【发布时间】:2015-09-08 02:36:03
【问题描述】:
对我来说,没有生成 CSRF 令牌....我搜索了很多链接仍然没有找到解决方案
收到此错误
在请求参数“_csrf”上发现无效的 CSRF 令牌“null” 或标题“X-CSRF-TOKEN”。
<%@ page language="java" contentType="text/html; charset=UTF-8"
pageEncoding="UTF-8"%>
<%@ taglib uri="http://java.sun.com/jsp/jstl/core" prefix="c" %>
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Insert title here</title>
</head>
<body>
<c:url value="/j_spring_security_check" var="postUrl"/>
<form action="${postUrl}" method="post" >
<c:if test="${param.error != null}">
<p>Invalid username and password.</p>
</c:if>
<c:if test="${param.logout != null}">
<p>You have been logged out.</p>
</c:if>
<p>
<label for="username">Username</label>
<input type="text"
id="username" name="username" />
</p>
<p>
<label for="password">Password</label> <input type="password"
id="password" name="password" />
</p>
<input type="text"
name="${_csrf.parameterName}"
value="${_csrf.token}" />
<button type="submit" class="btn">Log in</button>
</form>
</body>
</html>
在 pom.xml 中
<dependency>
<groupId>org.springframework.security</groupId>
<artifactId>spring-security-core</artifactId>
<version>4.0.1.RELEASE</version>
</dependency>
<dependency>
<groupId>org.springframework.security</groupId>
<artifactId>spring-security-config</artifactId>
<version>4.0.1.RELEASE</version>
</dependency>
<dependency>
<groupId>org.springframework.security</groupId>
<artifactId>spring-security-web</artifactId>
<version>4.0.1.RELEASE</version>
</dependency>
【问题讨论】:
-
你有configured it吗?
-
如果您使用 spring-form
<form:form>,它将为您添加 csrf 令牌(假设您已正确设置) -
这里有同样的问题。这是一个 csrf 令牌,他应该在哪里给出路径,因为你建议
标签: spring maven spring-security