赞
踩
因为接手的之前项目,项目shiro版本比较老,13个jar包都是1.4.0的:
最近护网行动期间项目被扫描有漏洞,所以要把shiro升级到1.9.1以上版本。于是我选了1.10.0,结果升级完后项目启动没问题,登录管理台报错:
- 2023-08-14 16:36:38.925 ERROR 500.jsp[148] - Filtered request failed.
- javax.servlet.ServletException: Filtered request failed.
- at org.apache.shiro.web.servlet.AbstractShiroFilter.doFilterInternal(AbstractShiroFilter.java:392) ~[shiro-web-1.10.0.jar:1.10.0]
- at org.apache.shiro.web.servlet.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:154) ~[shiro-web-1.10.0.jar:1.10.0]
- at org.springframework.web.filter.DelegatingFilterProxy.invokeDelegate(DelegatingFilterProxy.java:347) ~[spring-web-4.3.18.RELEASE.jar:4.3.18.RELEASE]
- at org.springframework.web.filter.DelegatingFilterProxy.doFilter(DelegatingFilterProxy.java:263) ~[spring-web-4.3.18.RELEASE.jar:4.3.18.RELEASE]
- at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:189) ~[catalina.jar:9.0.44]
- at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:162) ~[catalina.jar:9.0.44]
- at org.springframework.web.filter.CharacterEncodingFilter.doFilterInternal(CharacterEncodingFilter.java:197) ~[spring-web-4.3.18.RELEASE.jar:4.3.18.RELEASE]
- at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107) ~[spring-web-4.3.18.RELEASE.jar:4.3.18.RELEASE]
- at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:189) ~[catalina.jar:9.0.44]
- at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:162) ~[catalina.jar:9.0.44]
- at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:202) ~[catalina.jar:9.0.44]
- at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:97) ~[catalina.jar:9.0.44]
- at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:542) ~[catalina.jar:9.0.44]
- at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:143) ~[catalina.jar:9.0.44]
- at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:92) [catalina.jar:9.0.44]
- at org.apache.catalina.valves.AbstractAccessLogValve.invoke(AbstractAccessLogValve.java:687) [catalina.jar:9.0.44]
- at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:78) [catalina.jar:9.0.44]
- at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:357) [catalina.jar:9.0.44]
- at org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:374) [tomcat-coyote.jar:9.0.44]
- at org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:65) [tomcat-coyote.jar:9.0.44]
- at org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:893) [tomcat-coyote.jar:9.0.44]
- at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1707) [tomcat-coyote.jar:9.0.44]
- at org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49) [tomcat-coyote.jar:9.0.44]
- at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) [na:1.8.0_231]
- at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) [na:1.8.0_231]
- at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61) [tomcat-util.jar:9.0.44]
- at java.lang.Thread.run(Thread.java:748) [na:1.8.0_231]
- Caused by: java.lang.NoClassDefFoundError: org/owasp/encoder/Encode
- at org.apache.shiro.web.servlet.SimpleCookie.readValue(SimpleCookie.java:447) ~[shiro-web-1.10.0.jar:1.10.0]
- at org.apache.shiro.web.session.mgt.DefaultWebSessionManager.getSessionIdCookieValue(DefaultWebSessionManager.java:118) ~[shiro-web-1.10.0.jar:1.10.0]
- at org.apache.shiro.web.session.mgt.DefaultWebSessionManager.getReferencedSessionId(DefaultWebSessionManager.java:123) ~[shiro-web-1.10.0.jar:1.10.0]
- at org.apache.shiro.web.session.mgt.DefaultWebSessionManager.getSessionId(DefaultWebSessionManager.java:283) ~[shiro-web-1.10.0.jar:1.10.0]
- at com.ofsp.common.security.shiro.session.SessionManager.getSessionId(SessionManager.java:59) ~[ofsp-model-1.2.jar:na]
- at org.apache.shiro.web.session.mgt.DefaultWebSessionManager.getSessionId(DefaultWebSessionManager.java:277) ~[shiro-web-1.10.0.jar:1.10.0]
- at org.apache.shiro.session.mgt.DefaultSessionManager.retrieveSession(DefaultSessionManager.java:216) ~[shiro-core-1.10.0.jar:1.10.0]
- at com.ofsp.common.security.shiro.session.SessionManager.retrieveSession(SessionManager.java:70) ~[ofsp-model-1.2.jar:na]
- at org.apache.shiro.session.mgt.AbstractValidatingSessionManager.doGetSession(AbstractValidatingSessionManager.java:118) ~[shiro-core-1.10.0.jar:1.10.0]
- at org.apache.shiro.session.mgt.AbstractNativeSessionManager.lookupSession(AbstractNativeSessionManager.java:148) ~[shiro-core-1.10.0.jar:1.10.0]
- at org.apache.shiro.session.mgt.AbstractNativeSessionManager.getSession(AbstractNativeSessionManager.java:140) ~[shiro-core-1.10.0.jar:1.10.0]
- at org.apache.shiro.mgt.SessionsSecurityManager.getSession(SessionsSecurityManager.java:159) ~[shiro-core-1.10.0.jar:1.10.0]
- at org.apache.shiro.mgt.DefaultSecurityManager.resolveContextSession(DefaultSecurityManager.java:461) ~[shiro-core-1.10.0.jar:1.10.0]
- at org.apache.shiro.mgt.DefaultSecurityManager.resolveSession(DefaultSecurityManager.java:447) ~[shiro-core-1.10.0.jar:1.10.0]
- at org.apache.shiro.mgt.DefaultSecurityManager.createSubject(DefaultSecurityManager.java:343) ~[shiro-core-1.10.0.jar:1.10.0]
- at org.apache.shiro.subject.Subject$Builder.buildSubject(Subject.java:845) ~[shiro-core-1.10.0.jar:1.10.0]
- at org.apache.shiro.web.subject.WebSubject$Builder.buildWebSubject(WebSubject.java:148) ~[shiro-web-1.10.0.jar:1.10.0]
- at org.apache.shiro.web.servlet.AbstractShiroFilter.createSubject(AbstractShiroFilter.java:300) ~[shiro-web-1.10.0.jar:1.10.0]
- at org.apache.shiro.web.servlet.AbstractShiroFilter.doFilterInternal(AbstractShiroFilter.java:367) ~[shiro-web-1.10.0.jar:1.10.0]
- ... 26 common frames omitted
分析了一下少了一个encode的jar包,下载encode1.2.3后解决了该问题
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。