gpt4 book ai didi

java - 凭据错误的 POST 请求返回 405 而不是 401

转载 作者:搜寻专家 更新时间:2023-11-01 03:15:13 25 4
gpt4 key购买 nike

我正在尝试在由 Spring Security 保护的 Spring 中创建新的 POST 端点。端点正在工作。如果我提供正确的数据和凭据,服务器会处理请求并返回 200。如果我提供的凭据不正确,我会收到 405,我预计会收到 401。

我找到了 something similar我的问题,但我认为这不是我的情况。同question没有回应。

我还尝试将 Controller 的请求方法从 POST 更改为 GET,并将请求从 POST 更改为 GET,并且成功了!对于错误的凭据,a 收到 401,对于正确的凭据,则收到 200。

这是我的配置:

Controller

@Controller
@RequestMapping(value = "/api/v1")
@Secured(UserRoles.ROLE_USER)
public class ApiController {

@RequestMapping(value = "/test", method = RequestMethod.POST, consumes = MediaType.APPLICATION_JSON_VALUE)
@ResponseStatus(value = HttpStatus.OK)
@ResponseBody
public ResponseEntity<String> handleRequest(@RequestBody DataBody dataBody, Model model, Locale locale) {
try{
//do something
return new ResponseEntity<>("received", HttpStatus.OK);
} catch (SomeProblemException e) {
return new ResponseEntity<>(e.toString(), HttpStatus.BAD_REQUEST);
}
}

安全上下文

    <!-- In Memory Authentication Manager -->
<sec:authentication-manager id="inMemoryAuthManager" >
<sec:authentication-provider>
<sec:user-service properties="WEB-INF/classes/usersRoles.properties"/>
<sec:password-encoder hash="bcrypt" />
</sec:authentication-provider>
</sec:authentication-manager>

<!-- Definition of access rules for API -->
<sec:http use-expressions="true" pattern="/api/**" create-session="stateless"
authentication-manager-ref="inMemoryAuthManager">
<sec:intercept-url pattern="/api/**"
access="hasRole('ROLE_USER')"/>
<sec:http-basic/>
</sec:http>

<!-- Definition of access rules for WEB GUI. -->
<sec:http use-expressions="true"
authentication-manager-ref="inMemoryAuthManager">
<!-- Resources and errors do not need authorization. -->
<sec:intercept-url pattern="/favicon.ico" access="permitAll"/>
<sec:intercept-url pattern="/css/**" access="permitAll"/>
<sec:intercept-url pattern="/img/**" access="permitAll"/>
<sec:intercept-url pattern="/js/**" access="permitAll"/>
<sec:intercept-url pattern="/fonts/**" access="permitAll"/>
<sec:intercept-url pattern="/error/**" access="permitAll"/>
<sec:intercept-url pattern="/login" access="permitAll"/>
<sec:intercept-url pattern="/login.do" access="permitAll"/>

<!-- The rest of pages need authorized user with role ROLE_USER. -->
<sec:intercept-url pattern="/**"
access="hasRole('ROLE_USER')"/>
<!-- Configuration of login page. -->
<sec:form-login login-page="/login"
login-processing-url="/login.do"
authentication-failure-url="/login?error=true"
default-target-url="/applications" username-parameter="username"
password-parameter="password"/>
<!-- Redirect from logout page. -->
<sec:logout logout-url="/logout"
logout-success-url="/login?logout=true" invalidate-session="true"
delete-cookies="JSESSIONID"/>
<!-- Redirect for forbidden page. -->
<sec:access-denied-handler error-page="/error?err=403"/>
<!-- Port configuration. -->
<sec:port-mappings>
<sec:port-mapping http="8080" https="8443"/>
</sec:port-mappings>
<sec:headers>
<sec:frame-options policy="DENY"/>
<sec:content-type-options/>
<sec:xss-protection block="true"/>
</sec:headers>
</sec:http>

HTTP 请求( postman )

POST /api/v1/test HTTP/1.1
Host: localhost:8080
Content-Type: application/json
Authorization: Basic bWFudGfmZjptYW50YQ==
User-Agent: PostmanRuntime/7.15.2
Accept: */*
Host: localhost:8080

{
"something": "data",
"somethingelse": "data"
}

HTTP 响应( postman )

Status 405

WWW-Authenticate: Basic realm="Spring Security Application"
Allow: GET

我使用 Spring Security 3.2.10-RELEASE。我尝试启用 Spring Security 日志,但失败了。

最佳答案

问题就在这里:

@Controller
public class ErrorController {
@RequestMapping("/error")
public String error(@RequestParam(value = "err", required = false) Integer paramErrorCode, Locale locale,
ModelMap model, HttpServletRequest httpRequest) {
// Do something
}

我有一个 Controller ,它处理错误屏幕,但它只支持 GET 方法。当我将其同时更改为 GET 和 POST 时,它开始工作了。


解决方案:

@Controller
public class ErrorController {
@RequestMapping(value = "/error" method = {RequestMethod.GET, RequestMethod.POST})
public String error(@RequestParam(value = "err", required = false) Integer paramErrorCode, Locale locale,
ModelMap model, HttpServletRequest httpRequest) {
// Do something
}

不确定是什么导致了重定向,如果web.xml

<error-page>
<location>/error</location>
</error-page>

或者securitycontext.xml

<sec:access-denied-handler error-page="/error?err=403"/>

关于java - 凭据错误的 POST 请求返回 405 而不是 401,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/57559963/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com