springsecurity自定义403处理方案

在handler包下:

package com.wyt.handler;

import org.springframework.security.access.AccessDeniedException;
import org.springframework.security.web.access.AccessDeniedHandler;
import org.springframework.stereotype.Component;

import javax.servlet.ServletException;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;
import java.io.PrintWriter;

/**
 *
 **/

@Component
public class MyAccess implements AccessDeniedHandler {
    @Override
    public void handle(HttpServletRequest httpServletRequest, HttpServletResponse httpServletResponse, AccessDeniedException e) throws IOException, ServletException {
        httpServletResponse.setStatus(HttpServletResponse.SC_FORBIDDEN);
        PrintWriter writer = httpServletResponse.getWriter();
        writer.write("{\"status\":\"error\",\"msg\":\"权限不足,请联系管理 员!\"}");
        writer.flush();
        writer.close();
    }
}

修改配置

   //异常处理
        http.exceptionHandling()
                .accessDeniedHandler(myAccess);
package com.wyt.config;

import com.wyt.handler.MyAccess;
import com.wyt.handler.MyAuth;
import com.wyt.handler.MyAuthF;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;

/**
 *
 **/
@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Autowired
    private MyAccess myAccess;
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.formLogin()
                .loginProcessingUrl("/login").failureHandler(new MyAuthF("/fail.html"))
               // .failureForwardUrl("/fail")
                .successHandler(new MyAuth("/mian.html")).loginPage("/login.html");

        //url拦截(授权)部分  匹配规则+权限控制
        http.authorizeRequests()
                .antMatchers("/login.html").permitAll()//loigin.html被放行
                .antMatchers("/fail.html").permitAll()
               /* .antMatchers("/main1.html").hasAuthority("admin")*/
                .antMatchers("/main1.html").hasRole("abC")
                .anyRequest().authenticated();//所有的请求都必须被认证,必须登录才能访问

        //关闭csrf
        http.csrf().disable();


    //异常处理
        http.exceptionHandling()
                .accessDeniedHandler(myAccess);
}




    //采用哪种加密算法
    @Bean
    public PasswordEncoder getPe(){
        return new BCryptPasswordEncoder();

    }
}

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值