基于LDAP的RBAC:新版Spring Security权限校验方案问询
LDAP用户组权限校验在新版Spring Security中的实现
目标
现有一个/secure端点,要求LDAP用户必须属于admin组才能访问,如何在新版Spring Security中校验用户的授权权限?
背景
有一个基于OpenLDAP容器的LDAP认证可复现示例:在pre-upgrade版本中,unauthorized用户可完成认证但无法访问/secure端点;但升级到main分支当前版本后,unauthorized用户既能认证又能访问/secure端点,这不符合预期。
问题根源在于升级时对ldapAuthoritiesPopulator()的修改,重点查看SecurityConfig.java的版本差异即可发现。原ldapAuthoritiesPopulator()内部的getGroupMembershipRoles()方法负责角色校验,但升级后该方法已被移除。当前需要明确的核心问题是:基于LDAP组成员身份的端点权限校验逻辑应该迁移到哪里?
相关参考
- 文档:如何在不使用WebSecurityConfigurerAdapter的情况下发布AuthenticationManager @Bean
- 指南:嵌入式服务器下的LDAP认证
- Spring LDAP文档:使用DirContextAdapter访问属性
认证日志输出
升级前日志(authorized用户登录后,unauthorized用户登录)
10:22:07.156 [http-nio-8080-exec-3] WARN org.example.LoggerListener - Authentication event AuthenticationSuccessEvent: authorized; details: WebAuthenticationDetails [RemoteIpAddress=0:0:0:0:0:0:0:1, SessionId=A978FE05724BD750548AD8148347D665] 10:22:07.157 [http-nio-8080-exec-3] WARN org.example.LoggerListener - Authentication event SessionFixationProtectionEvent: authorized; details: WebAuthenticationDetails [RemoteIpAddress=0:0:0:0:0:0:0:1, SessionId=A978FE05724BD750548AD8148347D665] 10:22:07.157 [http-nio-8080-exec-3] WARN org.example.LoggerListener - Authentication event InteractiveAuthenticationSuccessEvent: authorized; details: WebAuthenticationDetails [RemoteIpAddress=0:0:0:0:0:0:0:1, SessionId=A978FE05724BD750548AD8148347D665] 10:23:43.668 [http-nio-8080-exec-8] WARN org.example.LoggerListener - Authentication event AuthenticationFailureBadCredentialsEvent: unauthorized; details: WebAuthenticationDetails [RemoteIpAddress=0:0:0:0:0:0:0:1, SessionId=65900F1284AA62D158BCA96A22D3744A]; exception: User must be a member of ROLE_ADMIN
升级后日志(authorized用户登录后,unauthorized用户登录)
10:15:24.101 [http-nio-8080-exec-4] WARN org.example.LoggerListener - Authentication event SessionFixationProtectionEvent: authorized; authorities: []; details: WebAuthenticationDetails [RemoteIpAddress=0:0:0:0:0:0:0:1, SessionId=E3CDB4A1CF9B3766A5DB70F9D7C50586] 10:15:24.102 [http-nio-8080-exec-4] WARN org.example.LoggerListener - Authentication event InteractiveAuthenticationSuccessEvent: authorized; authorities: []; details: WebAuthenticationDetails [RemoteIpAddress=0:0:0:0:0:0:0:1, SessionId=E3CDB4A1CF9B3766A5DB70F9D7C50586] 10:25:38.098 [http-nio-8080-exec-3] WARN org.example.LoggerListener - Authentication event SessionFixationProtectionEvent: unauthorized; authorities: []; details: WebAuthenticationDetails [RemoteIpAddress=0:0:0:0:0:0:0:1, SessionId=10D2AD100DDFF5CB15FDE5526BE85722] 10:25:38.098 [http-nio-8080-exec-3] WARN org.example.LoggerListener - Authentication event InteractiveAuthenticationSuccessEvent: unauthorized; authorities: []; details: WebAuthenticationDetails [RemoteIpAddress=0:0:0:0:0:0:0:1, SessionId=10D2AD100DDFF5CB15FDE5526BE85722]
内容的提问来源于stack exchange,提问作者S Mayer
相关产品推荐
相关产品推荐

