小编xib*_*ian的帖子

spring @PreAuthorize 不适用于 @EnableGlobalMethodSecurity(prePostEnabled = true)

这是我的代码:

@Configuration
@ComponentScan(basePackages = "com.webapp")
@EnableWebSecurity
@EnableGlobalMethodSecurity(prePostEnabled = true)
public class SecurityConfig extends WebSecurityConfigurerAdapter {

 @Bean
    @Override
    public AuthenticationManager authenticationManagerBean() throws Exception {
        return super.authenticationManagerBean();
    }

@Override
protected void configure(HttpSecurity http) throws Exception {
    http.
       authorizeRequests().antMatchers("/resources/**").permitAll().
       antMatchers("/admin/**").hasRole("ADMIN").
       anyRequest().authenticated().
       and().
       formLogin().loginPage("/login").permitAll().
       and().
       logout().permitAll();
}

@Autowired
public void configureGlobal(UserDetailsService userDetailsService, AuthenticationManagerBuilder auth)
        throws Exception {

    auth.userDetailsService(userDetailsService);

}
}
Run Code Online (Sandbox Code Playgroud)

当请求 /admin/* 传入时,它将通过调用“antMatchers("/admin/**").hasRole("ADMIN") 来验证用户是否具有管理员角色。,但在我的控制器中,它不会检查用户是否具有 @PreAuthorize 的其他权限。

@Controller
@SessionAttributes({ "user" })
@RequestMapping(value = "/admin/user")
public class UserController {

static Logger logger = LoggerFactory.getLogger(UserController.class);

@Autowired
private …
Run Code Online (Sandbox Code Playgroud)

spring spring-mvc spring-security

5
推荐指数
1
解决办法
6850
查看次数

标签 统计

spring ×1

spring-mvc ×1

spring-security ×1