我正在将spring security与使用sitemesh的web项目集成。我可以带登录页面,但在身份验证后它不会重定向到target-url。
以下是来自网络项目的web.xml。
<?xml version="1.0" encoding="UTF-8"?>
<web-app version="2.5" xmlns="http://java.sun.com/xml/ns/javaee"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd">
<filter>
<filter-name>springSecurityFilterChain</filter-name>
<filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
</filter>
<filter-mapping>
<filter-name>springSecurityFilterChain</filter-name>
<url-pattern>/*</url-pattern>
</filter-mapping>
<context-param>
<param-name>contextConfigLocation</param-name>
<param-value>
classpath:applicationContext-persistance.xml
classpath*:applicationContext.xml
classpath:spring-security.xml
</param-value>
</context-param>
<listener>
<listener-class>org.springframework.web.context.ContextLoaderListener</listener-class>
</listener>
<!-- Processes application requests -->
<servlet>
<servlet-name>appServlet</servlet-name>
<servlet-class>org.springframework.web.servlet.DispatcherServlet</servlet-class>
<init-param>
<param-name>contextConfigLocation</param-name>
<param-value>/WEB-INF/spring/appServlet/servlet-context.xml</param-value>
</init-param>
<load-on-startup>1</load-on-startup>
</servlet>
<servlet-mapping>
<servlet-name>appServlet</servlet-name>
<url-pattern>/</url-pattern>
</servlet-mapping>
<!--
<servlet-mapping>
<servlet-name>appServlet</servlet-name>
<url-pattern>/*.app</url-pattern>
</servlet-mapping>
-->
<!-- <servlet-mapping>
<servlet-name>appServlet</servlet-name>
<url-pattern>/index.html</url-pattern>
</servlet-mapping>
-->
<!-- Sitemesh -->
<filter>
<filter-name>sitemesh</filter-name>
<filter-class>
com.opensymphony.module.sitemesh.filter.PageFilter
</filter-class>
</filter>
<!-- <filter-mapping>
<filter-name>sitemesh</filter-name>
<url-pattern>/app/*</url-pattern>
</filter-mapping> -->
<filter-mapping>
<filter-name>sitemesh</filter-name>
<url-pattern>/*</url-pattern>
</filter-mapping>
<!--<welcome-file-list><welcome-file>index.jsp</welcome-file></welcome-file-list>-- >
</web-app>
以下是AppSecurity项目的spring-security.xml。
<security:http auto-config="true" use-expressions="true">
<security:form-login login-page="/login"
default-target-url="/index.html" always-use-default-target="true"
authentication-failure-url="/loginfailed"
authentication-success-handler-ref="postSuccessAuthHandler" />
<security:logout invalidate-session="true" logout-success-url="/app" />
<!-- <security:remember-me /> -->
<security:intercept-url pattern="/app" access="isAuthenticated()" />
<security:intercept-url pattern="/app/**" access="isAuthenticated()" />
<!-- <security:intercept-url pattern="/acct/app"
access="isAuthenticated()" /> -->
</security:http>
<!--<bean id="postSuccessAuthHandler"
class="org.springframework.security.web.authentication.SavedRequestAwareAuthentication SuccessHandler">
<property name="defaultTargetUrl" value="/index.html" />-->
我的loginpage.jsp位于webapp \ WEB-INF \ views中,由sitemesh装饰 -
<div id="mainNav"><div class="navWrapper">
<ul>
<li class="${fn:startsWith(menuPath, 'M')? 'selected':'first'}"><a
href="${pageContext.request.contextPath}/index.html"><spring:message
code="mnu.home" /></a></li>
处理此问题的LoginController.java是 -
@RequestMapping(value = "/login", method = RequestMethod.GET)
public String login(ModelMap model) {
return "loginpage";
}
所以这里的问题是访问网址 - http://localhost:8080/acct/app,它会显示登录页面。验证成功后,它会尝试重定向到http://localhost:8080/acct/app。不知道为什么会发生这种情况,而不是 default-target-url 中提到的 /index.html 。
来自tomcat的日志行显示 -
DEBUG: org.springframework.web.servlet.DispatcherServlet - DispatcherServlet with name 'appServlet' processing GET request for
[/acct/login]
DEBUG: org.springframework.web.servlet.mvc.annotation.DefaultAnnotationHandlerMapping - Mapping [/login] to HandlerExecutionCh
ain with handler [com.mycomp.security.controller.LoginController@1e5348f] and 2 interceptors
DEBUG: org.springframework.web.servlet.DispatcherServlet - Last-Modified value for [/acct/login] is: -1
DEBUG: org.springframework.web.bind.annotation.support.HandlerMethodInvoker - Invoking request handler method: public java.lan
g.String com.mycomp.security.controller.LoginController.login(org.springframework.ui.ModelMap)
DEBUG: org.springframework.web.servlet.DispatcherServlet - Rendering view [org.springframework.web.servlet.view.JstlView: name
'loginpage'; URL [/WEB-INF/views/loginpage.jsp]] in DispatcherServlet with name 'appServlet'
DEBUG: org.springframework.web.servlet.view.JstlView - Forwarding to resource [/WEB-INF/views/loginpage.jsp] in InternalResour
ceView 'loginpage'
DEBUG: org.springframework.web.servlet.DispatcherServlet - Successfully completed request
DEBUG: org.springframework.web.servlet.DispatcherServlet - DispatcherServlet with name 'appServlet' processing GET request for
[/acct/app]
WARN : org.springframework.web.servlet.PageNotFound - No mapping found for HTTP request with URI [/acct/app] in DispatcherServ
let with name 'appServlet'
DEBUG: org.springframework.web.servlet.DispatcherServlet - Successfully completed request
DEBUG: org.springframework.web.servlet.DispatcherServlet - DispatcherServlet with name 'appServlet' processing GET request for
[/acct/app]
WARN : org.springframework.web.servlet.PageNotFound - No mapping found for HTTP request with URI [/acct/app] in DispatcherServ
let with name 'appServlet'
DEBUG: org.springframework.web.servlet.DispatcherServlet - Successfully completed request
通过将DispatcherServlet映射更改为/而不是/index.html来尝试调试很多。将sitemesh过滤器映射更改为/ *而不是/index.html。 如果与示例Web项目集成(没有sitemesh),则相同的AppSecurity项目可以正常工作。 不知道我在sitemesh项目中缺少什么。任何帮助都会很棒。
答案 0 :(得分:1)
"default-target-url=/index.html"
这将在您成功登录后重定向页面。
例如,您可以在想要重定向到所需页面之前,在控制器中重定向到/home.html
或使用/home.do
来执行某些逻辑。
@RequestMapping(value = "/home.do", method = RequestMethod.POST)
public String login(ModelMap model) {
//TODO logic ...
return "/home.html";
}