实现功能:
使用自定义的登录界面替换Spring Security默认的登录界面
配置参考 Spring Securty 应用(1)– 基于内存的认证
spring-security.xml 的配置
<http security="none" pattern="/resources/**"/> 对资源文件不进行拦截
<http security="none" pattern="/login"/> 由于下面的配置/**是对所有的URL进行拦截,因此对logi页面就不能进行拦截,否则会出现死循环
http security="none" 表示对指定的URL放行,不进行安全拦截
form-login login-page="/login" 即指定自定义的登录界面,如果不指定,则默认为Spring Security的默认登录页面 j_spring_security_login
username-parameter="username" 指定登录页面中用户名的参数名称,此处指定为username,如果不指定,则默认为j_username
password-parameter="password" 指定登录页面中密码的参数名称,此处指定为password,如果不指定,则默认为j_password
<beans:beans xmlns="http://www.springframework.org/schema/security"
xmlns:beans="http://www.springframework.org/schema/beans"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mvc="http://www.springframework.org/schema/mvc"
xsi:schemaLocation="http://www.springframework.org/schema/beans
http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
http://www.springframework.org/schema/security
http://www.springframework.org/schema/security/spring-security-3.2.xsd http://www.springframework.org/schema/mvc http://www.springframework.org/schema/mvc/spring-mvc.xsd">
<!-- 不进行安全拦截 -->
<http security="none" pattern="/resources/**"/>
<http security="none" pattern="/login"/>
<http auto-config="true">
<!-- 指定登录页面,如果不配置默认是 j_spring_security_login -->
<form-login login-page="/login"
username-parameter="username"
password-parameter="password"/>
<intercept-url pattern="/**" access="ROLE_USER"/>
</http>
<!-- 基于内存的认证 -->
<authentication-manager>
<authentication-provider>
<user-service>
<user name="admin" password="123456" authorities="ROLE_USER"/>
</user-service>
</authentication-provider>
</authentication-manager>
</beans:beans>
自定义Login.jsp 主要是参考Spring Security默认的登录界面的代码
此处为自定义登录页面,需要特别注意的地方:
1.使用post方法提交
2.action指定为 /j_spring_security_check
3.用户名参数名称和密码参数名称要和前面 spring-security.xml 配置的一致,本文配置的为 username 和 password,这里特别需要注意的是name的名称,如果只指定了id没有指定name,则也无法通过认证
认证通过之后会自动跳转到ROOT目录/下面,因此可以你把/指定一个jsp页面,否则会出现 ”假的报错页面“
<%@ page language="java" contentType="text/html; charset=UTF-8"
pageEncoding="UTF-8" session="false" %>
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
<meta name="description" content="">
<meta name="author" content="">
<link rel="icon" href="../../favicon.ico">
<title>Signin Template for Bootstrap</title>
<!-- Bootstrap core CSS -->
<link href="${base.contextPath}/resources/bootstrap/css/bootstrap.min.css" rel="stylesheet">
<!-- Custom styles for this template -->
<link href="${base.contextPath}/resources/bootstrap/login/signin.css" rel="stylesheet">
</head>
<body>
<div class="container">
<form class="form-signin" action="/j_spring_security_check" method="post">
<h2 class="form-signin-heading">Please login in</h2>
<%--<label for="j_username" class="sr-only">User Name</label>--%>
<%--<input type="text" id="j_username" name="j_username" class="form-control" placeholder="User Name" required autofocus>--%>
<%--<label for="j_password" class="sr-only">Password</label>--%>
<%--<input type="password" id="j_password" name="j_password" class="form-control" placeholder="Password" required>--%>
<label for="username" class="sr-only">User Name</label>
<input type="text" id="username" name="username" class="form-control" placeholder="User Name" required
autofocus>
<label for="password" class="sr-only">Password</label>
<input type="password" id="password" name="password" class="form-control" placeholder="Password" required>
<div class="checkbox">
<label>
<input type="checkbox" value="remember-me"> Remember me
</label>
</div>
<button class="btn btn-lg btn-primary btn-block" type="submit">Sign in</button>
</form>
</div> <!-- /container -->
<!-- Bootstrap core JavaScript
================================================== -->
<!-- Placed at the end of the document so the pages load faster -->
<!-- IE10 viewport hack for Surface/desktop Windows 8 bug -->
<script src="${base.contextPath}/resources/bootstrap/assets/js/ie10-viewport-bug-workaround.js"></script>
</body>
</html>
Spring Security 默认登录页面的代码如下
自定义的登录页面实现主要参考 Spring Security默认登录页面的代码实现的,下面为Spring Security 的登录页面代码
从中可以可以看出关键属性如下:
action=’/j_spring_security_check’
name=’j_username’
name=’j_password’
<html><head><title>Login Page</title></head><body onload='document.f.j_username.focus();'>
<h3>Login with Username and Password</h3><form name='f' action='/j_spring_security_check' method='POST'>
<table>
<tr><td>User:</td><td><input type='text' name='j_username' value=''></td></tr>
<tr><td>Password:</td><td><input type='password' name='j_password'/></td></tr>
<tr><td colspan='2'><input name="submit" type="submit" value="Login"/></td></tr>
</table>
</form></body></html>
Controller代码
此处配置login对应的页面。登录成功之后Spring Security会默认跳转到Root目录(/)下面,此文配置/对应的为hello.jsp页面
package com.cnblogs.duoduo;
import org.springframework.stereotype.Controller;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.servlet.ModelAndView;
@Controller
public class HelloController {
@RequestMapping(value = "/login")
public ModelAndView index() {
ModelAndView model = new ModelAndView();
model.addObject("title", "Index - Spring Security Hello World");
model.addObject("message", "This is index page!");
model.setViewName("login");
return model;
}
@RequestMapping(value = {"/", "/welcome"})
public ModelAndView welcome() {
ModelAndView model = new ModelAndView();
model.addObject("title", "Welcome - Spring Security Hello World");
model.addObject("message", "This is welcome page!");
model.setViewName("hello");
return model;
}
@RequestMapping(value = "/admin")
public ModelAndView admin() {
ModelAndView model = new ModelAndView();
model.addObject("title", "Admin - Spring Security Hello World");
model.addObject("message", "This is protected page!");
model.setViewName("admin");
return model;
}
}