我有我的拦截网址配置
<security:http use-expressions="true" disable-url-rewriting="true">
<security:intercept-url pattern="/secure/admission/*" access="hasRole('ROLE_ADMISSIONER')" />
<security:intercept-url pattern="/secure/subdean/*" access="hasRole('ROLE_SUBDEAN')" />
<security:intercept-url pattern="/secure/referent/*" access="hasRole('ROLE_REFERENT')" />
<security:intercept-url pattern="/secure/index.xhtml" access="hasRole('ROLE_REFERENT, ROLE_SUBDEAN')" />
<security:intercept-url pattern="/secure/*" access="hasRole('ROLE_OMNI_ADMIN')" />
<security:intercept-url pattern="/**" access="isAuthenticated()" />
但是现在我有一个问题,可以访问我的应用程序的 url,例如具有角色 ROLE_ADMISSIONER 的 MY_APPLICATION/PririzMaven/secure/admin/updateRole.xhtml,具有相同角色的 url ..../secure/subdean/* 和依此类推...但应该禁止该用户使用。
你知道哪里有问题吗?