I have defined feature in main webappcontext config file. This file also contains element which scans all packages except controller classes. A separate dispatcher-servlet context file scans controller package. If I apply method level security on controller methods that serve requests, it doesnt't work. It works only if I explicitly mention that element in dispatcher-servlet also.
From my earlier que开发者_StackOverflowstion on this forum, I understand that dispatcher-servlet context is the child of main webapp context. In that case, dispatcher-servlet should pickup that element from parent right?
See Spring Security FAQ (emphasis mine). If you apply pointcuts to service layer you only need to set <global-method-security>
in your app's security context.
In a Spring web application, the application context which holds the Spring MVC beans for the dispatcher servlet is often separate from the main application context. It is often defined in a file called myapp-servlet.xml, where “myapp” is the name assigned to the Spring DispatcherServlet in web.xml. An application can have multiple DispatcherServlets, each with its own isolated application context. The beans in these “child” contexts are not visible to the rest of the application. The “parent” application context is loaded by the ContextLoaderListener you define in your web.xml and is visible to all the child contexts. This parent context is usually where you define your security configuration, including the element). As a result any security constraints applied to methods in these web beans will not be enforced, since the beans cannot be seen from the DispatcherServlet context. You need to either move the declaration to the web context or moved the beans you want secured into the main application context.
Generally we would recommend applying method security at the service layer rather than on individual web controllers.
精彩评论