diff --git a/config/src/main/java/org/springframework/security/config/annotation/web/AbstractRequestMatcherRegistry.java b/config/src/main/java/org/springframework/security/config/annotation/web/AbstractRequestMatcherRegistry.java index d93ec3f7bd0..5c1dd6118f0 100644 --- a/config/src/main/java/org/springframework/security/config/annotation/web/AbstractRequestMatcherRegistry.java +++ b/config/src/main/java/org/springframework/security/config/annotation/web/AbstractRequestMatcherRegistry.java @@ -18,6 +18,8 @@ import java.util.ArrayList; import java.util.Arrays; +import java.util.Collection; +import java.util.LinkedHashMap; import java.util.List; import java.util.Map; @@ -194,18 +196,31 @@ public C requestMatchers(HttpMethod method, String... patterns) { if (servletContext == null) { return requestMatchers(RequestMatchers.antMatchersAsArray(method, patterns)); } - Map registrations = servletContext.getServletRegistrations(); - if (registrations == null) { + Map registrations = mappableServletRegistrations(servletContext); + if (registrations.isEmpty()) { return requestMatchers(RequestMatchers.antMatchersAsArray(method, patterns)); } if (!hasDispatcherServlet(registrations)) { return requestMatchers(RequestMatchers.antMatchersAsArray(method, patterns)); } - Assert.isTrue(registrations.size() == 1, - "This method cannot decide whether these patterns are Spring MVC patterns or not. If this endpoint is a Spring MVC endpoint, please use requestMatchers(MvcRequestMatcher); otherwise, please use requestMatchers(AntPathRequestMatcher)."); + if (registrations.size() > 1) { + String errorMessage = computeErrorMessage(registrations.values()); + throw new IllegalArgumentException(errorMessage); + } return requestMatchers(createMvcMatchers(method, patterns).toArray(new RequestMatcher[0])); } + private Map mappableServletRegistrations(ServletContext servletContext) { + Map mappable = new LinkedHashMap<>(); + for (Map.Entry entry : servletContext.getServletRegistrations() + .entrySet()) { + if (!entry.getValue().getMappings().isEmpty()) { + mappable.put(entry.getKey(), entry.getValue()); + } + } + return mappable; + } + private boolean hasDispatcherServlet(Map registrations) { if (registrations == null) { return false; @@ -226,6 +241,19 @@ private boolean hasDispatcherServlet(Map return false; } + private String computeErrorMessage(Collection registrations) { + String template = "This method cannot decide whether these patterns are Spring MVC patterns or not. " + + "If this endpoint is a Spring MVC endpoint, please use requestMatchers(MvcRequestMatcher); " + + "otherwise, please use requestMatchers(AntPathRequestMatcher).\n\n" + + "This is because there is more than one mappable servlet in your servlet context: %s.\n\n" + + "For each MvcRequestMatcher, call MvcRequestMatcher#setServletPath to indicate the servlet path."; + Map> mappings = new LinkedHashMap<>(); + for (ServletRegistration registration : registrations) { + mappings.put(registration.getClassName(), registration.getMappings()); + } + return String.format(template, mappings); + } + /** *

* If the {@link HandlerMappingIntrospector} is available in the classpath, maps to an diff --git a/config/src/test/java/org/springframework/security/config/MockServletContext.java b/config/src/test/java/org/springframework/security/config/MockServletContext.java index bace54fff6a..67b7c396e74 100644 --- a/config/src/test/java/org/springframework/security/config/MockServletContext.java +++ b/config/src/test/java/org/springframework/security/config/MockServletContext.java @@ -16,8 +16,10 @@ package org.springframework.security.config; +import java.util.Arrays; import java.util.Collection; import java.util.LinkedHashMap; +import java.util.LinkedHashSet; import java.util.Map; import java.util.Set; @@ -35,7 +37,7 @@ public class MockServletContext extends org.springframework.mock.web.MockServlet public static MockServletContext mvc() { MockServletContext servletContext = new MockServletContext(); - servletContext.addServlet("dispatcherServlet", DispatcherServlet.class); + servletContext.addServlet("dispatcherServlet", DispatcherServlet.class).addMapping("/"); return servletContext; } @@ -59,6 +61,8 @@ private static class MockServletRegistration implements ServletRegistration.Dyna private final Class clazz; + private final Set mappings = new LinkedHashSet<>(); + MockServletRegistration(String name, Class clazz) { this.name = name; this.clazz = clazz; @@ -91,12 +95,13 @@ public void setAsyncSupported(boolean isAsyncSupported) { @Override public Set addMapping(String... urlPatterns) { - return null; + this.mappings.addAll(Arrays.asList(urlPatterns)); + return this.mappings; } @Override public Collection getMappings() { - return null; + return this.mappings; } @Override diff --git a/config/src/test/java/org/springframework/security/config/annotation/web/AbstractRequestMatcherRegistryTests.java b/config/src/test/java/org/springframework/security/config/annotation/web/AbstractRequestMatcherRegistryTests.java index 1a1aa1f3400..107b4694e78 100644 --- a/config/src/test/java/org/springframework/security/config/annotation/web/AbstractRequestMatcherRegistryTests.java +++ b/config/src/test/java/org/springframework/security/config/annotation/web/AbstractRequestMatcherRegistryTests.java @@ -174,12 +174,24 @@ public void requestMatchersWhenNoDispatcherServletThenAntPathRequestMatcherType( public void requestMatchersWhenAmbiguousServletsThenException() { MockServletContext servletContext = new MockServletContext(); given(this.context.getServletContext()).willReturn(servletContext); - servletContext.addServlet("dispatcherServlet", DispatcherServlet.class); - servletContext.addServlet("servletTwo", Servlet.class); + servletContext.addServlet("dispatcherServlet", DispatcherServlet.class).addMapping("/"); + servletContext.addServlet("servletTwo", Servlet.class).addMapping("/servlet/**"); assertThatExceptionOfType(IllegalArgumentException.class) .isThrownBy(() -> this.matcherRegistry.requestMatchers("/**")); } + @Test + public void requestMatchersWhenUnmappableServletsThenSkips() { + mockMvcIntrospector(true); + MockServletContext servletContext = new MockServletContext(); + given(this.context.getServletContext()).willReturn(servletContext); + servletContext.addServlet("dispatcherServlet", DispatcherServlet.class).addMapping("/"); + servletContext.addServlet("servletTwo", Servlet.class); + List requestMatchers = this.matcherRegistry.requestMatchers("/**"); + assertThat(requestMatchers).hasSize(1); + assertThat(requestMatchers.get(0)).isInstanceOf(MvcRequestMatcher.class); + } + private void mockMvcIntrospector(boolean isPresent) { ApplicationContext context = this.matcherRegistry.getApplicationContext(); given(context.containsBean("mvcHandlerMappingIntrospector")).willReturn(isPresent);