无法让@Secured在Spring MVC中工作

use*_*028 6 java spring spring-mvc spring-security restful-architecture

我正在使用Spring MVC来公开RESTful服务.我已经通过HTTPBasicAuthentication启用了身份验证,并且使用<security:http>i可以控制哪些角色可以访问URL.

现在我想使用@Secured注释.我试图将它添加到Controller方法但它不起作用.它什么都不做.

这是我的Controller班级:

@Controller
@RequestMapping("/*")
public class HomeController {
private static final Logger logger = LoggerFactory.getLogger(HomeController.class);

private static final String USERS = "/users";
private static final String USER = USERS+"/{userId:.*}";

    @RequestMapping(value=USER, method=RequestMethod.GET)
    @Secured(value = {"ROLE_ADMIN"})
    public @ResponseBody User signin(@PathVariable String userId) {
        logger.info("GET users/"+userId+" received");
        User user= service.getUser(userId);
        if(user==null)
                throw new ResourceNotFoundException();
        return user;
    }
}
Run Code Online (Sandbox Code Playgroud)

这是我的security-context.xml:

<http auto-config='true'>
    <intercept-url pattern="/**" access="ROLE_USER"/>
</http>

<global-method-security secured-annotations="enabled" />

<authentication-manager>
    <authentication-provider>
        <user-service>
            <user name="admin@somedomain.com" password="admin"
                authorities="ROLE_USER, ROLE_ADMIN" />
            <user name="user@somedomain.com" password="pswd"
                authorities="ROLE_USER" />
        </user-service>
    </authentication-provider>
</authentication-manager>
Run Code Online (Sandbox Code Playgroud)

我的root-context.xml:

<context:component-scan base-package="org.mypackage" />

<import resource="database/DataSource.xml"/> 

<import resource="database/Hibernate.xml"/>

<import resource="beans-context.xml"/> 

<import resource="security-context.xml"/> 
Run Code Online (Sandbox Code Playgroud)

一切正常,但如果我添加@Secured,它什么都不做:我也可以使用user@somedomain.com访问安全方法,它没有ROLE_ADMIN权限.我已经尝试过移动<security:global-method-security>到root-context.xml,这是行不通的.我也尝试通过<security:http>标签保护相同的方法,它工作正常,但我想使用@Secured注释.

谢谢.

编辑:我在appServlet子目录中也有servlet-context.xml一个controllers.xml配置文件.

这是servlet-context.xml:

<mvc:resources mapping="/resources/**" location="/resources/" />

<beans:bean class="org.springframework.web.servlet.view.InternalResourceViewResolver">
    <beans:property name="prefix" value="/WEB-INF/views/" />
    <beans:property name="suffix" value=".jsp" />
</beans:bean>

<beans:import resource="controllers.xml" />
Run Code Online (Sandbox Code Playgroud)

而且controllers.xml:

<context:component-scan base-package="org.mose.emergencyalert.controllers" />

<beans:bean id="multipartResolver" class="org.springframework.web.multipart.commons.CommonsMultipartResolver" />     

<beans:bean id="homeController" class="org.mose.emergencyalert.controllers.HomeController"/> 
Run Code Online (Sandbox Code Playgroud)

use*_*028 9

解决了,我添加了<global-method-security>标签servlet-context.xml,而不是security-context.xml.

这是新的security-context.xml:

<annotation-driven />

<security:global-method-security secured-annotations="enabled"/>

<resources mapping="/resources/**" location="/resources/" />

<beans:bean class="org.springframework.web.servlet.view.InternalResourceViewResolver">
    <beans:property name="prefix" value="/WEB-INF/views/" />
    <beans:property name="suffix" value=".jsp" />
</beans:bean>
Run Code Online (Sandbox Code Playgroud)

注意:现在Eclipse警告我<security:global-method-security>:" advises org.mypackage.HomeController.signin(String, Principal)",证明@Secured现在正在运行.