java - spring mvc登录后重定向到主页

标签 java spring spring-mvc

我有一个问题。假设我登录到应用程序并访问不同的页面,并让应用程序在 http://localhost:8080/InformationManagement/smartapp/allFileNetStatus 中停留 5 分钟。然后在 session 过期后尝试访问并重定向到登录页面。 一旦我输入凭据,它就会登录,它会让我进入 http://localhost:8080/InformationManagement/smartapp/allFileNetStatus而不是主页( http://localhost:8080/InformationManagement/ )

注意:我的登录页面和主页 URL 相同

我如何在 Spring Security 中控制它。

代码:

    <http pattern="/resources" security="none" />

<http auto-config="true" use-expressions="true">
    <intercept-url pattern="/login" access="permitAll" />
    <intercept-url pattern="/logout" access="permitAll" />
    <intercept-url pattern="/denied" access="hasRole('ROLE_USER')" />
    <intercept-url pattern="/" access="permitAll" />
    <intercept-url pattern="/user" access="hasRole('ROLE_USER')" />
    <intercept-url pattern="/user/create" access="hasRole('ROLE_ADMIN')" />
    <intercept-url pattern="/user/update"
        access="hasAnyRole('ROLE_READ','ROLE_ADMIN')" />
<intercept-url pattern="/smartapp/getNewFileNetStatus" access="hasRole('ROLE_SMARTAPP')" />
<intercept-url pattern="/smartapp/allFileNetStatus" access="hasRole('ROLE_SMARTAPP')" />
    <intercept-url pattern="/user/alluser" access="hasAnyRole('ROLE_READ','ROLE_ADMIN')" />
    <intercept-url pattern="/admin" access="hasRole('ROLE_ADMIN')" />

    <form-login login-page="/login" authentication-failure-url="/login/failure"
        default-target-url="/" />

    <access-denied-handler error-page="/denied" />

    <logout invalidate-session="true" logout-success-url="/logout/success"
        logout-url="/logout" />
</http>



<beans:bean id="daoAuthenticationProvider"
    class="org.springframework.security.authentication.dao.DaoAuthenticationProvider">
    <beans:property name="userDetailsService" ref="userDetailsService"></beans:property>

</beans:bean>

<beans:bean id="authenticationManager"
    class="org.springframework.security.authentication.ProviderManager">
    <beans:property name="providers">
        <beans:list>
            <beans:ref local="daoAuthenticationProvider" />
        </beans:list>
    </beans:property>
</beans:bean>

<authentication-manager>
    <authentication-provider user-service-ref="userDetailsService">
        <password-encoder hash="md5"></password-encoder>
    </authentication-provider>
</authentication-manager>

HomeController.java

 @Controller
 @RequestMapping("/")
 public class HomeController {

/*
 * @Value("${msg}") private String msg;
 */

   @Autowired
  UserDetailsService userService;

Logger logger = Logger.getLogger(HomeController.class);

@RequestMapping(value = "/help", method = RequestMethod.GET)
public String getAdminPage() {
    return "help";
}

@RequestMapping(method = RequestMethod.GET)
public String getHomePage(Model model, HttpSession session) {

    Authentication auth = SecurityContextHolder.getContext()
            .getAuthentication();

    if (!(auth instanceof AnonymousAuthenticationToken)) {

        /* The user is logged in :) */
        if (logger.isInfoEnabled()) {
            logger.info("User got logged in...");
        }
        int passwordResetValue = userService.userPasswordReset(auth
                .getName());
        session.setAttribute("username",auth.getName());
        System.out.println("username-- set-->"+session.getAttribute("username"));
        System.out.println("passwordResetValue" + passwordResetValue);
        if (passwordResetValue == 0) {
            return "home";
        } else {
            return "redirect:/password/changePassword?value=reset";
        }

    } else {
        if (logger.isInfoEnabled()) {
            logger.info("Redirected to Login Page");
        }
        return "access/login";
    }
}

AccessController.java

 @Controller
@RequestMapping
 public class AccessController {

@RequestMapping(value = "/denied")
public String denied() {
    return "access/denied";
}

@RequestMapping("/login")
public String login() {
    /*System.out.println("message-->" + message);
    model.addAttribute("message", message);*/
    Authentication auth = SecurityContextHolder.getContext()
            .getAuthentication();

    if (!(auth instanceof AnonymousAuthenticationToken)) {
        auth.getPrincipal();
        /* The user is logged in :) */
        System.out.println("eeee");
        return "redirect:/";
    } else {
        System.out.println("Finalalaay" + auth.getDetails());
        return "access/login";
    }
}

@RequestMapping(value = "/login/failure")
public String loginFailure(final RedirectAttributes redirect) {
    String message = "Please verify username and password";
    Authentication auth = SecurityContextHolder.getContext()
            .getAuthentication();

    if (!(auth instanceof AnonymousAuthenticationToken)) {

        /* The user is logged in :) */
        return "redirect:/";
    } else {
        redirect.addFlashAttribute("message", message);
        return "redirect:/login";
    }
}

@RequestMapping(value = "/logout/success")
public String logoutSuccess(final RedirectAttributes redirect) {
    String message = "You have been successfully logged out.";
    redirect.addFlashAttribute("message", message);
    return "redirect:/login";
}

}

最佳答案

您应该为此实现自己的AuthenticationSuccessHandler

 <!-- Add to your form login the handler-->
 <form-login login-page="/login" authentication-failure-url="/login/failure"
        default-target-url="/" authentication-success-handler-ref="homeRedirectSuccessHandler" />
 <beans:bean id="homeRedirectSuccessHandler"
    class="your.package.HomeRedirectSuccessHandler" />

在你的 HomeRedirectSuccessHandler 中:

protected void handle(HttpServletRequest request, 
  HttpServletResponse response, Authentication authentication) throws IOException {

    redirectStrategy.sendRedirect(request, response, "yourHomepage.html);
}

关于java - spring mvc登录后重定向到主页,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/39414305/

相关文章:

java - 使用 Spring Boot 将 Oracle 数据传输到 SQL Server

java - Spring框架, Controller PreAuthorize中自定义函数

java - 错误: no suitable constructor found for

java - MQJE001 : An MQException occurred: Completion Code 2, Reason 2009怎么解决

java - Java fx webview 中的 Google 身份验证

java - spring http请求将具有不同请求参数的单个uri映射到不同的方法是好的做法还是坏的做法

java - Spring Boot 项目作为可执行 jar 运行时找不到 Hibernate.cfg.xml

java - 通过自定义 Spring validator 处理绑定(bind)到输入字段的长值是否太晚了?

java - 旋转 BufferedImage 并删除黑色边界

java - Spring-Data-JPA - 查询返回 null - EmbeddedId