Spring security, either http basic or form login authentication

我们两清 提交于 2019-12-03 17:16:58

The answer could be in the description of the create-session attribute:

  • never - Spring Security will never create a session, but will make use of one if the application does.
  • stateless - Spring Security will not create a session and ignore the session for obtaining a Spring Authentication.

Since you chose stateless the auth object persisted in the session after the form-login is ignored. Try if never works as you expect.

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!