springSecurity框架的使用教程

参考链接:
http://blog.csdn.net/q274974359/article/details/51924818

http://blog.csdn.net/u012367513/article/details/38866465

初学者1-5简单认识,讲的很详细
http://blog.csdn.net/yin380697242/article/details/51771631 spring security 起步一:框架搭建
http://blog.csdn.net/yin380697242/article/details/51786388 spring security起步二:自定义登录页
http://blog.csdn.net/yin380697242/article/details/51893397 spring security起步三:自定义登录配置与form-login属性详解
http://blog.csdn.net/yin380697242/article/details/51921593 spring security起步四:退出登录配置以及logout属性详解
http://blog.csdn.net/yin380697242/article/details/51921612 spring security起步五:Remember Me功能实现
http://blog.csdn.net/yin380697242/article/details/51959422 spring security起步六:基于数据库的用户认证

pom.xml

<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
  xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd">
  <modelVersion>4.0.0</modelVersion>
  <groupId>com.qytx</groupId>
  <artifactId>spring-security</artifactId>
  <packaging>war</packaging>
  <version>1.0-SNAPSHOT</version>
  <name>spring-security Maven Webapp</name>
  <url>http://maven.apache.org</url>
  <dependencies>
    <dependency>
      <groupId>junit</groupId>
      <artifactId>junit</artifactId>
      <version>3.8.1</version>
      <scope>test</scope>
    </dependency>
    <dependency>
      <groupId>org.springframework.security</groupId>
      <artifactId>spring-security-web</artifactId>
      <version>4.1.1.RELEASE</version>
    </dependency>
    <dependency>
      <groupId>org.springframework.security</groupId>
      <artifactId>spring-security-config</artifactId>
      <version>4.1.1.RELEASE</version>
    </dependency>
    <dependency>
      <groupId>commons-logging</groupId>
      <artifactId>commons-logging</artifactId>
      <version>1.2</version>
    </dependency>
  </dependencies>
  <build>
    <finalName>spring-security</finalName>
  </build>
</project>

web.xml

<!DOCTYPE web-app PUBLIC
 "-//Sun Microsystems, Inc.//DTD Web Application 2.3//EN"
 "http://java.sun.com/dtd/web-app_2_3.dtd" >

<web-app>
  <display-name>Archetype Created Web Application</display-name>

  <context-param>
    <param-name>contextConfigLocation</param-name>
    <param-value>classpath*:application.xml</param-value>
  </context-param>

  <filter>
    <filter-name>springSecurityFilterChain</filter-name>
    <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
  </filter>
  <filter-mapping>
    <filter-name>springSecurityFilterChain</filter-name>
    <url-pattern>/*</url-pattern>
  </filter-mapping>
  <listener>
    <listener-class>
      org.springframework.web.context.ContextLoaderListener
    </listener-class>
  </listener>
</web-app>

application.xml

<?xml version="1.0" encoding="UTF-8"?>
<beans:beans xmlns="http://www.springframework.org/schema/security"
             xmlns:beans="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
             xsi:schemaLocation="http://www.springframework.org/schema/beans
      http://www.springframework.org/schema/beans/spring-beans-3.2.xsd
      http://www.springframework.org/schema/security
      http://www.springframework.org/schema/security/spring-security-4.1.xsd ">

    <!-- 不需要进行安全认证的资源 -->
    <http pattern="/resources/**" security="none" />
    <!-- 资源所需要的权限 -->
    <http use-expressions="true" auto-config="true">
        <csrf disabled="true" />
        <form-login login-page="/login.html" default-target-url="/home.jsp" authentication-failure-url="/login.html?erro"/>
        <logout logout-success-url="/out.jsp" />
        <remember-me key="authorition" />
       <!-- <intercept-url pattern="/index.jsp*" access="permitAll" />
        <intercept-url pattern="/user.jsp*" access="hasRole('ROLE_USER')" />
        <intercept-url pattern="/admin.jsp*" access="hasRole('ROLE_ADMIN')" />-->
        <intercept-url pattern="/login.html" access="permitAll" />
        <intercept-url pattern="/out.jsp" access="permitAll" />
        <intercept-url pattern="/favicon.ico" access="permitAll" />
        <intercept-url pattern="/**" access="hasRole('ROLE_USER')" />
    </http>

    <!-- 配置用户和相应的权限 -->
    <authentication-manager>
        <authentication-provider>
            <user-service>
                <user name="test" password="test" authorities="ROLE_USER" />
                <user name="admin" password="admin" authorities="ROLE_ADMIN" />
            </user-service>
        </authentication-provider>
    </authentication-manager>
</beans:beans>
发布了281 篇原创文章 · 获赞 50 · 访问量 45万+

猜你喜欢

转载自blog.csdn.net/lzh657083979/article/details/79349768