1.URL过滤:

<http><intercept-urlpattern="/**"access="hasRole('USER')"/><form-login/><logout/></http>

2.添加用户:

<authentication-manager><authentication-provider><user-service><username="jimi"password="jimispassword"authorities="ROLE_USER,ROLE_ADMIN"/><username="bob"password="bobspassword"authorities="ROLE_USER"/></user-service></authentication-provider></authentication-manager>


Spring Security xml:

<!--<http/>--><http><intercept-urlpattern="/**"access="hasRole('ADMIN')"/><form-login/><logout/></http><!--<user-service>--><!--<username="user"password="password"authorities="ROLE_USER"/>--><!--</user-service>--><authentication-manager><authentication-provider><user-service><username="user"password="password"authorities="ROLE_USER,ROLE_ADMIN"/><username="bob"password="bobspassword"authorities="ROLE_USER"/></user-service></authentication-provider></authentication-manager>