You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security 3升级至4(搭配PrimeFaces 5.2)遇问题求助

Spring Security 3.2.10 → 4.0.4 Migration Troubleshooting Guide

Hey there, let's break down the potential issues in your migrated config and walk through fixes that should get your setup running smoothly again. I’ve reviewed both your working Spring Security 3 config and the problematic Spring Security 4 version, and here are the key areas to address:

1. Misconfigured Authentication Entry Point

Your LoginUrlAuthenticationEntryPoint is currently pointing to /j_spring_security_check (the login processing URL), but this class expects the login page URL (the same value you use in <security:form-login login-page="..."/>).

This mismatch will cause incorrect redirect behavior—like infinite loops or 404 errors when the entry point tries to send unauthenticated users to the login page.

Fix: Update the entry point to use your actual login page URL:

<bean id="authenticationEntryPoint" class= "org.springframework.security.web.authentication.LoginUrlAuthenticationEntryPoint">
    <constructor-arg value="/your-login-page.jsf"/> <!-- Replace with your form-login's login-page value -->
</bean>

2. Conflicting Custom UsernamePasswordAuthenticationFilter

You’ve added a custom UsernamePasswordAuthenticationFilter before the default FORM_LOGIN_FILTER, but Spring Security 4’s auto-config="true" already configures this filter automatically. Your custom filter is missing critical properties (like filterProcessesUrl, success/failure handlers) which will break login flow or cause conflicts with the default filter.

Fix Options:

  • Option 1 (Simpler): Remove the custom authenticationFilter bean and the <security:custom-filter> entry entirely. The auto-configured filter will handle login using your <security:form-login> settings.
  • Option 2 (If you need customization): If you must keep the custom filter, fully configure it to match your login settings and disable auto-config to avoid conflicts:
<bean id="authenticationFilter" class="org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter">
    <property name="authenticationManager" ref="authenticationManager"/>
    <property name="filterProcessesUrl" value="/j_spring_security_check"/> <!-- Match form-login's login-processing-url -->
    <property name="authenticationSuccessHandler">
        <bean class="org.springframework.security.web.authentication.SavedRequestAwareAuthenticationSuccessHandler">
            <property name="defaultTargetUrl" value="/your-default-target.jsf"/> <!-- Match form-login's default-target-url -->
        </bean>
    </property>
    <property name="authenticationFailureHandler">
        <bean class="org.springframework.security.web.authentication.SimpleUrlAuthenticationFailureHandler">
            <property name="defaultFailureUrl" value="/your-authentication-failure-url.jsf"/> <!-- Match form-login's authentication-failure-url -->
        </bean>
    </property>
</bean>

Then set auto-config="false" in your <security:http> element and manually configure all required filters.

3. Missing Session Management Filter in the Filter Chain

Your sessionManagementFilter bean exists in the config, but you haven’t added it to Spring Security’s filter chain. In Spring Security 4, custom filters must be explicitly placed in the chain using <security:custom-filter>. Without this, your invalidSessionStrategy won’t trigger when sessions expire.

Fix: Add the filter to the chain at the correct position:

<security:http auto-config='true' use-expressions="true" disable-url-rewriting="false" entry-point-ref="authenticationEntryPoint" >
    ...
    <security:custom-filter before="SESSION_MANAGEMENT_FILTER" ref="sessionManagementFilter"/>
    ...
</security:http>

4. Typo in Logout URL

Your logout configuration has a missing leading slash in logout-url:

<security:logout logout-success-url="..." logout-url="j_spring_security_logout" />

This will cause the logout request to be resolved relative to the current URL, leading to 404 errors when users try to log out.

Fix: Add the leading slash:

<security:logout logout-success-url="..." logout-url="/j_spring_security_logout" />

5. Compatibility Check for Custom Expression Handler

Your custom MethodSecurityExpressionHandler needs to be compatible with Spring Security 4’s API. Spring 4 introduced changes to method security expression interfaces (like updates to MethodSecurityExpressionOperations).

Check:

  • Ensure your custom handler extends org.springframework.security.access.expression.method.DefaultMethodSecurityExpressionHandler (if it doesn’t already)
  • Verify all overridden methods match the Spring 4 method signatures
  • Look for NoSuchMethodError or ClassCastException in your logs—these are clear signs of API incompatibility

Additional Debugging Tip

Enable debug-level logging for Spring Security (set org.springframework.security to DEBUG in your logging config). This will show you the full filter chain execution, authentication flow details, and any exceptions thrown during processing—this is often the fastest way to pinpoint exactly where things are failing.


内容的提问来源于stack exchange,提问作者Michael Hegner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:28:06