意外错误转发或重定向到登录页面

时间:2013-05-07 10:23:13

标签: jsf error-handling facelets j-security-check viewexpiredexception

我在GlassFish 3.1.2.2上运行了一个JSF应用程序,使用Mojarra 2.1.21和OmniFaces 1.4.1来处理Ajax错误。该应用程序具有受保护和公共区域,使用基于表单的身份验证(在JSF表单上)和程序化登录。

当用户点击受保护页面上的commandButton时,我总是会看到一个空白页面,该页面由于基础 ServletException导致过期:意外错误转发或重定向到登录页面。

纠正我,如果我错了,但是从日志中,它似乎是由于Web容器转发到login.xhtml但仍然试图恢复旧视图 - 最终导致它包装到ServletException中的ViewExpiredException,因此,无法匹配和显示web.xml中定义的错误页面。这是例外:

    [#|2013-05-07T16:51:12.175+0800|WARNING|glassfish3.1.2|javax.enterprise.system.container.web.com.sun.enterprise.web|_ThreadID=105;_ThreadName=Thread-2;|ApplicationDispatcher[] PWC1231: Servlet.service() for servlet Faces Servlet threw exception
javax.faces.application.ViewExpiredException: viewId:/login.xhtml - View /login.xhtml could not be restored.
    at com.sun.faces.lifecycle.RestoreViewPhase.execute(RestoreViewPhase.java:205)
    at com.sun.faces.lifecycle.Phase.doPhase(Phase.java:101)
    at com.sun.faces.lifecycle.RestoreViewPhase.doPhase(RestoreViewPhase.java:116)
    at com.sun.faces.lifecycle.LifecycleImpl.execute(LifecycleImpl.java:118)
    at javax.faces.webapp.FacesServlet.service(FacesServlet.java:593)
    at org.apache.catalina.core.StandardWrapper.service(StandardWrapper.java:1550)
    at org.apache.catalina.core.ApplicationDispatcher.doInvoke(ApplicationDispatcher.java:809)
    ...
|#]

[#|2013-05-07T16:51:12.176+0800|WARNING|glassfish3.1.2|org.apache.catalina.authenticator.FormAuthenticator|_ThreadID=105;_ThreadName=Thread-2;|Unexpected error forwarding or redirecting to login page
javax.servlet.ServletException: viewId:/login.xhtml - View /login.xhtml could not be restored.
    at javax.faces.webapp.FacesServlet.service(FacesServlet.java:606)
    at org.apache.catalina.core.StandardWrapper.service(StandardWrapper.java:1550)
    at org.apache.catalina.core.ApplicationDispatcher.doInvoke(ApplicationDispatcher.java:809)
    at org.apache.catalina.core.ApplicationDispatcher.invoke(ApplicationDispatcher.java:671)
    ...
Caused by: javax.faces.application.ViewExpiredException: viewId:/login.xhtml - View /login.xhtml could not be restored.
    at com.sun.faces.lifecycle.RestoreViewPhase.execute(RestoreViewPhase.java:205)
    at com.sun.faces.lifecycle.Phase.doPhase(Phase.java:101)
    at com.sun.faces.lifecycle.RestoreViewPhase.doPhase(RestoreViewPhase.java:116)
    at com.sun.faces.lifecycle.LifecycleImpl.execute(LifecycleImpl.java:118)
    at javax.faces.webapp.FacesServlet.service(FacesServlet.java:593)
    ... 32 more
|#]

我已经尝试了几个小时来抓住它的方法无济于事:

  • faces-redirect=true添加到登录页面配置无效,因为它不是结果
 <form-login-config>
        <form-login-page>/login.xhtml?faces-redirect=true</form-login-page>
        <form-error-page>/login.xhtml?faces-redirect=true</form-error-page>
    </form-login-config>
  • 添加servlet过滤器以捕获rootCause不起作用,因为容器管理的安全性在过滤器之前启动,如另一篇文章所述
@Override
public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws ServletException, IOException {
    try {
        chain.doFilter(request, response);
    } catch (ServletException e) {
        Throwable rootCause = e.getRootCause();
        if (rootCause instanceof ViewExpiredException) { // This is true for any FacesException.
            throw (ViewExpiredException) rootCause; // Throw wrapped ViewExpiredException instead of ServletException.
        } else if (rootCause instanceof RuntimeException) { // This is true for any FacesException.
            throw (RuntimeException) rootCause; // Throw wrapped RuntimeException instead of ServletException.
        } else {
            throw e;
        }
    }
}
  • 使login.xhtml无状态(通过<f:view transient = "true">)没有帮助,因为它是Faces Servlet尝试恢复的过期页面的视图。

从StackOverflow上的众多帖子中我知道有几个选项:

  • 使登录页面成为非JSF页面,但我真的想要一些 登录页面上的动态数据
  • 使用自定义错误处理程序 工作,但它覆盖了OmniFaces的FullAjaxException处理程序,没有 更长时间尊重web.xml中的错误页面声明

我想知道的是,有没有其他方法可以优雅地处理此异常?允许转发到登录页面或显示错误页面。 (非Ajax相当于FullAjaxExceptionHandler将是完美的!)

