You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Vaadin Bakery App登录认证机制及新增账号方法咨询

Hey there! Let's break down your questions about the Vaadin Bakery App's login flow step by step—super glad you're diving into this framework!

1. Where to find the setAction('login') implementation logic

In the Bakery App, the setAction("login") call in LoginView.java ties your Vaadin login form to Spring Security's built-in authentication endpoint. Here's how to trace the actual logic:

  • First, the form submission sends a POST request to the /login path (the string you passed to setAction).
  • This request is intercepted by Spring Security's UsernamePasswordAuthenticationFilter, which handles the core authentication workflow.
  • To see how users are loaded and validated, look at the UserRepositoryUserDetailsService class (usually in the com.example.application.security package). This class implements Spring's UserDetailsService interface, and its loadUserByUsername method fetches user details from the database (or in-memory store) to compare against the submitted credentials.
  • You'll also find the security configuration in SecurityConfiguration.java, where the /login endpoint is configured to accept form submissions, and rules for authentication/authorization are defined.
2. How to add new usernames and passwords

You have two common approaches, depending on your setup:

Option 1: Add in-memory users (for development/testing)

If you're using the in-memory user store (default in some Bakery App versions), modify the userDetailsService bean in SecurityConfiguration.java:

@Bean
public UserDetailsService userDetailsService() {
    UserDetails user = User.withUsername("existing-user")
            .password(passwordEncoder().encode("existing-pass"))
            .roles("USER")
            .build();
            
    // Add your new user here
    UserDetails newUser = User.withUsername("new-user")
            .password(passwordEncoder().encode("new-pass"))
            .roles("USER", "ADMIN") // Assign roles as needed
            .build();
            
    return new InMemoryUserDetailsManager(user, newUser);
}

Option 2: Add users to the database (for production)

If the Bakery App is using a database (most production setups):

  • If you have the admin panel enabled, log in as an admin user, navigate to the User Management view (usually accessible via the sidebar), and create a new user directly through the UI.
  • Alternatively, you can insert a new record directly into the users table (make sure to encode the password using the same PasswordEncoder configured in SecurityConfiguration—typically BCrypt).
3. Full login authentication workflow for Vaadin Bakery App

Let's walk through the end-to-end process:

  1. Initial Request: When a user visits the app, if they're not authenticated, Spring Security redirects them to LoginView.
  2. Form Rendering: LoginView displays the username/password form, with setAction("login") telling Vaadin to submit the form data to the /login endpoint.
  3. Credential Submission: When the user clicks "Login", Vaadin sends a POST request to /login with the username and password (along with a CSRF token, which Vaadin handles automatically).
  4. Authentication Check: Spring Security's UsernamePasswordAuthenticationFilter catches the request, extracts the credentials, and uses UserRepositoryUserDetailsService to load the corresponding user from the database.
  5. Password Validation: The submitted password is compared to the stored encoded password using the configured PasswordEncoder (e.g., BCrypt).
  6. Success/Failure:
    • If valid: The authenticated user's details are stored in the SecurityContext, and Spring Security redirects them to the default secured view (usually MainView).
    • If invalid: The user is sent back to LoginView, and an error message is displayed (you'll see this handled in LoginView.java with error parameter checks).
  7. Session Management: The authenticated session is maintained, so the user stays logged in until they log out or the session expires.

内容的提问来源于stack exchange,提问作者Sudipta Roy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:03:18