gpt4 book ai didi

javascript - 无法在 spring security 3 中允许静态资源

转载 作者:数据小太阳 更新时间:2023-10-29 06:07:13 24 4
gpt4 key购买 nike

我无法在 spring security 3 中允许静态资源(如 js、css、图像)。下面是我的配置文件。

<beans xmlns="http://www.springframework.org/schema/beans"
xmlns:security="http://www.springframework.org/schema/security"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://www.springframework.org/schema/beans
http://www.springframework.org/schema/beans/spring-beans-3.1.xsd
http://www.springframework.org/schema/security
http://www.springframework.org/schema/security/spring-security-3.1.xsd">



<bean id="authenticationEntryPoint"
class="org.springframework.security.web.authentication.LoginUrlAuthenticationEntryPoint">
<property name="loginFormUrl" value="/login.htm" />
</bean>

<security:http security="none" pattern="/js/ajaxScript.js"/>
<security:http security="none" pattern="/js/commonScript.js"/>

<bean class="org.springframework.security.web.access.expression.DefaultWebSecurityExpressionHandler" />

<security:http auto-config="false" entry-point-ref="authenticationEntryPoint" disable-url-rewriting="true" use-expressions="true">

<security:custom-filter position="FORM_LOGIN_FILTER"
ref="customAuthenticationProcessingFilter" />

<!-- <security:intercept-url pattern="/js/jquery.min.js" access="isAuthenticated()" /> -->
<!-- <security:intercept-url pattern="/js/**/**" access="permitAll" /> -->
<security:intercept-url pattern="/displayAdminPage.htm" access="hasRole('ROLE_ADMIN')" />
<security:access-denied-handler ref="accessDeniedHandler" />

</security:http>

<security:authentication-manager alias="authenticationManager">
<security:authentication-provider user-service-ref="customUserDetailService">
</security:authentication-provider>
</security:authentication-manager>

<bean id="customUserDetailService" class="com.qait.cdl.services.impl.UserSecurityServiceImpl">
<property name="userDao" ref="userDao"/>
</bean>

<bean id="customAuthenticationProcessingFilter"
class="com.qait.cdl.services.impl.CustomAuthenticationProcessingFilter">
<property name="authenticationManager" ref="authenticationManager" />
</bean>

<bean id="accessDeniedHandler"
class="org.springframework.security.web.access.AccessDeniedHandlerImpl">
<property name="errorPage" value="/WEB-INF/jsp/customLoginForm/denied.jsp" />
</bean>
</beans>

我不知道我哪里错了?我希望 spring security 必须绕过所有 js、图像、css。JS 文件存在于 webapp/js 和 webapp/js/commonScript 文件夹中。图像存在于 webapp/图片文件夹。

下面是我的web.xml

<?xml version="1.0" encoding="UTF-8"?>
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns="http://java.sun.com/xml/ns/javaee" xmlns:web="http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd"
xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd"
id="WebApp_ID" version="2.5">
<display-name>cdl</display-name>
<servlet>
<servlet-name>dispatcher</servlet-name>
<servlet-class>org.springframework.web.servlet.DispatcherServlet</servlet-class>
<load-on-startup>1</load-on-startup>
</servlet>
<servlet-mapping>
<servlet-name>dispatcher</servlet-name>
<url-pattern>/</url-pattern>
</servlet-mapping>

<servlet>
<servlet-name>startUpServlet</servlet-name>
<servlet-class>com.qait.cdl.commons.startup.StartUpServlet</servlet-class>
<load-on-startup>2</load-on-startup>
</servlet>
<servlet-mapping>
<servlet-name>startUpServlet</servlet-name>
<url-pattern>/startUpServlet.htm</url-pattern>
</servlet-mapping>

<welcome-file-list>
<welcome-file>redirect.jsp</welcome-file>
</welcome-file-list>

<context-param>
<param-name>CDL_ENV</param-name>
<param-value>staging</param-value>
</context-param>

<listener>
<listener-class>com.qait.cdl.commons.startup.CdlContextListner</listener-class>
</listener>

<!-- Session timeout -->
<session-config>
<session-timeout>600</session-timeout>
</session-config>

<filter>
<filter-name>springSecurityFilterChain</filter-name>
<filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
</filter>

<filter-mapping>
<filter-name>springSecurityFilterChain</filter-name>
<url-pattern>/*</url-pattern>
</filter-mapping>

<listener>
<listener-class>org.springframework.web.context.ContextLoaderListener</listener-class>
</listener>

<context-param>
<param-name>contextConfigLocation</param-name>
<param-value>
WEB-INF/applicationContext.xml
<!-- WEB-INF/SpringSecurityConfig.xml -->
WEB-INF/dispatcher-servlet.xml
</param-value>
</context-param>

</web-app>

最佳答案

更新:

从更新的问题来看,是静态资源映射的问题。我们需要在 spring 配置中添加静态资源映射,因为所有请求都传递给调度程序 servlet。

需要在dispatcher-servelt.xml中添加如下内容

<mvc:resources mapping="/js/**" location="/js/" />

关于javascript - 无法在 spring security 3 中允许静态资源,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/16476004/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com