Spring security Spring引导安全性-多个Web安全配置适配器
我有一个auth cas库,它为我的spring引导项目提供身份验证。 在这个auth-cas库中,有一个类扩展了Spring security Spring引导安全性-多个Web安全配置适配器,spring-security,spring-boot,Spring Security,Spring Boot,我有一个auth cas库,它为我的spring引导项目提供身份验证。 在这个auth-cas库中,有一个类扩展了 websecurityConfigureAdapter具有以下配置功能 @Override @ConditionalOnProperty(value = "ugent.cas.serviceUrl", matchIfMissing = true) @ConditionalOnClass(Cas.class) protected void configure(HttpSecurity
websecurityConfigureAdapter
具有以下配置功能
@Override
@ConditionalOnProperty(value = "ugent.cas.serviceUrl", matchIfMissing = true)
@ConditionalOnClass(Cas.class)
protected void configure(HttpSecurity http) throws Exception {
http.exceptionHandling().authenticationEntryPoint(casAuthenticationEntryPoint());
if (basicAuthenticationProviders != null) {
http.addFilter(basicAuthFilter());
}
http.addFilter(casAuthenticationFilter())
.addFilter(requestSSOLogoutToCASServerLogoutFilter())
.logout()
.deleteCookies("JSESSIONID")
.permitAll()
.logoutSuccessUrl("/logout.html")
.and()
.csrf()
.disable()
.headers()
.frameOptions()
.disable();
http.authorizeRequests()
.antMatchers(HttpMethod.OPTIONS, "/api/**").permitAll()
.antMatchers("/**").authenticated();
}
由于这应该是黑盒,我添加了自己的websecurityConfigureAdapter
,如下所示:
@Configuration
//@Order(Integer.MAX_VALUE)
//@Order(SecurityProperties.ACCESS_OVERRIDE_ORDER)
@Order(1)
public class AuthSecurityConfiguration extends WebSecurityConfigurerAdapter {
@Override
public void configure(WebSecurity webSecurity) throws Exception {
webSecurity
.ignoring()
// All of Spring Security will ignore the requests
.antMatchers("/choose.html")
.antMatchers("/account/*");
}
@Override
protected void configure(HttpSecurity http) throws Exception {
http/*.addFilter(usernamePasswordAuthenticationFilter())
.formLogin()
.permitAll()
.and()
.logout()
.deleteCookies("JSESSIONID")
.permitAll()
.logoutSuccessUrl("/logout.html")
.and()
.csrf()
.disable()
.headers()
.frameOptions()
.disable();
*/
.authorizeRequests()
.anyRequest().authenticated()
.and()
.authenticationProvider(AuthenticationProvider())
.formLogin()
.permitAll()
.and()
.csrf()
.disable()
.headers()
.frameOptions()
.disable()
;
}
@Bean
public AuthenticationProvider AuthenticationProvider() {
return new LCAAuthenticationProvider();
}
@Bean
public UsernamePasswordAuthenticationFilter usernamePasswordAuthenticationFilter () throws Exception{
UsernamePasswordAuthenticationFilter filter = new UsernamePasswordAuthenticationFilter ();
filter.setAuthenticationManager(authenticationManager());
return filter;
}
}
我的自定义AuthenticationProvider实现“AuthenticationProvider”,并在页面中工作,将我重定向到/login页面,我可以在我的用户群中使用凭据登录。
唯一的问题是,当我已经登录到另一个身份验证cas网络时,我应该进行身份验证,但它仍然提示我使用自定义身份验证提供程序
我需要如何配置HttpSecurity,以便它与我的2个身份验证提供程序一起工作
其他相关问题,我如何从被忽略的页面/choose.html中选择使用两个身份验证提供商之一登录
编辑
这是我当前的“WebSecurityConfigureRadapter”配置
@Configuration
//@Order(Integer.MAX_VALUE)
//@Order(SecurityProperties.ACCESS_OVERRIDE_ORDER)
@Order(0)
public class AuthSecurityConfiguration extends WebSecurityConfigurerAdapter {
/**
* The authProvider bean used as a cas authentication provider.
