Search code examples

How to secure Struts actions with Spring single-sign-on

Currently I am using Struts 2 framework in my web application, now I have integrated single-sign-on with the help of Spring SAML extension and ADFS server, now every thing is working fine except Struts 2 actions,

when I am going to call/hit any Struts action like URL then Spring SSO never ask for authentication.

But when I hit any .jsp OR .js OR .css OR .html file

Ex. file in application it will prompt for authentication.

Screenshot image

Any ideas how to secure Struts actions with Spring single-sign-on, so that anybody can't access action URL directly without any authentication ?


  • Finally i got the solution, I have both Spring and Struts filter in my web.xml , I just changed filter order as below and its working for me.
