乐途乐途
主页
  • 计算机基础

    • TCP/IP
    • Linux
    • HTTP
  • 数据库

    • SQL
    • MySQL 5.7
  • 编程语言

    • C
    • C++
    • Java SE
    • Python2
    • Python3
  • 数据格式

    • JSON
    • XML
  • 认证与安全

    • JWT
  • 工具

    • Markdown
  • Git

    • GitFlow
  • Quartz

    • Quartz
  • Java

    • Maven 入门
    • Maven 进阶
    • MyBatis
    • Spring
    • Spring MVC
  • Java

    • Spring Boot
    • Spring Cloud
    • Spring Cloud Alibaba
    • Spring Security
    • Spring AI
    • Spring Batch
    • Kafka
    • Java 设计模式
  • 缓存

    • Redis
  • 搜索引擎

    • Elasticsearch
  • 分布式协调

    • ZooKeeper
联系
阿里云
主页
  • 计算机基础

    • TCP/IP
    • Linux
    • HTTP
  • 数据库

    • SQL
    • MySQL 5.7
  • 编程语言

    • C
    • C++
    • Java SE
    • Python2
    • Python3
  • 数据格式

    • JSON
    • XML
  • 认证与安全

    • JWT
  • 工具

    • Markdown
  • Git

    • GitFlow
  • Quartz

    • Quartz
  • Java

    • Maven 入门
    • Maven 进阶
    • MyBatis
    • Spring
    • Spring MVC
  • Java

    • Spring Boot
    • Spring Cloud
    • Spring Cloud Alibaba
    • Spring Security
    • Spring AI
    • Spring Batch
    • Kafka
    • Java 设计模式
  • 缓存

    • Redis
  • 搜索引擎

    • Elasticsearch
  • 分布式协调

    • ZooKeeper
联系
阿里云
  • 学习路径
  • 第1章 Spring Security 基础

    • 本章定位
    • Spring Security 是什么
    • DelegatingFilterProxy
    • 安全过滤器链
    • SecurityFilterChain
    • 过滤器执行顺序
  • 第2章 认证

    • 本章定位
    • Authentication
    • 认证流程
    • AuthenticationManager
    • ProviderManager
    • DaoAuthenticationProvider
    • UserDetails
    • UserDetailsService
    • PasswordEncoder
    • BCryptPasswordEncoder
    • DelegatingPasswordEncoder
    • 表单登录
    • SecurityContext
    • SecurityContextHolder
    • UsernamePasswordAuthenticationToken
  • 第3章 授权

    • 本章定位
    • 授权模型
    • GrantedAuthority
    • AccessDecisionManager
    • AccessDecisionVoter
    • URL 级别授权
    • 方法级别安全
    • @PreAuthorize
    • @PostAuthorize
    • @PreFilter
    • @PostFilter
    • @Secured
    • RoleHierarchy
  • 第4章 过滤器链

    • 本章定位
    • FilterChainProxy
    • SecurityContextHolderFilter
    • LogoutFilter
    • BasicAuthenticationFilter
    • CsrfFilter
    • CorsFilter
    • HeaderWriterFilter
    • AnonymousAuthenticationFilter
    • RequestCacheAwareFilter
    • ExceptionTranslationFilter
    • FilterSecurityInterceptor
  • 第5章 会话管理

    • 本章定位
    • 会话管理
    • SessionFixation
    • 会话并发控制
    • SessionCreationPolicy
    • RememberMe
  • 第6章 JWT

    • 本章定位
    • JWT
    • JwtDecoder
    • JWT 认证
    • JwtAuthenticationConverter
  • 第7章 OAuth2

    • 本章定位
    • OAuth2 基础
    • OAuth2 Client
    • OAuth2 Resource Server
    • 第三方登录配置
  • 第8章 攻击防护

    • 本章定位
    • CSRF 跨站请求伪造防护
    • CORS 跨域防护
    • Clickjacking 点击劫持防护
    • 安全响应头
    • Session Fixation 会话固定防护
  • 第9章 测试

