Spring security issue with 404 error?

greetings all, i am using spring security 3.0.2, urlRewrite 3.1.0 , and i have a problem with spring security that i have a rule that all the pages in the app requires authentication except for some pages so my security.xml is:

<http use-expressions="true" > 
<intercept-url pattern="/" access="permitAll" />
<intercept-url pattern="/error"  filter="none" />  
<intercept-url pattern="/**" access="isAuthenticated()" />

in the web.xml i have defined the error page


and the issue is that if i am not a logged in user, and typed some url that doesn't exist in the app like app/notFoundUrl the spring security matched this page to the pattern /** which requires authentication, so the user is not redirected to the error page as expected, but redirected to the login page and after it, redirected to the error page

and i want that if the user typed a bad url if he's logged in or not, he's redirected to the error page directly.

i think that the problem is related to the web.xml, here's it:

<?xml version="1.0" encoding="ISO-8859-1"?>
<web-app version="2.5" xmlns="http://java.sun.com/xml/ns/javaee"
    xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd">

    <!-- Beans in these files will makeup the configuration of the root web application context -->
    <!-- Bootstraps the root web application context before servlet initialization-->

    <!-- Deploys the 'projects' dispatcher servlet whose configuration resides in /WEB-INF/servlet-config.xml-->

    <!-- Maps all /p URLs to the 'p' servlet -->


   <!-- force encoding on the requests -->




    <!-- Security -->



any ideas how to solve this issue ?

4 Answers

You have said:

i want that if the user typed a bad url if he's logged in or not, he's redirected to the error page directly

Spring security will intercept every request before it knows whether its url is valid or not, so a way to get it would be intercept all valid urls with some patterns, and add at the end a general pattern which could be accessed by anyone.

<intercept-url pattern="/" access="permitAll" />
<intercept-url pattern="/validUrl1Pattern"  access="permitAll" />  
<intercept-url pattern="/validUrl2Pattern"  access="permitAll" />  
<intercept-url pattern="/validUrl2Pattern"  access="permitAll" />  
<intercept-url pattern="/**" access="ROLE_ANONYMOUS" />

The problem of this configuration is that is probably difficult to find patterns for all the valid urls if your application is complex.

Yep just add this:

<intercept-url pattern="/error/**" access="permitAll" />

That will make it so that anyone can get to all your error pages.

when you set the attribute access="true", you tell spring-security to check if the user has the security attribute (which is normally a role) named "true" . I don't think that is your goal?

to bypass security, you may set filters="none" and skip the access attribute: <intercept-url pattern="/errorpage" filters="none" />

see documentation of <intercept-url>

