spring security (3.0.x) and user impersonation

前端 未结 3 1494
Happy的楠姐
Happy的楠姐 2020-12-31 18:40

In my web application, there are times when an authenticated admin might want to impersonate another valid user of a system without having to know that user\'s password.

3条回答
  •  盖世英雄少女心
    2020-12-31 19:10

    It's in the Spring Security 3 and Spring Security 4 docs aptly named, "Run-As Authentication Replacement."

    The AbstractSecurityInterceptor is able to temporarily replace the Authentication object in the SecurityContext and SecurityContextHolder during the secure object callback phase.

提交回复
热议问题