Vaadin Bakery App登录认证机制及新增账号方法咨询
Hey there! Let's break down your questions about the Vaadin Bakery App's login flow step by step—super glad you're diving into this framework!
1. Where to find the
setAction('login') implementation logic In the Bakery App, the setAction("login") call in LoginView.java ties your Vaadin login form to Spring Security's built-in authentication endpoint. Here's how to trace the actual logic:
- First, the form submission sends a POST request to the
/loginpath (the string you passed tosetAction). - This request is intercepted by Spring Security's
UsernamePasswordAuthenticationFilter, which handles the core authentication workflow. - To see how users are loaded and validated, look at the
UserRepositoryUserDetailsServiceclass (usually in thecom.example.application.securitypackage). This class implements Spring'sUserDetailsServiceinterface, and itsloadUserByUsernamemethod fetches user details from the database (or in-memory store) to compare against the submitted credentials. - You'll also find the security configuration in
SecurityConfiguration.java, where the/loginendpoint is configured to accept form submissions, and rules for authentication/authorization are defined.
2. How to add new usernames and passwords
You have two common approaches, depending on your setup:
Option 1: Add in-memory users (for development/testing)
If you're using the in-memory user store (default in some Bakery App versions), modify the userDetailsService bean in SecurityConfiguration.java:
@Bean public UserDetailsService userDetailsService() { UserDetails user = User.withUsername("existing-user") .password(passwordEncoder().encode("existing-pass")) .roles("USER") .build(); // Add your new user here UserDetails newUser = User.withUsername("new-user") .password(passwordEncoder().encode("new-pass")) .roles("USER", "ADMIN") // Assign roles as needed .build(); return new InMemoryUserDetailsManager(user, newUser); }
Option 2: Add users to the database (for production)
If the Bakery App is using a database (most production setups):
- If you have the admin panel enabled, log in as an admin user, navigate to the User Management view (usually accessible via the sidebar), and create a new user directly through the UI.
- Alternatively, you can insert a new record directly into the
userstable (make sure to encode the password using the samePasswordEncoderconfigured inSecurityConfiguration—typically BCrypt).
3. Full login authentication workflow for Vaadin Bakery App
Let's walk through the end-to-end process:
- Initial Request: When a user visits the app, if they're not authenticated, Spring Security redirects them to
LoginView. - Form Rendering:
LoginViewdisplays the username/password form, withsetAction("login")telling Vaadin to submit the form data to the/loginendpoint. - Credential Submission: When the user clicks "Login", Vaadin sends a POST request to
/loginwith the username and password (along with a CSRF token, which Vaadin handles automatically). - Authentication Check: Spring Security's
UsernamePasswordAuthenticationFiltercatches the request, extracts the credentials, and usesUserRepositoryUserDetailsServiceto load the corresponding user from the database. - Password Validation: The submitted password is compared to the stored encoded password using the configured
PasswordEncoder(e.g., BCrypt). - Success/Failure:
- If valid: The authenticated user's details are stored in the
SecurityContext, and Spring Security redirects them to the default secured view (usuallyMainView). - If invalid: The user is sent back to
LoginView, and an error message is displayed (you'll see this handled inLoginView.javawith error parameter checks).
- If valid: The authenticated user's details are stored in the
- Session Management: The authenticated session is maintained, so the user stays logged in until they log out or the session expires.
内容的提问来源于stack exchange,提问作者Sudipta Roy
相关产品推荐
相关产品推荐

