Spring security Spring Security上不需要登录

Spring security Spring Security上不需要登录,spring-security,spring-roo,Spring Security,Spring Roo,我必须做什么才能不需要登录主页? 这是applicationContext-Security.xml的一部分 <http auto-config="true" use-expressions="true"> <form-login login-processing-url="/resources/j_spring_security_check" login-page="/login" authentication-failure-url="/login?login_er

我必须做什么才能不需要登录主页? 这是applicationContext-Security.xml的一部分

<http auto-config="true" use-expressions="true">
    <form-login login-processing-url="/resources/j_spring_security_check" login-page="/login" authentication-failure-url="/login?login_error=t" />
    <logout logout-url="/resources/j_spring_security_logout" />
    <!-- Configure these elements to secure URIs in your application -->
    <intercept-url pattern="/choices/**" access="hasRole('ROLE_ADMIN')" />
    <intercept-url pattern="/member/**" access="isAuthenticated()" />
    <intercept-url pattern="/resources/**" access="permitAll" />
    <intercept-url pattern="/login/**" access="permitAll" />
    <intercept-url pattern="/**" access="isAuthenticated()" />
</http>
你试过这个吗

<http pattern="/home" security='none' />

将其与您的标签放在同一水平面上

尝试以下操作:

<http auto-config="true" use-expressions="true">
    <form-login login-processing-url="/resources/j_spring_security_check" login-page="/login" authentication-failure-url="/login?login_error=t" />
    <logout logout-url="/resources/j_spring_security_logout" />
    <!-- Configure these elements to secure URIs in your application -->
    <intercept-url pattern="/choices/**" access="hasRole('ROLE_ADMIN')" />
    <intercept-url pattern="/member/**" access="isAuthenticated()" />
    <intercept-url pattern="/resources/**" access="permitAll" />
    <intercept-url pattern="/login/**" access="permitAll" />
    <intercept-url pattern="/index" access="permitAll" /> <!-- new -->
    <intercept-url pattern="/" access="permitAll" /> <!-- new -->
    <intercept-url pattern="/**" access="isAuthenticated()" />
</http>

intercep url按顺序计算并使用第一个匹配权限。因此,如果在/**之前添加/index和/pattern,将应用此匹配

使用permitAll作为主页URL模式,不管是什么。这是我尝试的第一件事。为什么你的问题没有它?除非您提供更多信息—URL、使用的实际配置和日志输出,否则很难提供答案。