【问题标题】:Method configure(WebSecurity web) in Spring Security doesn't workSpring Security 中的方法 configure(WebSecurity web) 不起作用
【发布时间】:2020-05-12 15:39:04
【问题描述】:

我的 Spring Security 配置有问题,方法 configure(WebSecurity) 不能正常工作,下面是我的源代码:

@Override
protected void configure(HttpSecurity http) throws Exception {
    http.addFilter(jwtAuthenticationTokenFilter())
    .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS);
}

@Override
public void configure(WebSecurity web)  {
    web.ignoring().antMatchers("/auth", 
            "/v2/api-docs", 
            "/swagger-resources/**", 
            "/configuration/**", 
            "/swagger-ui.html",
            "/webjars/**",
            "/", "/refreshconfig", "/*.html", "/*.gif", "/favicon.ico", "/**/*.html", "/**/*.gif",
            "/**/*.css", "/**/*.js");
}


public class JwtAuthenticationTokenFilter extends BasicAuthenticationFilter {

private static final Logger log = LoggerFactory.getLogger(JwtAuthenticationTokenFilter.class);

@Autowired
private JwtTokenUtil jwtTokenUtil;

public JwtAuthenticationTokenFilter(JwtTokenUtil jwtTokenUtil, AuthenticationManager authenticationManager) {
    super(authenticationManager);
}

@Override
protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain filterChain)
        throws IOException, ServletException {

    String token = request.getHeader(JwtTokenUtil.TOKEN_HEADER);
    Authentication authentication = null;

    try {
        if (StringUtils.isNotBlank(token) && token.startsWith(JwtTokenUtil.TOKEN_PREFIX)) {
            log.info("JWT found {}", token);
            authentication = jwtTokenUtil.getAuthentication(token.replace(JwtTokenUtil.TOKEN_PREFIX, ""));
            SecurityContextHolder.getContext().setAuthentication(authentication);
        } else if (SecurityContextHolder.getContext().getAuthentication() != null
                && SecurityContextHolder.getContext().getAuthentication().isAuthenticated()) {
            log.info("User already authenticated {}",
                    SecurityContextHolder.getContext().getAuthentication().getPrincipal());
        } else {
            log.info("Invalid JWT {}", token);
        }
        filterChain.doFilter(request, response);
    } catch (ExpiredJwtException ex) {
        response.setContentType("application/json");
        response.setStatus(HttpStatus.SC_INSUFFICIENT_SPACE_ON_RESOURCE);
        ErrorObj err = new ErrorObj(GamblingErrors.UNAUTHORIZED.getCode(), ex.getMessage());
        log.info("OUT ERROR END: {}", err.toString());
        response.getOutputStream().println(err.toString());
    } catch (UnsupportedJwtException | MalformedJwtException | SignatureException | IllegalArgumentException ex) {
        response.setContentType("application/json");
        response.setStatus(HttpStatus.SC_UNAUTHORIZED);
        ErrorObj err = new ErrorObj(GamblingErrors.UNAUTHORIZED.getCode(), ex.getMessage());
        log.info("OUT ERROR END: {}", err.toString());
        response.getOutputStream().println(err.toString());
    }
}

}

即使使用configure(WebSecurity web) 方法,在configure(HttpSecurity) 添加的过滤器仍然适用于所有资源,不包括web.ignoring。 有人可以告诉我为什么它不起作用吗?

【问题讨论】:

  • 请在本文中包含 jwtAuthenticationTokenFilter 的源代码!
  • 我添加了 jwtAuthenticationTokenFilter 的源代码
  • JwtAuthenticationTokenFilter 是用@Service 还是@Component 注解的?
  • 不,它没有注释

标签: spring-security web-config


【解决方案1】:

从问题中不完整的源代码来看,我可能会建议 Spring BootJwtAuthenticationTokenFilter 类自动放入过滤器链中。因此,尽管在安全配置中的 ignoring() 方法中排除 /auth/ 是正确的,但这还不足以阻止过滤器在 Spring Boot 本身的上下文中发生。解决方案是从jwtAuthenticationTokenFilter()方法中删除注解@Bean或者按照Spring Security filter chain not ignoring specified path中解释的其他方式

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2018-08-12
    • 1970-01-01
    • 2021-12-15
    • 2012-01-02
    • 2017-08-19
    • 2012-01-01
    • 2017-06-08
    • 2018-06-26
    相关资源
    最近更新 更多