如何配置tomcat-users.xml来保护tomcat中的页面?

tho*_*ron 3 tomcat login admin

我正在尝试使用tomcat保护我的管理页面web.xml,tomcat-users.xml但它不起作用.登录表单出现但无法连接

这是web.xml在我的web/WEB_INF文件夹中:

<security-constraint>
    <web-resource-collection>
        <web-resource-name>Admin</web-resource-name>
        <url-pattern>/admin/*</url-pattern>
    </web-resource-collection>
    <auth-constraint>
        <role-name>admin</role-name>
    </auth-constraint>
</security-constraint>
<login-config>
    <auth-method>BASIC</auth-method>
    <realm-name>Admin</realm-name>
</login-config>
Run Code Online (Sandbox Code Playgroud)

tomcat-users.xml在服务器/ tomcat的/ conf目录/文件夹:

<tomcat-users>
   <role rolename="manager"/>
   <role rolename="tomcat"/>
   <role rolename="admin"/>
   <role rolename="role1"/>
   <user username="manager" password="manager" roles="manager"/>
   <user username="both" password="tomcat" roles="tomcat,role1"/>
   <user username="tomcat" password="tomcat" roles="tomcat"/>
   <user username="role1" password="tomcat" roles="role1"/>
   <user username="admin" password="admin" roles="admin"/>
</tomcat-users>
Run Code Online (Sandbox Code Playgroud)

任何的想法 ?

Jit*_*ute 11

可能迟到回答,但无论如何你在web.xml中缺少角色而且也不必提及领域,因此你的web.xml应该如下所示

<security-constraint>
   <web-resource-collection>
      <web-resource-name>Admin</web-resource-name>
      <url-pattern>/admin/*</url-pattern>
    </web-resource-collection>
    <auth-constraint>
      <role-name>admin</role-name>
    </auth-constraint>
 </security-constraint>
 <login-config>
       <auth-method>BASIC</auth-method>
      <!-- Please note following line .. its commented -->
      <!-- <realm-name>Admin</realm-name> -->
 </login-config>
 <!-- Following section was missing -->
 <security-role>
     <role-name>admin</role-name>
</security-role>
Run Code Online (Sandbox Code Playgroud)