Java:Spring security 3 角色层次结构
Posted
技术标签:
【中文标题】Java:Spring security 3 角色层次结构【英文标题】:Java: Spring security 3 Role hierarchy 【发布时间】:2011-11-03 19:42:10 【问题描述】:我正在使用 Spring 框架 mvc 3 + spring security 3。 我想在我的 Spring Security 中启用角色层次结构。 根据http://static.springsource.org/spring-security/site/docs/3.1.x/reference/authz-arch.html我应该写
<bean id="roleVoter" class="org.springframework.security.access.vote.RoleHierarchyVoter">
<constructor-arg ref="roleHierarchy" />
</bean>
<bean id="roleHierarchy"
class="org.springframework.security.access.hierarchicalroles.RoleHierarchyImpl">
<property name="hierarchy">
ROLE_ADMIN > ROLE_STAFF
ROLE_STAFF > ROLE_USER
ROLE_USER > ROLE_GUEST
</property>
</bean>
但是我应该把它放在哪里呢?我试图把它放到我的 app-security.xml 中:
<beans:beans xmlns="http://www.springframework.org/schema/security"
xmlns:beans="http://www.springframework.org/schema/beans"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://www.springframework.org/schema/beans
http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
http://www.springframework.org/schema/security
http://www.springframework.org/schema/security/spring-security-3.0.xsd">
<http>
<intercept-url pattern="/entryPost/**" access="ROLE_USER" requires-channel="https"/>
<intercept-url pattern="/entryDelete/**" access="ROLE_ADMIN" requires-channel="https"/>
<intercept-url pattern="/commentDelete/**" access="ROLE_ADMIN" requires-channel="https"/>
<intercept-url pattern="/login" access="ROLE_ANONYMOUS" requires-channel="https"/>
<form-login login-page="/login" default-target-url="/entryList/1" authentication-failure-url="/login?error=true" />
<logout logout-success-url="/login" />
<session-management>
<concurrency-control max-sessions="1" />
</session-management>
<access-denied-handler error-page="/accessDenied"/>
</http>
<authentication-manager>
<authentication-provider>
<jdbc-user-service data-source-ref="dataSource"
users-by-username-query="SELECT username,password,'true' as enabled FROM member WHERE username=?"
authorities-by-username-query="SELECT member.username,role FROM member,memberRole WHERE member.username=? AND member.id=memberRole.member_id"/>
</authentication-provider>
</authentication-manager>
<bean id="roleVoter" class="org.springframework.security.access.vote.RoleHierarchyVoter">
<constructor-arg ref="roleHierarchy" />
</bean>
<bean id="roleHierarchy" class="org.springframework.security.access.hierarchicalroles.RoleHierarchyImpl">
<property name="hierarchy">
ROLE_ADMIN > ROLE_STAFF
ROLE_STAFF > ROLE_USER
ROLE_USER > ROLE_GUEST
</property>
</bean>
但它不起作用:HTTP 状态 404。
当我把它放到 app-servlet.xml 中时:
<?xml version="1.0" encoding="UTF-8"?>
<beans xmlns="http://www.springframework.org/schema/beans"
xmlns:mvc="http://www.springframework.org/schema/mvc"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:context="http://www.springframework.org/schema/context"
xsi:schemaLocation="http://www.springframework.org/schema/beans
http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
http://www.springframework.org/schema/context
http://www.springframework.org/schema/context/spring-context-3.0.xsd
http://www.springframework.org/schema/mvc
http://www.springframework.org/schema/mvc/spring-mvc-3.0.xsd">
<context:component-scan base-package="rus.web"/>
<bean id="entryValidator" class="rus.domain.EntryValidator"/>
<bean id="commentValidator" class="rus.domain.CommentValidator"/>
<mvc:annotation-driven/>
<mvc:resources mapping="/resources/**" location="/resources/"/>
<bean class="org.springframework.web.servlet.view.InternalResourceViewResolver">
<property name="prefix" value="/WEB-INF/jsp/"/>
<property name="suffix" value=".jsp"/>
</bean>
<bean id="messageSource" class="org.springframework.context.support.ResourceBundleMessageSource">
<property name="basename" value="messages"/>
</bean>
<!--<bean class="org.springframework.web.servlet.handler.SimpleMappingExceptionResolver">
<property name="defaultErrorView" value="error"/>
</bean> -->
<bean id="roleVoter" class="org.springframework.security.access.vote.RoleHierarchyVoter">
<constructor-arg ref="roleHierarchy" />
</bean>
<bean id="roleHierarchy" class="org.springframework.security.access.hierarchicalroles.RoleHierarchyImpl">
<property name="hierarchy">
ROLE_ADMIN > ROLE_STAFF
ROLE_STAFF > ROLE_USER
ROLE_USER > ROLE_GUEST
</property>
</bean>
</beans>
抛出异常:
org.springframework.beans.factory.xml.XmlBeanDefinitionStoreException:来自 ServletContext 资源 [/WEB-INF/rus-servlet.xml] 的 XML 文档中的第 35 行无效;嵌套异常是 org.xml.sax.SAXParseException: cvc-complex-type.2.3: Element 'property' cannot have character [children],因为该类型的内容类型是 element-only。
org.xml.sax.SAXParseException: cvc-complex-type.2.3: 元素 'property' 不能有字符 [children],因为该类型的内容类型是仅元素。
我应该怎么做才能解决这个问题?
【问题讨论】:
我遇到了同样的问题。我按照这里的说明解决了这个问题:***.com/questions/7809313/… 【参考方案1】:文档有误,这是无效的:
<property name="hierarchy">
ROLE_ADMIN > ROLE_STAFF
ROLE_STAFF > ROLE_USER
ROLE_USER > ROLE_GUEST
</property>
你需要把内容包裹在<value>
里面:
<property name="hierarchy">
<value>
ROLE_ADMIN > ROLE_STAFF
ROLE_STAFF > ROLE_USER
ROLE_USER > ROLE_GUEST
</value>
</property>
我建议在SpringSource JIRA 上提出问题,要求他们修复文档。
【讨论】:
好的,它有帮助,但没有那么多...当我尝试使用 ROLE_ADMIN 转到页面 entryPost/ (access="ROLE_USER") 时,它说:“访问被拒绝”。为什么会这样?以上是关于Java:Spring security 3 角色层次结构的主要内容,如果未能解决你的问题,请参考以下文章
具有角色的经过身份验证的用户的 Spring Security Java 配置
Spring 3,Spring Security,LDAP,如何向 LDAP 添加角色?
java spring security 3 修改权限 刷新内存
Spring Security(Java Config)登录 - 根据用户角色返回不同的 URL