没有配置entry-point-ref
<http use-expressions="true" entry-point-ref="authenticationProcessingFilterEntryPoint">
<!-- 登出配置 -->
<logout logout-url="/logout" logout-success-url="/login" />
<access-denied-handler error-page="/accessDenied" />
<!-- 过滤不被拦截的请求 -->
<intercept-url pattern="/login*" access="permitAll" />
<intercept-url pattern="/resources/**" access="permitAll" />
<!-- 只有权限才能访问的请求 -->
<intercept-url pattern="/admin/**" access="isAuthenticated()" />
</http>
不过我还真没用过xml来配置security,可以继承WebSecurityConfigurerAdapter来试一下,感觉比xml配置好
@Configuration
@EnableWebSecurity
public class SecurityConfiguration extends WebSecurityConfigurerAdapter