KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
This is a Spring Security question. In my application, I have a User entity as a domain object. Users will be registered and will be logging in with credentials stored in the database. My User domain object contains implementation to support Spring UserDetails object. The challenge is that I need an ability to log into the application even before the first user is created. In other words, I need to log in as 'admin' to create the 'admin' user. To make sure my Spring setup is working, I'm currently returning the hardcoded admin user from SpringSecurityUserDetailsServiceImpl.loadUserByUsername(String userName). public UserDetails loadUserByUsername(String userName) throws UsernameNotFoundException, DataAccessException { User user=null; try { if("admin".equalsIgnoreCase(userName)) { user=new User(); user.setUserName("ADMIN"); user.setPassword("adsf"); // assume there's a hash of a true password here user.setStatus(UserStatus.ACTIVE); user.setAccessLevel(UserAccessLevel.ADMINISTRATOR); } else { //user = userDAO.getUserByUserName(userName); } } catch(Throwable t) { throw new UsernameNotFoundException("Unable to locate User with user name \"" + userName + "\".", t); } return user; } This works, so now, I'm looking for the right way to do it. One would be to define this default admin user credentials in a properties file and read that properties file within loadUserByUsername(String userName) to construct the admn user object. However, I'm hoping there is a way to do this within the Spring Security xml configuration. I tried security:user name="admin" password="admin" authorities="ADMINISTRATOR" but that apparently does not work when you have security:authentication-provider user-service-ref="customUserDetailsService" My spring-security.xml <
Tags (comma-separated)
Save Edits
Cancel