE");
- }
- }
- @RequestMapping(value = "/myurl",method = RequestMethod.GET)
- @ResponseBody
- public boolean getTestService(HttpServletRequest request)
- throws sqlException,PoRulesException {
- System.out.println("get security context");
- System.out.println("--------------------");
- SecurityContext secuContext = (SecurityContext) request.getSession().getAttribute("SPRING_SECURITY_CONTEXT");
- System.out.println(secuContext);
- System.out.println("get security context holder");
- System.out.println(SecurityContextHolder.getContext());
- return testService.getTestMethod();
- }
服务中的方法
- @Secured("ROLE_TEST_SERVICE")
- public boolean getTestMethod() {
- Sysout.out.println("Hiii")
- return true
- }
现在,日志不行时:
- INFO 2016-07-11 15:57:00,006 [http-bio-8080-exec-3] com.po.mvc.controller.LoginController - Login
- INFO 2016-07-11 15:57:00,057 [http-bio-8080-exec-3] com.po.mvc.controller.LoginController - User : axel
- INFO 2016-07-11 15:57:00,065 [http-bio-8080-exec-3] com.po.mvc.controller.LoginController - Authenticate : true
- INFO 2016-07-11 15:57:00,065 [http-bio-8080-exec-3] com.po.mvc.controller.LoginController - Authenticate : org.springframework.security.authentication.UsernamePasswordAuthenticationToken@bbbc4f45: Principal: org.springframework.security.core.userdetails.User@fc8a: Username: ADM; Password: [PROTECTED]; Enabled: true; AccountNonExpired: true; credentialsNonExpired: true; AccountNonLocked: true; Granted Authorities: ROLE_ADMIN,ROLE_CONSULTER_CA,ROLE_USER; Credentials: [PROTECTED]; Authenticated: true; Details: org.springframework.security.web.authentication.WebAuthenticationDetails@fffde5d4: RemoteIpAddress: 0:0:0:0:0:0:0:1; SessionId: 613DFE47B2CE6E29DA3C227F8E028590; Granted Authorities: ROLE_ADMIN,ROLE_TEST_SERVICE
- get security context
- --------------------
- org.springframework.security.core.context.SecurityContextImpl@bbbc4f45: Authentication: org.springframework.security.authentication.UsernamePasswordAuthenticationToken@bbbc4f45: Principal: org.springframework.security.core.userdetails.User@fc8a: Username: ADM; Password: [PROTECTED]; Enabled: true; AccountNonExpired: true; credentialsNonExpired: true; AccountNonLocked: true; Granted Authorities: ROLE_ADMIN,ROLE_TEST_SERVICE
- get security context holder
- org.springframework.security.core.context.SecurityContextImpl@ffffffff: Null authentication
- ERROR 2016-07-11 15:57:01,960 [http-bio-8080-exec-10] com.po.exception.GlobalControllerExceptionHandler - org.springframework.security.authentication.AuthenticationCredentialsNotFoundException: An Authentication object was not found in the SecurityContext
- org.springframework.security.authentication.AuthenticationCredentialsNotFoundException: An Authentication object was not found in the SecurityContext
- at org.springframework.security.access.intercept.AbstractSecurityInterceptor.credentialsNotFound(AbstractSecurityInterceptor.java:378)
- at org.springframework.security.access.intercept.AbstractSecurityInterceptor.beforeInvocation(AbstractSecurityInterceptor.java:222)
- at org.springframework.security.access.intercept.aopalliance.MethodSecurityInterceptor.invoke(MethodSecurityInterceptor.java:64)
- at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:179)
- at org.springframework.aop.framework.CglibAopProxy$DynamicAdvisedInterceptor.intercept(CglibAopProxy.java:655)
- at com.po.service.CAService$$EnhancerBySpringCGLIB$$f6e21857.getVarAndPrevCa(<generated>)
- at com.po.mvc.controller.CaController.getVarAndPrevCa(CaController.java:56)
- at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
- at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
- at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
- at java.lang.reflect.Method.invoke(Method.java:606)
- at org.springframework.web.method.support.InvocableHandlerMethod.doInvoke(InvocableHandlerMethod.java:222)
- at org.springframework.web.method.support.InvocableHandlerMethod.invokeForRequest(InvocableHandlerMethod.java:137)
- at org.springframework.web.servlet.mvc.method.annotation.ServletInvocableHandlerMethod.invokeAndHandle(ServletInvocableHandlerMethod.java:110)
- at org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerAdapter.invokeHandlerMethod(RequestMappingHandlerAdapter.java:814)
- at org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerAdapter.handleInternal(RequestMappingHandlerAdapter.java:737)
- at org.springframework.web.servlet.mvc.method.AbstractHandlerMethodAdapter.handle(AbstractHandlerMethodAdapter.java:85)
- at org.springframework.web.servlet.DispatcherServlet.doDispatch(DispatcherServlet.java:959)
- at org.springframework.web.servlet.DispatcherServlet.doService(DispatcherServlet.java:893)
- at org.springframework.web.servlet.FrameworkServlet.processRequest(FrameworkServlet.java:969)
- at org.springframework.web.servlet.FrameworkServlet.doGet(FrameworkServlet.java:860)
- at javax.servlet.http.HttpServlet.service(HttpServlet.java:621)
- at org.springframework.web.servlet.FrameworkServlet.service(FrameworkServlet.java:845)
- at javax.servlet.http.HttpServlet.service(HttpServlet.java:722)
- at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:304)
- at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:210)
- at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:224)
- at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:169)
- at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:472)
- at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:168)
- at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:100)
- at org.apache.catalina.valves.AccessLogValve.invoke(AccessLogValve.java:929)
- at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:118)
- at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:405)
- at org.apache.coyote.http11.AbstractHttp11Processor.process(AbstractHttp11Processor.java:964)
- at org.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process(AbstractProtocol.java:515)
- at org.apache.tomcat.util.net.JIoEndpoint$SocketProcessor.run(JIoEndpoint.java:304)
- at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
- at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
- at java.lang.Thread.run(Thread.java:745)
当它工作时.我只是看到没有区别… Spring上下文被设置并且包含作为sysout proove的凭据,但是SecurityContextHolder没有设置.