    • 本章定位
    • 安全测试
    • @WithMockUser
    • 最佳实践

"认证通过后,小崔问:'现在用户能登录了,但怎么控制谁能看成绩、谁能改分数?'白歌说:'认证回答你是谁,授权回答你能做什么。Spring Security 的授权体系从 URL 到方法到数据行,层层设防。'这一章,你将掌握三层授权模型的完整机制。"

章节导读:授权

本章定位

本章解决的核心问题:Spring Security 如何在用户身份确认后,通过 URL 级、方法级、实例级三层模型,实现从粗到细的访问控制决策。 涵盖授权决策架构(AccessDecisionManager + Voter)、权限模型(Role/Authority/Hierarchy)和五大方法安全注解。

学习路线图

学习顺序说明:先建立授权三层模型的整体认知(URL→方法→实例)→ 深入授权决策架构:AccessDecisionManager(决策核心)+ AccessDecisionVoter(投票单元)+ GrantedAuthority(权限载体)→ 掌握 RoleHierarchy(角色继承)简化权限配置 → 逐一吃透五大方法安全注解:PreAuthorize(前置拦截)、PostAuthorize(后置拦截)、PreFilter(入参过滤)、PostFilter(出参过滤)、Secured(JSR-250 兼容)。

文件关系说明

文件一句话角色
授权模型.md建立三层授权模型的整体认知:URL 级、方法级、实例级,从粗到细纵深防御。
URL级别授权.mdHttpSecurity 的 authorizeRequests() DSL:路径匹配、角色/权限表达式、配置顺序。
方法级别安全.md@EnableGlobalMethodSecurity 启用注解驱动的方法级授权,与 URL 级互补。
AccessDecisionManager.md授权决策核心:汇总所有 Voter 投票结果,以 Affirmative/Consensus/Unanimous 策略判定放行或拒绝。
AccessDecisionVoter.md投票单元:对特定配置属性(如 hasRole('ADMIN'))进行投票(GRANT/ABSTAIN/DENY)。
GrantedAuthority.md权限载体:封装用户拥有的权限字符串(ROLE_ADMIN、READ_ORDER),认证后写入 Authentication。
RoleHierarchy.md角色继承:定义 ROLE_ADMIN > ROLE_USER > ROLE_GUEST,避免重复赋权。
PreAuthorize.md前置拦截:方法调用前执行 SpEL 表达式,如 @PreAuthorize("hasRole('ADMIN')")。
PostAuthorize.md后置拦截:方法执行后校验返回值,如 @PostAuthorize("returnObject.owner == authentication.name")。
PreFilter.md入参过滤:过滤传入集合中的元素,如只保留当前用户的数据。
PostFilter.md出参过滤:过滤返回集合中的元素,如只返回用户可见的数据。
Secured.mdJSR-250 兼容注解:@Secured("ROLE_ADMIN"),Spring Security 的简化安全注解。

知识图谱

核心逻辑:Spring Security 的授权体系是"纵深防御":URL 级在过滤器链最外层拦截粗粒度请求(如 /admin/**);方法级在 AOP 层拦截业务方法调用(如 deleteOrder);实例级通过 SpEL 表达式对返回数据做行级过滤(如"只能看自己的订单")。AccessDecisionManager 汇总 Voter 投票结果,GrantedAuthority 承载权限信息,RoleHierarchy 简化角色配置。五大注解(PreAuthorize/PostAuthorize/PreFilter/PostFilter/Secured)提供声明式的方法级控制。

与上下章的衔接

上一章回顾:你已经掌握了认证流程——从用户提交凭据到 SecurityContext 存储的完整链路。认证解决"你是谁",授权解决"你能做什么",两者是 Spring Security 的两大支柱。

下一章预告:本章的 URL 级授权和方法级授权都依赖于过滤器链的执行。下一章「过滤器链与核心机制」将逐一拆解构成安全过滤器链的12+个过滤器,看清每个过滤器的职责、顺序和协作关系。

下一页
授权模型