http://hi.baidu.com/jogcy/blog/item/2a5a34cc077ee01d00e92858.html
<security:http auto-config="false" access-denied-page="/access_denied.jsp" entry-point-ref="authenticationProcessingFilterEntryPoint">
...
</security:http>
<security:authentication-manager alias="authenticationManager"/>
<bean id="customizedFormLoginFilter" class="org.springframework.security.ui.webapp.Authenticat ionProcessingFilter">
<security:custom-filter position="AUTHENTICATION_PROCESSING_FILTER "/>
<property name="authenticationManager" ref="authenticationManager"/>
<property name="alwaysUseDefaultTargetUrl" value="false" />
<property name="defaultTargetUrl" value="/" />
<property name="authenticationFailureUrl" value="/login.jsp?login_error=1" />
</bean>
<bean id="authenticationProcessingFilterEntryPoint" class="org.springframework.security.ui.webapp.Authenticat ionProcessingFilterEntryPoint">
<property name="loginFormUrl" value="/login.jsp" />
<property name="forceHttps" value="false" />
</bean>