微信公众号搜"智元新知"关注
微信扫一扫可直接关注哦!

spring – 使用mockmvc和junit添加csrf标记

我有两个Metas的视图(我使用的是thymeleaf):

    <Meta name="_csrf" th:content="${_csrf.token}" />
    <Meta name="_csrf_header" th:content="${_csrf.headerName}" />

在我的测试控制器中,我这样做:

HttpSessionCsrftokenRepository httpSessionCsrftokenRepository = new HttpSessionCsrftokenRepository();
Csrftoken csrftoken2 = httpSessionCsrftokenRepository.generatetoken(new MockHttpServletRequest());

CustomUser user = new CustomUser();
user.setName("foo");
user.setSurname("fooo");
ListecurityContextRepository.SPRING_Security_CONTEXT_KEY,new MockSecurityContext(token));
session.setAttribute("_csrf",csrftoken2);


this.mockmvc.perform(post("/foo/update")
            .param("param","asdfasd")
            ....
            .session(session)
            )
        .andExpect(view().name(("foo/detail"))).andExpect(model().hasErrors())  

当我运行测试时,我收到此错误(未找到令牌或为空):

org.springframework.web.util.nestedservletexception: Request
processing Failed; nested exception is
org.thymeleaf.exceptions.TemplateProcessingException: Exception
evaluating SpringEL expression: “_csrf.token” (layout/default:4) at
org.springframework.web.servlet.FrameworkServlet.processRequest(FrameworkServlet.java:979)
at
org.springframework.web.servlet.FrameworkServlet.doPost(FrameworkServlet.java:869)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:707) at
org.springframework.web.servlet.FrameworkServlet.service(FrameworkServlet.java:843)
at
org.springframework.test.web.servlet.TestdispatcherServlet.service(TestdispatcherServlet.java:65)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:790) at
org.springframework.mock.web.MockFilterChain$ServletFilterProxy.doFilter(MockFilterChain.java:167)
at
org.springframework.mock.web.MockFilterChain.doFilter(MockFilterChain.java:134)
at
org.springframework.test.web.servlet.mockmvc.perform(mockmvc.java:144)
at
es.xunta.amtega.axipro.web.controller.solicitudeControllerSaveTest.testSaveValidator(SolicitudeControllerSaveTest.java:144)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) at
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
at
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
at java.lang.reflect.Method.invoke(Method.java:601) at
org.junit.runners.model.FrameworkMethod$1.runReflectiveCall(FrameworkMethod.java:50)
at
org.junit.internal.runners.model.ReflectiveCallable.run(ReflectiveCallable.java:12)
at
org.junit.runners.model.FrameworkMethod.invokeExplosively(FrameworkMethod.java:47)
at
org.junit.internal.runners.statements.InvokeMethod.evaluate(InvokeMethod.java:17)
at
org.junit.internal.runners.statements.RunBefores.evaluate(RunBefores.java:26)
at
org.springframework.test.context.junit4.statements.RunBeforeTestMethodCallbacks.evaluate(RunBeforeTestMethodCallbacks.java:75)
at
org.springframework.test.context.junit4.statements.RunAfterTestMethodCallbacks.evaluate(RunAfterTestMethodCallbacks.java:86)
at
org.springframework.test.context.junit4.statements.SpringRepeat.evaluate(SpringRepeat.java:70)
at org.junit.runners.ParentRunner.runLeaf(ParentRunner.java:325) at
org.springframework.test.context.junit4.SpringJUnit4ClassRunner.runchild(SpringJUnit4ClassRunner.java:224)
at
org.springframework.test.context.junit4.SpringJUnit4ClassRunner.runchild(SpringJUnit4ClassRunner.java:83)
at org.junit.runners.ParentRunner$3.run(ParentRunner.java:290) at
org.junit.runners.ParentRunner$1.schedule(ParentRunner.java:71) at
org.junit.runners.ParentRunner.runchildren(ParentRunner.java:288) at
org.junit.runners.ParentRunner.access$000(ParentRunner.java:58) at
org.junit.runners.ParentRunner$2.evaluate(ParentRunner.java:268) at
org.junit.internal.runners.statements.RunBefores.evaluate(RunBefores.java:26)
at
org.springframework.test.context.junit4.statements.RunBeforeTestClassCallbacks.evaluate(RunBeforeTestClassCallbacks.java:61)
at
org.springframework.test.context.junit4.statements.RunAfterTestClassCallbacks.evaluate(RunAfterTestClassCallbacks.java:70)
at org.junit.runners.ParentRunner.run(ParentRunner.java:363) at
org.springframework.test.context.junit4.SpringJUnit4ClassRunner.run(SpringJUnit4ClassRunner.java:163)
at
org.eclipse.jdt.internal.junit4.runner.JUnit4TestReference.run(JUnit4TestReference.java:50)
at
org.eclipse.jdt.internal.junit.runner.TestExecution.run(TestExecution.java:38)
at
org.eclipse.jdt.internal.junit.runner.RemoteTestRunner.runTests(RemoteTestRunner.java:459)
at
org.eclipse.jdt.internal.junit.runner.RemoteTestRunner.runTests(RemoteTestRunner.java:675)
at
org.eclipse.jdt.internal.junit.runner.RemoteTestRunner.run(RemoteTestRunner.java:382)
at
