如何禁用Activiti Spring REST API基础认证并复用现有安全配置
Hey there! I’ve tackled this exact issue before while working with Activiti 5.x and Spring 4.x, so let’s break down how to turn off Activiti’s built-in authentication and hook up your existing security system.
Why You’re Running Into This
The org.activiti.rest.servlet.WebConfigurer listener in your web.xml automatically registers Activiti’s default authentication filters (like basic auth) for its REST endpoints. To reuse your custom Spring Security setup, we first need to disable this default auth layer.
Solution 1: Use a Context Parameter (Simplest Fix)
Activiti 5.x provides a built-in flag to skip default authentication setup. Add this context parameter to your web.xml (place it above your WebConfigurer listener entry):
<context-param> <param-name>activiti.rest.authentication.enabled</param-name> <param-value>false</param-value> </context-param>
This will prevent the listener from registering Activiti’s default auth filters entirely.
Solution 2: Customize WebConfigurer (If Solution 1 Fails)
If the context parameter doesn’t work (due to classpath or configuration quirks), create a custom subclass of WebConfigurer to override the security initialization logic:
First, write the custom listener class:
package com.yourcompany.activiti.config; import org.activiti.rest.servlet.WebConfigurer; import javax.servlet.ServletContext; public class CustomActivitiWebConfigurer extends WebConfigurer { @Override protected void initSecurity(ServletContext servletContext) { // Empty implementation to skip Activiti's default security setup } }
Then update your web.xml to use this custom listener instead of the default:
<listener> <listener-class>com.yourcompany.activiti.config.CustomActivitiWebConfigurer</listener-class> </listener>
Final Step: Secure Activiti REST Endpoints with Your Spring Security
Once Activiti’s default auth is disabled, add rules to your Spring Security configuration to protect the Activiti REST endpoints (typically under /activiti-rest/**):
XML Config Example:
<security:http auto-config="false" use-expressions="true"> <!-- Your existing security rules --> <security:intercept-url pattern="/activiti-rest/**" access="isAuthenticated()" /> <!-- Include your authentication providers, filters, etc. --> </security:http>
Java Config Example:
@Override protected void configure(HttpSecurity http) throws Exception { http // Your existing security configuration .authorizeRequests() .antMatchers("/activiti-rest/**").authenticated(); }
That’s it! Your existing Spring Security system will now handle authentication for Activiti’s REST services instead of the default Activiti auth layer.
内容的提问来源于stack exchange,提问作者Learn Hadoop

