使用名称AuthenticationManager创建bean时出错

时间:2015-01-20 09:05:06

标签: spring spring-mvc spring-security

我正在开发一个使用Spring-Security的Spring-MVC应用程序。在登录应用程序中,我必须使用2个登录URL

  • / j_spring_security_check_for_person            AND
  • / j_spring_security_check_for_group

对我已实现UserDetails和userDetailsS​​ervice的数据库进行登录URL检查。要连接这两个url用于登录,我使用的是springSecurityFilterChain。不幸的是,它没有用。我从2天开始遇到这个问题,我可能会犯一些愚蠢的错误。请检查日志和xml,

错误日志:

Caused by: org.springframework.beans.factory.BeanCreationException: Error creating bean with name 'org.springframework.security.authenticationManager': Could not resolve matching constructor (hint: specify index/type/name arguments for simple parameters to avoid type ambiguities)
    at org.springframework.beans.factory.support.ConstructorResolver.autowireConstructor(ConstructorResolver.java:239)
    at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.autowireConstructor(AbstractAutowireCapableBeanFactory.java:1114)
    at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBeanInstance(AbstractAutowireCapableBeanFactory.java:1017)
    at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.doCreateBean(AbstractAutowireCapableBeanFactory.java:504)
    at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBean(AbstractAutowireCapableBeanFactory.java:475)
    at org.springframework.beans.factory.support.AbstractBeanFactory$1.getObject(AbstractBeanFactory.java:302)
    at org.springframework.beans.factory.support.DefaultSingletonBeanRegistry.getSingleton(DefaultSingletonBeanRegistry.java:228)
    at org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:298)
    at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:193)
    at org.springframework.security.config.authentication.AuthenticationManagerFactoryBean.getObject(AuthenticationManagerFactoryBean.java:28)
    at org.springframework.security.config.authentication.AuthenticationManagerFactoryBean.getObject(AuthenticationManagerFactoryBean.java:20)
    at org.springframework.beans.factory.support.FactoryBeanRegistrySupport.doGetObjectFromFactoryBean(FactoryBeanRegistrySupport.java:168)

安全应用context.xml中

<security:http create-session="ifRequired" use-expressions="true"
               auto-config="true" disable-url-rewriting="true">
    <security:form-login login-page="/" default-target-url="/canvas/list"
               always-use-default-target="false"  authentication-failure-url="/denied.jsp" />
<security:logout logout-success-url="/" delete-cookies="JSESSIONID"
                     invalidate-session="true" logout-url="/j_spring_security_logout"/>
</security:http>



<bean id="springSecurityFilterChain" class="org.springframework.security.web.FilterChainProxy">
        <security:filter-chain-map path-type="ant">
            <security:filter-chain pattern="/**" filters="authenticationProcessingFilterForPersonal, authenticationProcessingFilterForGroup"/>
        </security:filter-chain-map>
    </bean>


    <bean id="authenticationProcessingFilterForPersonal"
          class="org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter">
        <property name="authenticationManager" ref="authenticationManagerForPersonal"/>
        <property name="filterProcessesUrl" value="/j_spring_security_check_for_person" />
    </bean>

    <bean id="authenticationProcessingFilterForGroup"
          class="org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter">
        <property name="authenticationManager" ref="authenticationManagerForGroup"/>
        <property name="filterProcessesUrl" value="/j_spring_security_check_for_group"/>
    </bean>


    <bean id="authenticationManagerForPersonal" class="org.springframework.security.authentication.ProviderManager">
    <property name="providers">
            <list>
                <bean class="org.springframework.security.authentication.dao.DaoAuthenticationProvider">
                    <property name="userDetailsService">
                        <ref bean="userDetailsService"/>
                    </property>
                    <property name="passwordEncoder" ref="encoder"/>
                </bean>
            </list>
        </property>
    </bean>



    <bean id="authenticationManagerForGroup" class="org.springframework.security.authentication.ProviderManager">
        <property name="providers">
            <list>
                <bean class="org.springframework.security.authentication.dao.DaoAuthenticationProvider">
                    <property name="userDetailsService">
                        <ref bean="groupDetailsService"/>
                    </property>
                    <property name="passwordEncoder" ref="encoder"/>
                </bean>
            </list>
        </property>
    </bean>

    <security:authentication-manager alias="authenticationManager">
        <security:authentication-provider ref="authenticationManagerForPersonal"/>
        <security:authentication-provider ref="authenticationManagerForGroup"/>
    </security:authentication-manager>


    <beans:bean id="encoder"
                class="org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder">
        <beans:constructor-arg name="strength" value="11" />
    </beans:bean>

如果我用下面的代码片段替换身份验证管理器代码,我不会收到错误,但是2个登录URL没有注册:

<security:authentication-manager alias="authenticationManager">
            <security:authentication-provider user-service-ref="userDetailsService">
                <security:password-encoder ref="encoder"/>
            </security:authentication-provider>
            <security:authentication-provider user-service-ref="groupDetailsService">
                <security:password-encoder ref="encoder"/>
            </security:authentication-provider>
        </security:authentication-manager>-->

2 个答案:

答案 0 :(得分:1)

authenticationManagerForPersonalauthenticationManagerForGroup属于bean类型ProviderManager。这是错的。您必须将这些bean声明为DaoAuthenticationProvider类型。 请仔细查看我的spring security配置。

答案 1 :(得分:0)

如异常消息所示,您的authenticationManagerForGroupauthenticationManagerForPersonal配置无效。从类型签名和JavaDoc中可以发现,ProviderManagerAuthenticationManager列表作为构造函数参数,但您将AuthenticationManager配置为属性参数。

您应该可以通过将<property name="providers">元素替换为<constructor-arg>来实现此目的。