亚洲精品久久久中文字幕-亚洲精品久久片久久-亚洲精品久久青草-亚洲精品久久婷婷爱久久婷婷-亚洲精品久久午夜香蕉

您的位置:首頁技術文章
文章詳情頁

java - Spring Session, Spring Security 如何在無權限攔截的url不自動創建session?

瀏覽:53日期:2023-10-24 09:08:00

問題描述

我做了一個API服務器提供給手機端調用,用Spring Session連接Redis來做多臺tomcat的session共享,用security來做API的權限攔截,并且使用了x-auth-token也就是header的token驗證。現在遇到一個問題,有一些API是無權限驗證的,但訪問這些API時,spring會為每次request都創建session,返回一個新的x-auth-token,這樣可能會導致session過多,請問如何配置才能讓這種情況無需創建session呢?已經配置create-session='never',但不管用。以下是security配置

<http realm='Protected API' use-expressions='true' auto-config='false'create-session='never' entry-point-ref='customAuthenticationEntryPoint'><intercept-url pattern='/auth/login/phone' access='permitAll()' /><intercept-url pattern='/**' access='isAuthenticated()' /><access-denied-handler ref='customAccessDeniedHandler' /> </http>

spring session

<!-- 在HTTP的header中使用x-auth-token:來實現session --> <bean /><!-- This is essential to make sure that the Spring Security session registryis notified when the session is destroyed. --> <bean /> <bean scope='singleton'><!-- session為60分鐘過期 --><property name='maxInactiveIntervalInSeconds' value='${session.maxInactiveIntervalInSeconds}'></property> </bean>...省略redis pool配置

問題解答

回答1:

找到原因了,首先打開log的trace,然后trace org.springframework,這個時候可以看到每次創建新session時都會有日志,spring會打印session的創建棧

java.lang.RuntimeException: For debugging purposes only (not an error) at org.springframework.session.web.http.SessionRepositoryFilter$SessionRepositoryRequestWrapper.getSession(SessionRepositoryFilter.java:368) at org.springframework.session.web.http.SessionRepositoryFilter$SessionRepositoryRequestWrapper.getSession(SessionRepositoryFilter.java:390) at org.springframework.session.web.http.SessionRepositoryFilter$SessionRepositoryRequestWrapper.getSession(SessionRepositoryFilter.java:217) at javax.servlet.http.HttpServletRequestWrapper.getSession(HttpServletRequestWrapper.java:238) at xxx.xxxxxxxx.LogFilter.doFilterInternal(LogFilter.java:52) at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107) at org.springframework.web.filter.DelegatingFilterProxy.invokeDelegate(DelegatingFilterProxy.java:346) at org.springframework.web.filter.DelegatingFilterProxy.doFilter(DelegatingFilterProxy.java:262) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:243) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:210) at org.springframework.security.web.FilterChainProxy.doFilterInternal(FilterChainProxy.java:208) at org.springframework.security.web.FilterChainProxy.doFilter(FilterChainProxy.java:177) at org.springframework.web.filter.DelegatingFilterProxy.invokeDelegate(DelegatingFilterProxy.java:346) at org.springframework.web.filter.DelegatingFilterProxy.doFilter(DelegatingFilterProxy.java:262) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:243) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:210) at org.springframework.session.web.http.SessionRepositoryFilter.doFilterInternal(SessionRepositoryFilter.java:167) at org.springframework.session.web.http.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:80) at org.springframework.web.filter.DelegatingFilterProxy.invokeDelegate(DelegatingFilterProxy.java:346) at org.springframework.web.filter.DelegatingFilterProxy.doFilter(DelegatingFilterProxy.java:262) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:243) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:210) at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:222) at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:123) at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:502) at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:171) at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:100) at org.apache.catalina.valves.AccessLogValve.invoke(AccessLogValve.java:953) at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:118) at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:408) at org.apache.coyote.http11.AbstractHttp11Processor.process(AbstractHttp11Processor.java:1041) at org.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process(AbstractProtocol.java:603) at org.apache.tomcat.util.net.JIoEndpoint$SocketProcessor.run(JIoEndpoint.java:310) at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142) at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617) at java.lang.Thread.run(Thread.java:745)

其中可以找到xxx.xxxx這行,LogFilter第52行查看代碼發現調用了req.getSession(),雖然create-session配置了never,但若有代碼調用req.getSession(),spring仍然會創建一個全新的session。盡量不要在filter等全局攔截器里調用req.getSession(),否則會隨時創建一個新的session

標簽: java
主站蜘蛛池模板: 97国内精品久久久久久久影视 | 久热精品视频在线观看99小说 | 国产精品二 | 国产免费久久精品99久久 | 精品国产一区二区三区在线观看 | 女人a级毛片| 国产精品久久99 | 国产欧美精品系列在线播放 | 免费一级毛片在线视频观看 | 亚洲高清美女一区二区三区 | 国产精品高清一区二区不卡 | 在线播放交视频 | 欧美成人观看免费版 | 亚洲精品一区二区三区国产 | 亚洲一级片在线播放 | 美女一级毛片毛片在线播放 | 国产超级碰碰在线公开视频 | 欧美一级毛片大片免费播放 | 亚洲欧美v视色一区二区 | 久久久噜噜噜久久中文字幕色伊伊 | 狠狠色噜噜狠狠狠狠狠色综合久久 | 亚洲国产天堂久久综合 | 欧美亚洲一区二区三区在线 | 免费中文字幕不卡视频 | 亚洲特黄 | 毛片免费观看的视频在线 | 色综合夜夜嗨亚洲一二区 | 三级视频中文字幕 | 亚洲男女视频 | 亚洲成在人线久久综合 | 亚洲精品一区二区观看 | 国产a不卡片精品免费观看 国产a毛片高清视 | 精品国产一区二区三区四 | 在线视频一二三区 | 色婷综合 | 久久精品这里是免费国产 | 草草在线观看 | 国产福利在线观看第二区 | 免费无遮挡十八污污网站 | 国产国语一级毛片全部 | 国产 欧美 日产久久 |