我无法在 spring security 3 中允许静态资源(如 js、css、图像)。下面是我的配置文件。

<beans xmlns="http://www.springframework.org/schema/beans" 
    xmlns:security="http://www.springframework.org/schema/security" 
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
    xsi:schemaLocation="http://www.springframework.org/schema/beans  
              http://www.springframework.org/schema/beans/spring-beans-3.1.xsd 
              http://www.springframework.org/schema/security  
              http://www.springframework.org/schema/security/spring-security-3.1.xsd"> 
 
 
 
    <bean id="authenticationEntryPoint" 
        class="org.springframework.security.web.authentication.LoginUrlAuthenticationEntryPoint"> 
        <property name="loginFormUrl" value="/login.htm" /> 
    </bean> 
 
    <security:http security="none" pattern="/js/ajaxScript.js"/>    
    <security:http security="none" pattern="/js/commonScript.js"/>   
 
    <bean class="org.springframework.security.web.access.expression.DefaultWebSecurityExpressionHandler" /> 
 
    <security:http auto-config="false" entry-point-ref="authenticationEntryPoint" disable-url-rewriting="true" use-expressions="true"> 
 
        <security:custom-filter position="FORM_LOGIN_FILTER" 
            ref="customAuthenticationProcessingFilter" /> 
 
<!--        <security:intercept-url pattern="/js/jquery.min.js" access="isAuthenticated()" /> --> 
<!--        <security:intercept-url pattern="/js/**/**" access="permitAll" />  --> 
        <security:intercept-url pattern="/displayAdminPage.htm" access="hasRole('ROLE_ADMIN')" /> 
        <security:access-denied-handler ref="accessDeniedHandler" /> 
 
    </security:http> 
 
    <security:authentication-manager alias="authenticationManager"> 
       <security:authentication-provider user-service-ref="customUserDetailService"> 
       </security:authentication-provider> 
    </security:authentication-manager>  
 
    <bean id="customUserDetailService" class="com.qait.cdl.services.impl.UserSecurityServiceImpl"> 
        <property name="userDao" ref="userDao"/> 
       </bean> 
 
    <bean id="customAuthenticationProcessingFilter" 
        class="com.qait.cdl.services.impl.CustomAuthenticationProcessingFilter"> 
        <property name="authenticationManager" ref="authenticationManager" /> 
    </bean> 
 
    <bean id="accessDeniedHandler" 
        class="org.springframework.security.web.access.AccessDeniedHandlerImpl"> 
        <property name="errorPage" value="/WEB-INF/jsp/customLoginForm/denied.jsp" /> 
    </bean> 
</beans>  

我不知道我哪里错了?我希望 spring security 必须绕过所有 js、图像、css。JS 文件存在于 webapp/js 和 webapp/js/commonScript 文件夹中。图像存在于 webapp/图片文件夹。

下面是我的web.xml

<?xml version="1.0" encoding="UTF-8"?> 
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
    xmlns="http://java.sun.com/xml/ns/javaee" xmlns:web="http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd" 
    xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd" 
    id="WebApp_ID" version="2.5"> 
    <display-name>cdl</display-name> 
    <servlet> 
        <servlet-name>dispatcher</servlet-name> 
        <servlet-class>org.springframework.web.servlet.DispatcherServlet</servlet-class> 
        <load-on-startup>1</load-on-startup> 
    </servlet> 
    <servlet-mapping> 
        <servlet-name>dispatcher</servlet-name> 
        <url-pattern>/</url-pattern> 
    </servlet-mapping> 
 
    <servlet> 
        <servlet-name>startUpServlet</servlet-name> 
        <servlet-class>com.qait.cdl.commons.startup.StartUpServlet</servlet-class> 
        <load-on-startup>2</load-on-startup> 
    </servlet> 
    <servlet-mapping> 
        <servlet-name>startUpServlet</servlet-name> 
        <url-pattern>/startUpServlet.htm</url-pattern> 
    </servlet-mapping> 
 
    <welcome-file-list> 
        <welcome-file>redirect.jsp</welcome-file> 
    </welcome-file-list> 
 
    <context-param> 
        <param-name>CDL_ENV</param-name> 
        <param-value>staging</param-value> 
    </context-param> 
 
    <listener> 
        <listener-class>com.qait.cdl.commons.startup.CdlContextListner</listener-class> 
    </listener> 
 
    <!-- Session timeout --> 
    <session-config> 
        <session-timeout>600</session-timeout> 
    </session-config> 
 
    <filter> 
        <filter-name>springSecurityFilterChain</filter-name> 
        <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class> 
    </filter> 
 
    <filter-mapping> 
        <filter-name>springSecurityFilterChain</filter-name> 
        <url-pattern>/*</url-pattern> 
    </filter-mapping> 
 
    <listener> 
        <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class> 
    </listener> 
 
    <context-param> 
     <param-name>contextConfigLocation</param-name> 
     <param-value> 
     WEB-INF/applicationContext.xml 
<!--      WEB-INF/SpringSecurityConfig.xml --> 
     WEB-INF/dispatcher-servlet.xml 
     </param-value> 
    </context-param> 
 
</web-app> 

请您参考如下方法:

更新:

从更新的问题来看,是静态资源映射的问题。我们需要在 spring 配置中添加静态资源映射,因为所有请求都传递给调度程序 servlet。

需要在dispatcher-servelt.xml中添加如下内容

<mvc:resources mapping="/js/**" location="/js/" /> 


评论关闭
IT虾米网

微信公众号号:IT虾米 (左侧二维码扫一扫)欢迎添加!