- INFO 2016-07-11 16:09:45,374 [http-bio-8080-exec-3] com.po.mvc.controller.LoginController - Login
- INFO 2016-07-11 16:09:45,393 [http-bio-8080-exec-3] com.po.mvc.controller.LoginController - User : axel
- INFO 2016-07-11 16:09:45,395 [http-bio-8080-exec-3] com.po.mvc.controller.LoginController - Authenticate : true
- INFO 2016-07-11 16:09:45,395 [http-bio-8080-exec-3] com.po.mvc.controller.LoginController - Authenticate : org.springframework.security.authentication.UsernamePasswordAuthenticationToken@bbbc4f45: Principal: org.springframework.security.core.userdetails.User@fc8a: Username: ADM; Password: [PROTECTED]; Enabled: true; AccountNonExpired: true; credentialsNonExpired: true; AccountNonLocked: true; Granted Authorities: ROLE_ADMIN,ROLE_TEST_SERVICE; Credentials: [PROTECTED]; Authenticated: true; Details: org.springframework.security.web.authentication.WebAuthenticationDetails@fffde5d4: RemoteIpAddress: 0:0:0:0:0:0:0:1; SessionId: 613DFE47B2CE6E29DA3C227F8E028590; Granted Authorities: ROLE_ADMIN,ROLE_TEST_SERVICE Credentials: [PROTECTED]; Authenticated: true; Details: org.springframework.security.web.authentication.WebAuthenticationDetails@fffde5d4: RemoteIpAddress: 0:0:0:0:0:0:0:1; SessionId: 613DFE47B2CE6E29DA3C227F8E028590; Granted Authorities: ROLE_ADMIN,ROLE_USER
- get security context holder
- org.springframework.security.core.context.SecurityContextImpl@4440cc59: Authentication: org.springframework.security.authentication.UsernamePasswordAuthenticationToken@4440cc59: Principal: org.springframework.security.core.userdetails.User@fc8a: Username: ADM; Password: [PROTECTED]; Enabled: true; AccountNonExpired: true; credentialsNonExpired: true; AccountNonLocked: true; Granted Authorities: ROLE_ADMIN,ROLE_USER; Credentials: [PROTECTED]; Authenticated: true; Details: org.springframework.security.web.authentication.WebAuthenticationDetails@166c8: RemoteIpAddress: 0:0:0:0:0:0:0:1; SessionId: 19994511EEE72462E8D680CDADCFEC4C; Granted Authorities: ROLE_ADMIN,ROLE_USER
- INFO 2016-07-11 16:09:46,879 [http-bio-8080-exec-3] Hiii
它的工作原理与何时不同的唯一区别是:
>当我从我的网站的页面连接时工作,例如我在mywebsite.com是公共的,并且去mywebsite.com/login?user=me它工作
>但是如果我在mywebsite.com/login?user=me上来自Google,则无效
会话属性SPRING_SECURITY_CONTEXT在这两种情况下设置,但不是SecurityContextHolder,它在@Secured line 222中触发异常
我不想使用一个技巧,例如手动检查SecurityContextHolder(在重定向之后),如果为空,则设置会话属性SPRING_SECURITY_CONTEXT,该属性不为空,我想在根解决问题.
解决方法
从根本上说,你所做的一切都不会奏效,除非你将自己限于容器中的一个线程(这是一个可怕的想法).从SecurityContextHolder上的文档:
Associates a given
SecurityContext
with the current execution thread.
这很重要 – 当前的执行线程.如果您创建了一个由线程A处理的登录请求,那么您尝试转到安全页面,但此请求由线程B处理,则您在A上设置的SecurityContext将不会在B上可用.
Spring Security通过将安全上下文存储在会话中并根据需要存储/获取它(参见org.springframework.security.web.session.SessionManagementFilter),可以很好地处理此问题.但是,您需要对配置进行一些更改.
主要地,您将需要创建一个从AbstractAuthenticationProcessingFilter扩展的新类,并覆盖useAuthentication方法.然后,这个新的过滤器需要被注册,并且需要替换现有的org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter.这个类也可能是一个很好的地方,以了解如何将它们全部挂在一起,以及您可以配置的内容.
这个新的过滤器会做一些事情
- public Authentication attemptAuthentication(HttpServletRequest request,HttpServletResponse response) throws AuthenticationException {
- UserLDAP ldapUser = CorpLDAP.findUser(request);
- User user = new User(ldapUser.getProfil(),ldapUser.getPwd(),Collections.emptyList());
- return new UsernamePasswordAuthenticationToken(user,"",Collections.emptyList());
- }
这将返回完全认证的用户,稍后可以使用.这将保存在SecurityContextHolder中,并且可以方便地检索.它也将存储在会话中(如果已配置),因此我建议确保它是可序列化的.由于您不使用密码,我强烈建议您不要将其存储在用户中.
希望这将使你朝着正确的方向发展.