2014-10-29 53 views
1

我试图用本地会话使用Grails:四郎抛出一个异常/无效

[main] 
sessionManager = org.apache.shiro.session.mgt.DefaultSessionManager 
securityManager.sessionManager = \$sessionManager 

直到会话找不到或无效它的伟大工程。

  1. 启动服务器。登录
  2. 重新启动服务器。

    org.apache.shiro.session.ExpiredSessionException: Session with id [3c3ffbef-ee93-4f6e-a599-1f1f4c03d037] has expired. Last access time: 29.10.14 12:18. Current time: 29.10.14 12:18. Session timeout is set to 1 seconds (0 minutes) 
         at org.apache.shiro.session.mgt.SimpleSession.validate(SimpleSession.java:292) 
         at org.apache.shiro.session.mgt.AbstractValidatingSessionManager.doValidate(AbstractValidatingSessionManager.java:186) 
         at org.apache.shiro.session.mgt.AbstractValidatingSessionManager.validate(AbstractValidatingSessionManager.java:143) 
         at org.apache.shiro.session.mgt.AbstractValidatingSessionManager.doGetSession(AbstractValidatingSessionManager.java:120) 
         at org.apache.shiro.session.mgt.AbstractNativeSessionManager.lookupSession(AbstractNativeSessionManager.java:108) 
         at org.apache.shiro.session.mgt.AbstractNativeSessionManager.lookupRequiredSession(AbstractNativeSessionManager.java:112) 
         at org.apache.shiro.session.mgt.AbstractNativeSessionManager.getAttribute(AbstractNativeSessionManager.java:209) 
         at org.apache.shiro.session.mgt.DelegatingSession.getAttribute(DelegatingSession.java:141) 
         at org.apache.shiro.session.ProxiedSession.getAttribute(ProxiedSession.java:121) 
         at org.apache.shiro.subject.support.DelegatingSubject.getRunAsPrincipalsStack(DelegatingSubject.java:469) 
         at org.apache.shiro.subject.support.DelegatingSubject.getPrincipals(DelegatingSubject.java:153) 
         at org.apache.shiro.subject.support.DelegatingSubject.getPrincipal(DelegatingSubject.java:149) 
         at org.apache.shiro.web.servlet.ShiroHttpServletRequest.getSubjectPrincipal(ShiroHttpServletRequest.java:95) 
         at org.apache.shiro.web.servlet.ShiroHttpServletRequest.getUserPrincipal(ShiroHttpServletRequest.java:111) 
    

有什么意义?为什么Shiro会抛出异常而不是静默处理它?它使得shiro会话无法使用。

这很有趣,甚至注销不起作用:
1. ShiroHttpServletRequest记得校长会议
2. SecurityUtils.subject?.logout()无效校长会议
3.在处理响应存取东西会议(request.getSession(false)),它返回无效的会话=>org.apache.shiro.session.UnknownSessionException

There is no session with id [86f8b1dc-0c16-4836-9564-c8cc3cc1c03a]. Stacktrace follows: 
java.lang.IllegalStateException: org.apache.shiro.session.UnknownSessionException: There is no session with id [86f8b1dc-0c16-4836-9564-c8cc3cc1c03a] 
    at org.apache.shiro.web.servlet.ShiroHttpSession.getAttribute(ShiroHttpSession.java:133) 
    at grails.plugin.cache.web.filter.PageFragmentCachingFilter.doFilter(PageFragmentCachingFilter.java:195) 
    at grails.plugin.cache.web.filter.AbstractFilter.doFilter(AbstractFilter.java:63) 
    at org.apache.shiro.web.servlet.AbstractShiroFilter.executeChain(AbstractShiroFilter.java:449) 
    at org.apache.shiro.web.servlet.AbstractShiroFilter$1.call(AbstractShiroFilter.java:365) 

什么是使用本机Shiro会话的正确方法?

回答

0

看起来您正在使用非Web会话管理器。这不会利用httpsession的东西,你真的想在像grails这样的servlet环境中使用,因为Web服务器可以帮助你使会话无效或在重新部署时恢复它们。

使用DefaultWebSessionManager代替:

[main] 
sessionManager = org.apache.shiro.web.session.mgt.DefaultWebSessionManager 

它扩展DefaultSessionManager,所以任何你想用,这样做,你可以与网络会话管理器做的。