我已经实现了一个Custom PermissionEvaluator并将其配置如下
<security:http access-denied-page="/" auto-config="true" use-expressions="true">
<security:anonymous />
<security:form-login always-use-default-target="false" default-target-url="/people/login/redirect" login-page="/people/login" login-processing-url="/people/login/submit" password-parameter="password" username-parameter="emailAddress" />
<security:logout delete-cookies="true" invalidate-session="true" logout-success-url="/people/login/redirect" logout-url="/people/logout" />
</security:http>
<security:authentication-manager erase-credentials="false">
<security:authentication-provider ref="authenticationProvider" />
</security:authentication-manager>
<security:global-method-security jsr250-annotations="enabled" pre-post-annotations="enabled" secured-annotations="enabled" >
<security:expression-handler ref="expressionHandler"/>
</security:global-method-security>
<bean id="expressionHandler" class="org.springframework.security.access.expression.method.DefaultMethodSecurityExpressionHandler">
<property name="permissionEvaluator" ref="appPermissionEvaluator"/>
</bean>
<bean class="com.web.security.ApplicationPermissionEvaluator" id="appPermissionEvaluator" />
然后我在我的一个ControllerClass上的一个方法上应用了hasPermissionCheck,如下所示
@PreAuthorize("hasPermission(#accountCode, 'AdministerPosition')")
@RequestMapping(method = RequestMethod.GET, value = "/cloud/{account}/position")
public String list(@PathVariable String account, @RequestParam(required = false, value = URLParameter.ACCOUNT_CODE) final String accountCode, final Model model) {
}
在这种情况下,我从未在ApplicationPermissionEvaluator
课程中获得控件。
我发现在我的情况下始终会DenyAllPermissionEvaluator
执行以下错误消息
DenyAllPermissionEvaluator - Denying user ****** permission 'AdministerPosition'
请尽快给我建议。我真的很困惑。
答案 0 :(得分:1)
实现此功能的方法是在spring mvc上下文中配置<security:global-method-security ..>
,而不是主要上下文
即。在这里mvc-servlet-context.xml
<servlet>
<servlet-name>appServlet</servlet-name>
<servlet-class>org.springframework.web.servlet.DispatcherServlet</servlet-class>
<init-param>
<param-name>contextConfigLocation</param-name>
<param-value>classpath:META-INF/spring/mvc-servlet-context.xml</param-value>
</init-param>
<load-on-startup>1</load-on-startup>
</servlet>