第一步:
将开放所用到的jar文件导入到工程的lib文件夹
第二步:
在web.xml中配置Spring Security的拦截器
源码:
<filter>
<filter-name>springSecurityFilterChain</filter-name>
<filter-class>
org.springframework.web.filter.DelegatingFilterProxy
</filter-class>
</filter>
<filter-mapping>
<filter-name>springSecurityFilterChain</filter-name>
<url-pattern>/*</url-pattern>
</filter-mapping>
第三步:
手动配置用户信息:
修改Spring配置文件(applicationContext.xml):
1. 命名空间修改
<beans:beans xmlns="http://www.springframework.org/schema/security"
xmlns:beans="http://www.springframework.org/schema/beans"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://www.springframework.org/schema/beans
http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
    http://www.springframework.org/schema/security
http://www.springframework.org/schema/security/spring-security-3.0.xsd">. . . . . . 
. . . . . .
</beans:beans>
2. 配置不同角色的权限
<http auto-config="true">
<intercept-url pattern="/admin/**" access="ROLE_ADMIN" />
<intercept-url pattern="/article/**" access="ROLE_USER" />
</http>
3.手动设置用户名、密码、权限
<authentication-manager>
<authentication-provider>
<user-service>
<user name="admin" password="admin"
authorities="ROLE_USER,ROLE_ADMIN" />
<user name="user" password="user"
authorities="ROLE_USER" />
</user-service>
</authentication-provider>
</authentication-manager>