线程:如何绕过

时间:2011-11-02 08:05:02

标签: spring spring-security oauth-2.0 intercept

i have  a spring configuration,
i want to access <intercept-url pattern="/trusted/**"   filters = "none" />   

没有过滤器     有没有办法访问     我使用filters =“none”时会出现此错误     org.springframework.beans.factory.parsing.BeanDefinitionParsingException:Config     使用问题:不再支持使用“filters ='none'”。请定义     你要排除的模式的单独元素和使用att     ribute“security ='none'”。|违规资源:ServletContext资源[/ WEB-INF /     弹簧servlet.xml中]

      <http  access-denied-page="/login.jsp" access-decision-manager-ref="accessDecisionManager" xmlns="http://www.springframework.org/schema/security">
            <intercept-url pattern="/photos" access="ROLE_USER,SCOPE_READ" />
            <intercept-url pattern="/photos/**" access="ROLE_USER,SCOPE_READ" />
    <!--        <intercept-url pattern="/trusted/**" access="ROLE_USER,SCOPE_TRUST" />-->
             <intercept-url pattern="/trusted/**"   filters = "none" />
            <intercept-url pattern="/oauth/token" access="IS_AUTHENTICATED_ANONYMOUSLY" />
            <intercept-url pattern="/oauth/**" access="ROLE_USER" />
            <intercept-url pattern="/request_token_authorized.jsp" access="ROLE_USER,DENY_OAUTH" />
            <intercept-url pattern="/**" access="IS_AUTHENTICATED_ANONYMOUSLY,DENY_OAUTH" />

            <form-login authentication-failure-url="/login.jsp" default-target-url="/index.jsp" login-page="/login.jsp"
                login-processing-url="/login.do" />
            <logout logout-success-url="/index.jsp" logout-url="/logout.do" />
            <anonymous />
            <custom-filter ref="oauth2ProviderFilter" after="EXCEPTION_TRANSLATION_FILTER" />
        </http>

1 个答案:

答案 0 :(得分:6)

您需要添加额外的http元素:

<http pattern="/trusted/**" secure="none">
</http>