非常感谢提前。

我的web.xml:

> <?xml version="1.0" encoding="UTF-8"?>
<web-app version="3.0" xmlns="http://java.sun.com/xml/ns/javaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_3_0.xsd">
    <context-param>
        <param-name>javax.faces.PROJECT_STAGE</param-name>
        <param-value>Development</param-value>
    </context-param>
    <context-param>
        <param-name>javax.faces.INTERPRET_EMPTY_STRING_SUBMITTED_VALUES_AS_NULL</param-name>
        <param-value>true</param-value>
    </context-param>
    <!-- See annotation declared servlets, converters, and filters in faces and servlet folders -->
    <servlet>
        <servlet-name>Faces Servlet</servlet-name>
        <servlet-class>javax.faces.webapp.FacesServlet</servlet-class>
        <load-on-startup>1</load-on-startup>
    </servlet>
    <servlet-mapping>
        <servlet-name>Faces Servlet</servlet-name>
        <url-pattern>*.xhtml</url-pattern>
    </servlet-mapping>
    <servlet>
        <servlet-name>javax.ws.rs.core.Application</servlet-name>
        <load-on-startup>2</load-on-startup>
    </servlet>
    <servlet-mapping>
        <servlet-name>javax.ws.rs.core.Application</servlet-name>
        <url-pattern>/rest/*</url-pattern>
    </servlet-mapping>
    <session-config>
        <session-timeout>
            1
        </session-timeout>
    </session-config>
    <welcome-file-list>
        <welcome-file>index.xhtml</welcome-file>
    </welcome-file-list>
    <error-page>
        <exception-type>javax.faces.application.ViewExpiredException</exception-type>
        <location>/WEB-INF/errorpages/expired.xhtml</location>
    </error-page>
    <error-page>
        <exception-type>java.lang.RuntimeException</exception-type>
        <location>/WEB-INF/errorpages/error.xhtml</location>
    </error-page>
    <error-page>
        <error-code>500</error-code>
        <location>/WEB-INF/errorpages/error.xhtml</location>
    </error-page>
    <error-page>
        <error-code>404</error-code>
        <location>/WEB-INF/errorpages/404.xhtml</location>
    </error-page>
    <!-- SECURITY -->
    <security-constraint>
        <display-name>AdminPagesConstraint</display-name>
        <web-resource-collection>
            <web-resource-name>AdminResource</web-resource-name>
            <description/>
            <url-pattern>/admin/*</url-pattern>
        </web-resource-collection>
        <auth-constraint>
            <description/>
            <role-name>ADMIN</role-name>
        </auth-constraint>
    </security-constraint>
    <security-constraint>
        <display-name>CustomerPagesConstraint</display-name>
        <web-resource-collection>
            <web-resource-name>CustomerResource</web-resource-name>
            <description/>
            <url-pattern>/customer/*</url-pattern>
        </web-resource-collection>
        <auth-constraint>
            <description/>
            <role-name>CUSTOMER</role-name>
        </auth-constraint>
    </security-constraint>
    <login-config>
        <auth-method>FORM</auth-method>
        <realm-name>App_Realm</realm-name>
        <form-login-config>
            <form-login-page>/login.xhtml</form-login-page>
            <form-error-page>/login.xhtml</form-error-page><!-- no use for programmatic login -->
        </form-login-config>
    </login-config>
    <security-role>
        <description/>
        <role-name>CUSTOMER</role-name>
    </security-role>
    <security-role>
        <description/>
        <role-name>ADMIN</role-name>
    </security-role>
</web-app>

1 个答案:

答案 0 :(得分:0)

在web.xml中包含以下代码段。它对我有用

<error-page>
    <exception-type>javax.faces.application.ViewExpiredException</exception-type>
    <location>/login.xhtml?faces-redirect=true</location>
</error-page>

但要注释

<error-page>
    <error-code>500</error-code>
    <location>/WEB-INF/errorpages/error.xhtml</location>
</error-page>