*/
@Autowired
private LCAAuthenticationProvider authProvider;
@Override
public void configure(WebSecurity webSecurity) throws Exception {
webSecurity
.ignoring()
// All of Spring Security will ignore the requests
.antMatchers("/choose.html")
.antMatchers("/account/*");
}
@Autowired
public void configureGlobal(AuthenticationManagerBuilder auth) throws Exception {
auth.authenticationProvider(authProvider);
}
/**
* The authenticationManagerBean bean.
*
* @return the authenticationManagerBean
* @throws Exception
*/
@Override
public AuthenticationManager authenticationManagerBean() throws Exception {
return super.authenticationManagerBean();
}
/**
* The loginUrlAuthenticationEntryPoint bean
*
* @return the loginUrlAuthenticationEntryPoint
*/
@Bean
public LoginUrlAuthenticationEntryPoint loginUrlAuthenticationEntryPoint() {
LoginUrlAuthenticationEntryPoint ep = new LoginUrlAuthenticationEntryPoint("/choose.html");
//ep.setLoginUrl(cas.getLoginUrl());
return ep;
}
@Override
protected void configure(HttpSecurity http) throws Exception {
http.exceptionHandling().authenticationEntryPoint(loginUrlAuthenticationEntryPoint());
http.addFilter(usernamePasswordAuthenticationFilter())
.formLogin()
.permitAll()
.and()
.logout()
.deleteCookies("JSESSIONID")
.permitAll()
.logoutSuccessUrl("/logout.html")
.and()
.csrf()
.disable()
.headers()
.frameOptions()
.disable();
/*
.authorizeRequests()
.anyRequest().authenticated()
.and()
.authenticationProvider(AuthenticationProvider())
.formLogin()
.loginPage("choose.html")
.permitAll()
.and()
.csrf()
.disable()
.headers()
.frameOptions()
.disable()
;
*/
}
@Bean
public LCAAuthenticationProvider lcaAuthenticationProvider() {
return new LCAAuthenticationProvider();
}
@Bean
public UsernamePasswordAuthenticationFilter usernamePasswordAuthenticationFilter () throws Exception{
UsernamePasswordAuthenticationFilter filter = new UsernamePasswordAuthenticationFilter ();
filter.setAuthenticationManager(authenticationManager());
return filter;
}
}
但我得到了以下错误:
Exception in thread "main" java.lang.RuntimeException: java.lang.reflect.InvocationTargetException
at org.springframework.boot.loader.MainMethodRunner.run(MainMethodRunner.java:62)
at java.lang.Thread.run(Unknown Source)
Caused by: java.lang.reflect.InvocationTargetException
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
at java.lang.reflect.Method.invoke(Unknown Source)
at org.springframework.boot.loader.MainMethodRunner.run(MainMethodRunner.java:54)
... 1 more
Caused by: org.springframework.beans.factory.BeanCreationException: Error creating bean with name 'springSecurityFilterChain' defined in class path resource [org/springframework/security/config/annotation/web/configuration/WebSecurityConfiguration.class]: Bean instantiation via factory method failed; nested exception is org.springframework.beans.BeanInstantiationException: Failed to instantiate [javax.servlet.Filter]: Factory method 'springSecurityFilterChain' threw exception; nested exception is org.springframework.security.config.annotation.AlreadyBuiltException: This object has already been built
at org.springframework.beans.factory.support.ConstructorResolver.instantiateUsingFactoryMethod(ConstructorResolver.java:599)
at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.instantiateUsingFactoryMethod(AbstractAutowireCapableBeanFactory.java:1123)
at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBeanInstance(AbstractAutowireCapableBeanFactory.java:1018)
at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.doCreateBean(AbstractAutowireCapableBeanFactory.java:510)
at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBean(AbstractAutowireCapableBeanFactory.java:482)
at org.springframework.beans.factory.support.AbstractBeanFactory$1.getObject(AbstractBeanFactory.java:306)
at org.springframework.beans.factory.support.DefaultSingletonBeanRegistry.getSingleton(DefaultSingletonBeanRegistry.java:230)
at org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:302)
at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:197)
at org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:296)
