gpt4 book ai didi

java - 注销重定向到 `/sessiontimeout` 而不是 `/logout`

转载 作者:行者123 更新时间:2023-12-01 11:12:29 24 4
gpt4 key购买 nike

我确信这个问题被问过很多次,但我找不到一个好的解决方案。

当用户单击注销时,控件将转到 /sessiontimeout 而不是 /logout。我见过不同的解决方案,其中建议将 invalidate-session 的值更改为 false。如果是这样,我们如何根据 spring 标准使 session 无效。

我尝试了这个解决方案,但如果我们尝试使用同一用户再次登录,它会给出一个本质:先前的 session 仍然存在。

<?xml version="1.0" encoding="UTF-8"?>
<beans:beans xmlns="http://www.springframework.org/schema/security"
xmlns:beans="http://www.springframework.org/schema/beans" xmlns:aop="http://www.springframework.org/schema/aop"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:context="http://www.springframework.org/schema/context"
xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-3.1.xsd
http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security-3.2.xsd
http://www.springframework.org/schema/context http://www.springframework.org/schema/context/spring-context.xsd
http://www.springframework.org/schema/aop http://www.springframework.org/schema/aop/spring-aop-3.0.xsd">

<context:property-placeholder location="classpath*:META-INF/spring/*.properties"/>
<context:component-scan base-package="blah.blah.blah" />

<http pattern="/resources/**" security="none"/>

<http access-decision-manager-ref="accessDecisionManager" use-expressions="true">
<http access-decision-manager-ref="accessDecisionManager" use-expressions="true">
<intercept-url pattern="/login" access="permitAll" />
<intercept-url pattern="/logout" access="permitAll" />
<intercept-url pattern="/loginfailed" access="permitAll" />
<intercept-url pattern="/sessiontimeout" access="permitAll" />
<intercept-url pattern="/sessionTerminated" access="permitAll" />
<logout delete-cookies="JSESSIONID" logout-success-url="/login" logout-url="/logout" invalidate-session="true"/>
<session-management session-authentication-error-url="/loginfailed" session-fixation-protection="newSession" invalid-session-url="/sessiontimeout">
<concurrency-control max-sessions="1" error-if-maximum-exceeded="false" expired-url="/sessionTerminated" session-registry-alias="sessionRegistry"/>
</session-management>
</http>

<authentication-manager alias="authenticationManager">
<authentication-provider>
<jdbc-user-service data-source-ref="infrastructureDataSource"
authorities-by-username-query="//query//"
users-by-username-query="//query//" />
<password-encoder ref="passwordEncoder" />
</authentication-provider>

<authentication-provider ref="authService" />
</authentication-manager>


<beans:bean id="authService" class="blah.blah.blah.blah.AuthServiceImpl" />

<beans:bean id="passwordEncoder" class="org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder"/>

<beans:bean id="customAuthenticationHandler" class="blah.blah.blah.CustomAuthenticationSuccessHandler" />

<beans:bean id="sessionRegistry" class="org.springframework.security.core.session.SessionRegistryImpl" />

<beans:bean id="customApplicationListener" class="blah.blah.blah.CustomApplicationListener" />
</beans:beans>

Web.xml:

<?xml version="1.0" encoding="ISO-8859-1"?>
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns="http://java.sun.com/xml/ns/javaee"
xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd"
id="WebApp_ID"
version="2.5"
metadata-complete="true">

<!-- Processes application requests -->
<servlet>
<servlet-name>appContext</servlet-name>
<servlet-class>org.springframework.web.servlet.DispatcherServlet</servlet-class>
<load-on-startup>1</load-on-startup>
</servlet>

<servlet-mapping>
<servlet-name>appContext</servlet-name>
<url-pattern>/</url-pattern>
</servlet-mapping>

<listener>
<listener-class>org.springframework.web.context.ContextLoaderListener</listener-class>
</listener>
<listener>
<listener-class>org.springframework.security.web.session.HttpSessionEventPublisher</listener-class>
</listener>

<session-config>
<session-timeout>240</session-timeout>
</session-config>

<!-- The definition of the Root Spring Container shared by all Servlets and Filters -->
<context-param>
<param-name>contextConfigLocation</param-name>
<param-value>/WEB-INF/appContext-servlet.xml
/WEB-INF/spring/root-context.xml
/WEB-INF/spring/root-context-security.xml</param-value>
</context-param>

<!-- Filters -->
<filter>
<filter-name>springSecurityFilterChain</filter-name>
<filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
</filter>

<!-- some other stuff -->

在这里,我正在实现 session 窃取(如果有人在不同的计算机上使用相同的凭据登录,现有用户必须注销)和 session 超时。

你们有没有可行的解决方案?

最佳答案

解决方案是这样的:

<!-- this is the pattern used in order to disable the filters for logout-success-url -->
<http pattern="/login**" security="none"></http>
<http pattern="/resources/**" security="none"/>

<http access-decision-manager-ref="accessDecisionManager" use-expressions="true">
<http access-decision-manager-ref="accessDecisionManager" use-expressions="true">
<intercept-url pattern="/logout" access="permitAll" />
<intercept-url pattern="/loginfailed" access="permitAll" />
<intercept-url pattern="/sessiontimeout" access="permitAll" />

关于java - 注销重定向到 `/sessiontimeout` 而不是 `/logout`,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/32189709/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com