代理Servlet過濾器

來源:互聯網
上載者:User

標籤:

Spring Security藉助一些列Servlet 過濾器 來提供 各種 安全性功能。

我們只需要在應用中的 web.xml 中配置 一個過濾器。

<filter>        <filter-name>springSecurityFilterChain</filter-name>        <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>    </filter><filter-mapping>        <filter-name>springSecurityFilterChain</filter-name>        <url-pattern>/*</url-pattern></filter-mapping>

DelegatingFilterProxy是一個特殊的 Servlet 過濾器,它本身所做的工作不多。

只是將工作 委託給 一個 javax.servlet.Filter 實作類別,這個實作類別作為一個 <bean>註冊在 Spring 應用上下文中。

 

為了完成各自的工作內容,Spring Security 的 過濾器 必須注入 一些 其他的 Bean。

我們 無法對 註冊 在 web.xml 中的  servlet 過濾器 進行 Bean 注入。

但是,通過使用 DelegatingFilterProxy , 我們可以在 Spring 中 配置 實際的 過濾器,從而 能夠 充分利用 Spring 對 依賴注入的支援。

 

DelegatingFilterProxy 的  <filter-name> 值 是有意義的。

這個名字 用於 在 Spring 應用上下文中 尋找 過濾器Bean。 Spring Security  將自動 建立 一個 ID 為 springSecurityFilterChain的 過濾器Bean,

這就是 我們在 web.xml 中  為 DelegatingFilterProxy 所設定的 name 值。

 

springSecurityFilterChain 本身 是另一個 特殊的  過濾器,他也被稱為 FilterChainProxy。

它可以 連結 任意 一個 或 多個其它的 過濾器。

Spring Security  依賴一系列Servlet 過濾器來 提供 不同 的 安全性。但是,你幾乎不需要知道這些細節,

因為 你 不需要顯示 聲明 springSecurityFilterChain 以及 它所 連結 在一起的 其他 過濾器。

當配置  <http> 元素時, Spring Security 將 會為我們自動 建立 這些Bean。

 

j_spring_security_check

j_username

j_password

/spring_security_login 路徑 來訪問 這個自動產生的 表單。

 

代理Servlet過濾器

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.