You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SpringBoot整合Togglz实现UsernameActivationStrategy技术咨询

How to Get Togglz UsernameActivationStrategy Working in Spring Boot

Let's break down how to get the UsernameActivationStrategy up and running in your Spring Boot + Togglz POC. I'll walk through the key pieces you're missing and how to validate everything works as expected.

First, Understand How UsernameActivationStrategy Works

This strategy checks if the current logged-in user's username matches any of the usernames specified in the PARAM_USERS activation parameter. If there's a match, the feature is enabled (even if it's not enabled globally). If no match, it falls back to the feature's default state (or any other strategies you've configured).

Your current code is on the right track—you've annotated the HELLO feature with the strategy and specified "suga" as the allowed user. Now we just need to make sure Togglz can correctly fetch the current user's username and use it for the check.


Step 1: Fix UserProvider & Spring Security Integration

Your SpringSecurityUserProvider is correctly set up, but we need to ensure it can actually retrieve the current user's username from Spring Security's context. Here's what to check:

a. Ensure Spring Security is Configured to Authenticate Users

The SpringSecurityUserProvider pulls the current user from SecurityContextHolder.getContext().getAuthentication(). If you haven't set up Spring Security yet, add a basic configuration to create test users (like your "suga" user). For example:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.provisioning.InMemoryUserDetailsManager;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .anyRequest().authenticated()
            )
            .formLogin(form -> form.permitAll()); // Enable simple form login for testing
        return http.build();
    }

    @Bean
    public UserDetailsService userDetailsService() {
        UserDetails suga = User.withUsername("suga")
            .password("{noop}password123") // {noop} means no password encoding for testing
            .roles("USER", "ADMIN") // Include ADMIN role to access Togglz console
            .build();

        return new InMemoryUserDetailsManager(suga);
    }
}

b. Verify the UserProvider Returns the Correct Username

The SpringSecurityUserProvider you're using does two things:

  1. Controls access to the Togglz admin console (only users with ADMIN_ROLE can modify feature states)
  2. Provides the current user's username to activation strategies like UsernameActivationStrategy

As long as your Spring Security Authentication object returns the correct username via getName(), this will work. For UserDetails users (like the example above), getName() delegates to getUsername(), so it's set correctly.


Step 2: Validate the Feature Activation

Now let's test if the HELLO feature activates only for the "suga" user. Add a simple controller to check the feature state:

import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;

@RestController
public class FeatureTestController {

    @GetMapping("/hello-feature")
    public String checkHelloFeature() {
        if (Features.HELLO.isActive()) {
            return "HELLO feature is ACTIVE for current user!";
        } else {
            return "HELLO feature is INACTIVE for current user.";
        }
    }
}

Test Scenarios:

  • Log in as "suga": Access /hello-feature—you should see the active message, since the username matches the PARAM_USERS value.
  • Log in as another user (add a test user to the UserDetailsService): The feature should be inactive, since the username doesn't match.
  • Anonymous user: The feature will stay inactive (since there's no username to match).

Step 3: Avoid Common Pitfalls

  • Don't let the state file override your annotation: Your FileBasedStateRepository uses /tmp/features.properties. If this file already exists with a manual state for HELLO, it will override the annotation's activation strategy. Delete the file before testing to use the annotation defaults.
  • Check for typos: Make sure the username in PARAM_USERS exactly matches the logged-in user's username (case-sensitive!).
  • Ensure Togglz is properly auto-configured: If you're using the Togglz Spring Boot starter, you don't need extra configuration beyond your TogglzConfig class. If not, make sure you've added all required dependencies to your pom.xml.

Final Notes

Your original Features enum and TogglzConfig class are mostly correct—you just needed to tie in Spring Security to provide a valid user context. Once you have the security setup in place, the UsernameActivationStrategy will automatically compare the current user's username to the list you specified.

内容的提问来源于stack exchange,提问作者Sugandha Mishra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 12:32:38