at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:197)
at org.springframework.beans.factory.support.DefaultListableBeanFactory.preInstantiateSingletons(DefaultListableBeanFactory.java:772)
at org.springframework.context.support.AbstractApplicationContext.finishBeanFactoryInitialization(AbstractApplicationContext.java:839)
at org.springframework.context.support.AbstractApplicationContext.refresh(AbstractApplicationContext.java:538)
at org.springframework.boot.context.embedded.EmbeddedWebApplicationContext.refresh(EmbeddedWebApplicationContext.java:118)
at org.springframework.boot.SpringApplication.refresh(SpringApplication.java:766)
at org.springframework.boot.SpringApplication.createAndRefreshContext(SpringApplication.java:361)
at org.springframework.boot.SpringApplication.run(SpringApplication.java:307)
at org.springframework.boot.SpringApplication.run(SpringApplication.java:1191)
at org.springframework.boot.SpringApplication.run(SpringApplication.java:1180)
at be.ugent.lca.Application.main(Application.java:16)
... 6 more
Caused by: org.springframework.beans.BeanInstantiationException: Failed to instantiate [javax.servlet.Filter]: Factory method 'springSecurityFilterChain' threw exception; nested exception is org.springframework.security.config.annotation.AlreadyBuiltException: This object has already been built
at org.springframework.beans.factory.support.SimpleInstantiationStrategy.instantiate(SimpleInstantiationStrategy.java:189)
at org.springframework.beans.factory.support.ConstructorResolver.instantiateUsingFactoryMethod(ConstructorResolver.java:588)
... 26 more
Caused by: org.springframework.security.config.annotation.AlreadyBuiltException: This object has already been built
at org.springframework.security.config.annotation.AbstractSecurityBuilder.build(AbstractSecurityBuilder.java:44)
at org.springframework.security.config.annotation.web.configuration.WebSecurityConfiguration.springSecurityFilterChain(WebSecurityConfiguration.java:105)
at org.springframework.security.config.annotation.web.configuration.WebSecurityConfiguration$$EnhancerBySpringCGLIB$$699e3cc3.CGLIB$springSecurityFilterChain$2(<generated>)
at org.springframework.security.config.annotation.web.configuration.WebSecurityConfiguration$$EnhancerBySpringCGLIB$$699e3cc3$$FastClassBySpringCGLIB$$e656a0ba.invoke(<generated>)
at org.springframework.cglib.proxy.MethodProxy.invokeSuper(MethodProxy.java:228)
at org.springframework.context.annotation.ConfigurationClassEnhancer$BeanMethodInterceptor.intercept(ConfigurationClassEnhancer.java:355)
at org.springframework.security.config.annotation.web.configuration.WebSecurityConfiguration$$EnhancerBySpringCGLIB$$699e3cc3.springSecurityFilterChain(<generated>)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
at java.lang.reflect.Method.invoke(Unknown Source)
at org.springframework.beans.factory.support.SimpleInstantiationStrategy.instantiate(SimpleInstantiationStrategy.java:162)
线程“main”java.lang.RuntimeException中的异常:java.lang.reflect.InvocationTargetException
位于org.springframework.boot.loader.MainMethodRunner.run(MainMethodRunner.java:62)
位于java.lang.Thread.run(未知源)
原因:java.lang.reflect.InvocationTargetException
在sun.reflect.NativeMethodAccessorImpl.invoke0(本机方法)处
位于sun.reflect.NativeMethodAccessorImpl.invoke(未知源)
在sun.reflect.DelegatingMethodAccessorImpl.invoke处(未知源)
位于java.lang.reflect.Method.invoke(未知源)
位于org.springframework.boot.loader.MainMethodRunner.run(MainMethodRunner.java:54)
... 还有一个
原因:org.springframework.beans.factory.BeanCreationException:创建名为“springSecurityFilterChain”的bean时出错,该bean在类路径资源[org/springframework/security/config/annotation/web/configuration/WebSecurityConfiguration.class]中定义:通过工厂方法实例化bean失败;嵌套异常为org.springframework.beans.beanstantiationException:未能实例化[javax.servlet.Filter]:工厂方法“springSecurityFilterChain”引发异常;嵌套异常为org.springframework.security.config.annotation.AlreadyBuiltException:此对象已生成
位于org.springframework.beans.factory.support.ConstructorResolver.InstanceUsingFactoryMethod(ConstructorResolver.java:599)