org.eclipse.jdt.internal.junit.runner.RemoteTestRunner.main(RemoteTestRunner.java:192)
Caused by: org.thymeleaf.exceptions.TemplateProcessingException:
Exception evaluating SpringEL expression: “_csrf.token”
(layout/default:4) at
org.thymeleaf.spring4.expression.SpelVariableExpressionEvaluator.evaluate(SpelVariableExpressionEvaluator.java:161)
at
org.thymeleaf.standard.expression.VariableExpression.executeVariable(VariableExpression.java:154)
at
org.thymeleaf.standard.expression.SimpleExpression.executeSimple(SimpleExpression.java:59)
at
org.thymeleaf.standard.expression.Expression.execute(Expression.java:103)
at
org.thymeleaf.standard.expression.Expression.execute(Expression.java:133)
at
org.thymeleaf.standard.expression.Expression.execute(Expression.java:120)
at
org.thymeleaf.standard.processor.attr.AbstractStandardSingleAttributeModifierAttrProcessor.getTargetAttributeValue(AbstractStandardSingleAttributeModifierAttrProcessor.java:67)
at
org.thymeleaf.processor.attr.AbstractSingleAttributeModifierAttrProcessor.getModifiedAttributeValues(AbstractSingleAttributeModifierAttrProcessor.java:59)
at
org.thymeleaf.processor.attr.AbstractAttributeModifierAttrProcessor.processAttribute(AbstractAttributeModifierAttrProcessor.java:62)
at
org.thymeleaf.processor.attr.AbstractAttrProcessor.doProcess(AbstractAttrProcessor.java:87)
at
org.thymeleaf.processor.AbstractProcessor.process(AbstractProcessor.java:212)
at org.thymeleaf.dom.Node.applyNextProcessor(Node.java:1017) at
org.thymeleaf.dom.Node.processNode(Node.java:972) at
org.thymeleaf.dom.nestableNode.computeNextChild(nestableNode.java:695)
at
org.thymeleaf.dom.nestableNode.doAdditionalProcess(nestableNode.java:668)
at org.thymeleaf.dom.Node.processNode(Node.java:990) at
org.thymeleaf.dom.nestableNode.computeNextChild(nestableNode.java:695)
at
org.thymeleaf.dom.nestableNode.doAdditionalProcess(nestableNode.java:668)
at org.thymeleaf.dom.Node.processNode(Node.java:990) at
org.thymeleaf.dom.nestableNode.computeNextChild(nestableNode.java:695)
at
org.thymeleaf.dom.nestableNode.doAdditionalProcess(nestableNode.java:668)
at org.thymeleaf.dom.Node.processNode(Node.java:990) at
org.thymeleaf.dom.Document.process(Document.java:93) at
org.thymeleaf.TemplateEngine.process(TemplateEngine.java:1155) at
org.thymeleaf.TemplateEngine.process(TemplateEngine.java:1060) at
org.thymeleaf.TemplateEngine.process(TemplateEngine.java:1011) at
org.thymeleaf.spring4.view.ThymeleafView.renderFragment(ThymeleafView.java:335)
at
org.thymeleaf.spring4.view.ThymeleafView.render(ThymeleafView.java:190)
at
org.springframework.web.servlet.dispatcherServlet.render(dispatcherServlet.java:1244)
at
org.springframework.test.web.servlet.TestdispatcherServlet.render(TestdispatcherServlet.java:105)
at
org.springframework.web.servlet.dispatcherServlet.processdispatchResult(dispatcherServlet.java:1027)
at
org.springframework.web.servlet.dispatcherServlet.dodispatch(dispatcherServlet.java:971)
at
org.springframework.web.servlet.dispatcherServlet.doService(dispatcherServlet.java:893)
at
org.springframework.web.servlet.FrameworkServlet.processRequest(FrameworkServlet.java:967)
… 40 more Caused by:
org.springframework.expression.spel.SpelEvaluationException:
EL1007E:(pos 0): Property or field ‘token’ cannot be found on null at
org.springframework.expression.spel.ast.PropertyOrFieldReference.readProperty(PropertyOrFieldReference.java:220)
at
org.springframework.expression.spel.ast.PropertyOrFieldReference.getValueInternal(PropertyOrFieldReference.java:94)
at
org.springframework.expression.spel.ast.PropertyOrFieldReference.access$000(PropertyOrFieldReference.java:46)
at
org.springframework.expression.spel.ast.PropertyOrFieldReference$AccessorLValue.getValue(PropertyOrFieldReference.java:374)
at
org.springframework.expression.spel.ast.CompoundExpression.getValueInternal(CompoundExpression.java:88)
at
org.springframework.expression.spel.ast.SpelNodeImpl.getValue(SpelNodeImpl.java:120)
at
org.springframework.expression.spel.standard.SpelExpression.getValue(SpelExpression.java:267)
at
org.thymeleaf.spring4.expression.SpelVariableExpressionEvaluator.evaluate(SpelVariableExpressionEvaluator.java:139)
… 73 more

我找到了一个时间解决方案,但它不是一个好的解决方案..:

Meta name="_csrf" th:content="${_csrf.token}" />
   <Meta name="_csrf_header" th:content="${_csrf.headerName}" />
最佳答案
要访问您需要的会话属性

th:text="${session._csrf.headerName}">
th:text="${session._csrf.token}">

spring thymeleaf

如果在测试中使用mockmvc,则可以设置csrf标记

mvc
.perform(post("/").with(csrf()))

web security

版权声明:本文内容由互联网用户自发贡献,该文观点与技术仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 [email protected] 举报,一经查实,本站将立刻删除。

相关推荐