将Spring Web应用(web.xml)迁移至Spring Boot 1.5.10遇认证问题求助
Let's walk through what's wrong with your current setup and how to fix it to get back container-managed authentication and cross-app session sharing:
1. Your Custom MyAuthProvider Isn't Actually Validating Credentials
Right now, your MyAuthProvider takes the incoming username/password and immediately wraps them into an authenticated token without checking against tomcat-users.xml or application-users.properties. It's essentially skipping all real validation—so no wonder your container's user stores aren't being used!
You don't need this custom provider if you want to reuse the container's built-in authentication system. Let's remove it entirely.
2. Configure Spring Security to Use Container-Managed Authentication
To make Spring Security delegate to Tomcat/Wildfly's native authentication realms (and their user stores), update your security config to use the ServletContainerAuthenticationProvider instead of your custom provider:
@Configuration @EnableWebSecurity @EnableGlobalMethodSecurity(securedEnabled = true) public class MySecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(final HttpSecurity http) throws Exception { http .authorizeRequests() .anyRequest().fullyAuthenticated() .and() .httpBasic() .realmName("myRealm") .and() .csrf().disable(); } @Override protected void configure(AuthenticationManagerBuilder auth) throws Exception { // Delegate authentication to the servlet container (Tomcat/Wildfly) auth.authenticationProvider(new ServletContainerAuthenticationProvider()); } }
For Tomcat:
Ensure your tomcat-users.xml is in the correct location (e.g., src/main/resources/tomcat/conf if using embedded Tomcat) and has valid users/roles matching your realm:
<tomcat-users xmlns="http://tomcat.apache.org/xml" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://tomcat.apache.org/xml tomcat-users.xsd" version="1.0"> <role rolename="admin"/> <user username="your-user" password="your-password" roles="admin"/> </tomcat-users>
If using embedded Tomcat, add a bean to load this custom realm:
@Bean public TomcatEmbeddedServletContainerFactory tomcatFactory() { return new TomcatEmbeddedServletContainerFactory() { @Override protected void postProcessContext(Context context) { Realm realm = new MemoryRealm(); realm.setPathname("src/main/resources/tomcat/conf/tomcat-users.xml"); context.setRealm(realm); } }; }
For Wildfly:
Wildfly automatically uses application-users.properties and application-roles.properties from its configuration directory. Just ensure you've added users via the Wildfly CLI (add-user.sh/add-user.bat) and the roles match your application's requirements. The ServletContainerAuthenticationProvider will automatically hook into Wildfly's authentication system.
3. Restore Cross-App Authentication Sharing
Your original setup used container-level session sharing. To replicate this, choose one of these options:
Option 1: Container-Level Session Replication
- Tomcat: Configure a cluster with session replication (using multicast or a shared file system). All three apps need to be deployed on the same Tomcat cluster.
- Wildfly: Set up a domain cluster with session replication enabled across nodes.
Option 2: Spring Session (Cross-Container Compatible)
For a flexible solution that works across Tomcat/Wildfly, use Spring Session to store sessions in a shared datastore like Redis:
- Add the Spring Session dependency to your
pom.xml:<dependency> <groupId>org.springframework.session</groupId> <artifactId>spring-session-data-redis</artifactId> </dependency> - Configure Redis connection in
application.properties:spring.redis.host=your-redis-host spring.redis.port=6379 spring.session.store-type=redis - Add
@EnableRedisHttpSessionto your security config or a separate configuration class.
This will store all authentication sessions in Redis, so users only need to log in once across all three apps.
4. Migrate the Error Page Configuration
Replace your original web.xml error page with Spring Boot's equivalent configuration. Add this bean to your config:
@Bean public ErrorPageRegistrar errorPageRegistrar() { return registry -> registry.addErrorPages(new ErrorPage(Throwable.class, "/aviso_page.jsp")); }
Or set it directly in application.properties:
server.error.path=/aviso_page.jsp
内容的提问来源于stack exchange,提问作者carolnogueira