位于org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.InstanceUsingFactoryMethod(AbstractAutowireCapableBeanFactory.java:1123)
位于org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBeanInstance(AbstractAutowireCapableBeanFactory.java:1018)
位于org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.doCreateBean(AbstractAutowireCapableBeanFactory.java:510)
位于org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBean(AbstractAutowireCapableBeanFactory.java:482)
位于org.springframework.beans.factory.support.AbstractBeanFactory$1.getObject(AbstractBeanFactory.java:306)
位于org.springframework.beans.factory.support.DefaultSingletonBeanRegistry.getSingleton(DefaultSingletonBeanRegistry.java:230)
位于org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:302)
位于org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:197)
位于org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:296)
位于org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:197)
位于org.springframework.beans.factory.support.DefaultListableBeanFactory.PreInstanceSingleton(DefaultListableBeanFactory.java:772)
位于org.springframework.context.support.AbstractApplicationContext.finishBeanFactoryInitialization(AbstractApplicationContext.java:839)
位于org.springframework.context.support.AbstractApplicationContext.refresh(AbstractApplicationContext.java:538)
位于org.springframework.boot.context.embedded.EmbeddedWebApplicationContext.refresh(EmbeddedWebApplicationContext.java:118)
位于org.springframework.boot.SpringApplication.refresh(SpringApplication.java:766)
位于org.springframework.boot.SpringApplication.createAndRefreshContext(SpringApplication.java:361)
位于org.springframework.boot.SpringApplication.run(SpringApplication.java:307)
位于org.springframework.boot.SpringApplication.run(SpringApplication.java:1191)
位于org.springframework.boot.SpringApplication.run(SpringApplication.java:1180)
位于be.ugent.lca.Application.main(Application.java:16)
... 还有6个
原因:org.springframework.beans.beans实例化异常:未能实例化[javax.servlet.Filter]:工厂方法“springSecurityFilterChain”引发异常;嵌套异常为org.springframework.security.config.annotation.AlreadyBuiltException:此对象已生成
位于org.springframework.beans.factory.support.SimpleInstallationStrategy.instantiate(SimpleInstallationStrategy.java:189)
位于org.springframework.beans.factory.support.ConstructorResolver.InstanceUsingFactoryMethod(ConstructorResolver.java:588)
... 26多
原因:org.springframework.security.config.annotation.AlreadyBuiltException:此对象已生成
位于org.springframework.security.config.annotation.AbstractSecurityBuilder.build(AbstractSecurityBuilder.java:44)
位于org.springframework.security.config.annotation.web.configuration.WebSecurityConfiguration.springSecurityFilterChain(WebSecurityConfiguration.java:105)
位于org.springframework.security.config.annotation.web.config
<security:http xmlns="http://www.springframework.org/schema/security" entry-point-ref="clientAuthenticationEntryPoint">
<intercept-url pattern="/login" access="IS_AUTHENTICATED_ANONYMOUSLY" />
<intercept-url pattern="/choose.html" access="IS_AUTHENTICATED_ANONYMOUSLY" />
<intercept-url pattern="/autherror" access="IS_AUTHENTICATED_ANONYMOUSLY" />
<intercept-url pattern="/**/**" access="IS_AUTHENTICATED_FULLY"/>
<custom-filter ref="logoutFilter" position="LOGOUT_FILTER" />
<custom-filter ref="authenticationBrokerProcessingFilter" after="LOGOUT_FILTER" />
<custom-filter ref="oauth2ClientContextFilter" after="EXCEPTION_TRANSLATION_FILTER"/>
<custom-filter ref="oAuth2AuthenticationProcessingFilter" before="FILTER_SECURITY_INTERCEPTOR"/>
<form-login
login-page="/login"
default-target-url="/main"
username-parameter="username"
password-parameter="password"
login-processing-url="/loginSubmit"
authentication-failure-handler-ref="passwordFailureHandler"
authentication-success-handler-ref="passwordAuthenticationSuccessHandler"
always-use-default-target="false"
/>
<csrf />
<access-denied-handler ref="accessDeniedHandler" />
</security:http>
<bean id="clientAuthenticationEntryPoint" class="org.springframework.security.web.authentication.LoginUrlAuthenticationEntryPoint">
<constructor-arg name="loginFormUrl" value="/choose.html"/>
</bean>