为了账号安全,请及时绑定邮箱和手机立即绑定

主体为空:Spring

主体为空:Spring

UYOU 2021-12-01 14:33:16
我有以下@RestContoller登录:  @RequestMapping("/account/login")@ResponseBody@CrossOrigin(origins = "*", maxAge = 3600)public Principal login(Principal principal) {    logger.info("user logged " + principal.getName());    return principal;}我有客户端发出的以下请求,它是一个 Angularjs 应用程序。Accept: application/jsonAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9,fa;q=0.8,it;q=0.7Authorization: Basic bWVocmRhZGFsbGFoa2FyYW1pQGdtYWlsLmNvbTptZWhyZGFkConnection: keep-aliveDNT: 1Host: localhost:8080Origin: http://localhost:4200Referer: http://localhost:4200/loginUser-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.62 Safari/537.36但是我得到200了响应,服务器打印null并且客户端收到错误响应:HttpErrorResponse {headers: HttpHeaders, status: 400, statusText: "OK", url: "http://localhost:8080/account/login", ok: false, …}error: {timestamp: 1540136257516, status: 400, error: "Bad Request", exception: "org.springframework.web.bind.ServletRequestBindingException", message: "Missing request header 'header' for method parameter of type Header", …}headers: HttpHeaders {normalizedNames: Map(0), lazyUpdate: null, lazyInit: ƒ}message: "Http failure response for http://localhost:8080/account/login: 400 OK"name: "HttpErrorResponse"ok: falsestatus: 400statusText: "OK"url: "http://localhost:8080/account/login"__proto__: HttpResponseBase谁能帮我知道我哪里错了?它以前工作过,但我在 Angular 中使用了拦截器,但它不再工作了。我的登录控制器是这样的:@Injectable()export class AuthService {  constructor(public http: HttpClient, public auth: InterceptorAuthService) {  }  public logIn(user: User) {    this.auth.setUser(user);    return this.http.get(AppComponent.API_URL + "/account/login")      .pipe(        map(response => {            // login successful if there's a jwt token in the response            let user = response;// the returned user object is a principal object          })        ));  }}
查看完整描述

2 回答

?
明月笑刀无情

TA贡献1828条经验 获得超4个赞

尝试添加sec:authorize="isAuthenticated()到要显示用户名的“/account/login”模板

例如:

<h3 sec:authorize="isAuthenticated()" th:text="${user.username}"></h3>

如果它发生了,它将获得身份验证状态,否则,它不会显示<h3>代码块。


查看完整回答
反对 回复 2021-12-01
?
临摹微笑

TA贡献1982条经验 获得超2个赞

@Component

public class MyBasicAuthenticationEntryPoint extends BasicAuthenticationEntryPoint {

@Override

public void afterPropertiesSet() throws Exception {

    setRealmName("Baeldung");

    super.afterPropertiesSet();

}

@Override

public void commence(

  HttpServletRequest request, HttpServletResponse response, AuthenticationException authEx) 

  throws IOException, ServletException {

    response.addHeader("WWW-Authenticate", "Basic realm="" + getRealmName() + """);

    response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);

    PrintWriter writer = response.getWriter();

    writer.println("HTTP Status 401 - " + authEx.getMessage());

}

}


// inside filter we can get the 

SecurityContextHolder.getContext().getAuthentication().getPrincipal()


查看完整回答
反对 回复 2021-12-01
  • 2 回答
  • 0 关注
  • 133 浏览

添加回答

举报

0/150
提交
取消
意见反馈 帮助中心 APP下载
官方微信