参考链接:
http://blog.csdn.net/q274974359/article/details/51924818
http://blog.csdn.net/u012367513/article/details/38866465
初学者1-5简单认识,讲的很详细
http://blog.csdn.net/yin380697242/article/details/51771631 spring security 起步一:框架搭建
http://blog.csdn.net/yin380697242/article/details/51786388 spring security起步二:自定义登录页
http://blog.csdn.net/yin380697242/article/details/51893397 spring security起步三:自定义登录配置与form-login属性详解
http://blog.csdn.net/yin380697242/article/details/51921593 spring security起步四:退出登录配置以及logout属性详解
http://blog.csdn.net/yin380697242/article/details/51921612 spring security起步五:Remember Me功能实现
http://blog.csdn.net/yin380697242/article/details/51959422 spring security起步六:基于数据库的用户认证
pom.xml
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd">
<modelVersion>4.0.0</modelVersion>
<groupId>com.qytx</groupId>
<artifactId>spring-security</artifactId>
<packaging>war</packaging>
<version>1.0-SNAPSHOT</version>
<name>spring-security Maven Webapp</name>
<url>http://maven.apache.org</url>
<dependencies>
<dependency>
<groupId>junit</groupId>
<artifactId>junit</artifactId>
<version>3.8.1</version>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.springframework.security</groupId>
<artifactId>spring-security-web</artifactId>
<version>4.1.1.RELEASE</version>
</dependency>
<dependency>
<groupId>org.springframework.security</groupId>
<artifactId>spring-security-config</artifactId>
<version>4.1.1.RELEASE</version>
</dependency>
<dependency>
<groupId>commons-logging</groupId>
<artifactId>commons-logging</artifactId>
<version>1.2</version>
</dependency>
</dependencies>
<build>
<finalName>spring-security</finalName>
</build>
</project>
web.xml
<!DOCTYPE web-app PUBLIC
"-//Sun Microsystems, Inc.//DTD Web Application 2.3//EN"
"http://java.sun.com/dtd/web-app_2_3.dtd" >
<web-app>
<display-name>Archetype Created Web Application</display-name>
<context-param>
<param-name>contextConfigLocation</param-name>
<param-value>classpath*:application.xml</param-value>
</context-param>
<filter>
<filter-name>springSecurityFilterChain</filter-name>
<filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
</filter>
<filter-mapping>
<filter-name>springSecurityFilterChain</filter-name>
<url-pattern>/*</url-pattern>
</filter-mapping>
<listener>
<listener-class>
org.springframework.web.context.ContextLoaderListener
</listener-class>
</listener>
</web-app>
application.xml
<?xml version="1.0" encoding="UTF-8"?>
<beans:beans xmlns="http://www.springframework.org/schema/security"
xmlns:beans="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://www.springframework.org/schema/beans
http://www.springframework.org/schema/beans/spring-beans-3.2.xsd
http://www.springframework.org/schema/security
http://www.springframework.org/schema/security/spring-security-4.1.xsd ">
<!-- 不需要进行安全认证的资源 -->
<http pattern="/resources/**" security="none" />
<!-- 资源所需要的权限 -->
<http use-expressions="true" auto-config="true">
<csrf disabled="true" />
<form-login login-page="/login.html" default-target-url="/home.jsp" authentication-failure-url="/login.html?erro"/>
<logout logout-success-url="/out.jsp" />
<remember-me key="authorition" />
<!-- <intercept-url pattern="/index.jsp*" access="permitAll" />
<intercept-url pattern="/user.jsp*" access="hasRole('ROLE_USER')" />
<intercept-url pattern="/admin.jsp*" access="hasRole('ROLE_ADMIN')" />-->
<intercept-url pattern="/login.html" access="permitAll" />
<intercept-url pattern="/out.jsp" access="permitAll" />
<intercept-url pattern="/favicon.ico" access="permitAll" />
<intercept-url pattern="/**" access="hasRole('ROLE_USER')" />
</http>
<!-- 配置用户和相应的权限 -->
<authentication-manager>
<authentication-provider>
<user-service>
<user name="test" password="test" authorities="ROLE_USER" />
<user name="admin" password="admin" authorities="ROLE_ADMIN" />
</user-service>
</authentication-provider>
</authentication-manager>
</beans:beans>