You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 3.1.12升级后antMatcher()等方法适配问题求助

修复方案详解

修改后的完整可运行代码

import org.springframework.beans.factory.annotation.Value;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.authorization.AuthorizationManagers;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configurers.AbstractHttpConfigurer;
import org.springframework.security.core.Authentication;
import org.springframework.security.oauth2.jwt.Jwt;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
public class ResourceServerConfig {

    @Bean
    SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
                .csrf(AbstractHttpConfigurer::disable)
                // 移除原antMatcher,改用authorizeHttpRequests统一配置授权规则
                .authorizeHttpRequests(auth -> auth
                        .requestMatchers("/**/actuator/health").permitAll()
                        .anyRequest()
                        // 用AuthorizationManagers包装SpEL表达式替代原access字符串参数
                        .access(AuthorizationManagers.expression("@webSecurityAccess.hasAccess(authentication)"))
                )
                .oauth2ResourceServer(oauth2 -> oauth2
                        // JWT配置位置不变,可在lambda内添加自定义逻辑
                        .jwt(jwt -> {})
                );
        return http.build();
    }

    @Bean
    WebSecurityAccess webSecurityAccess() {
        return new WebSecurityAccess();
    }

    public static class WebSecurityAccess {

        @Value("${om.test.app.client-id}")
        private String omTestAppClientId;

        public boolean hasAccess(Authentication authentication) {
            return authentication.isAuthenticated() && authentication.getPrincipal() instanceof Jwt
                    && omTestAppClientId.equals(((Jwt) authentication.getPrincipal()).getClaims().get("clientId"));
        }
    }

}

核心修改点说明

1. 移除antMatcher()方法

Spring Security 6+(对应Spring Boot 3)已删除antMatcher(),无需单独配置全局请求匹配:

  • 原.antMatcher("/**")可直接删除,authorizeHttpRequests()默认覆盖所有请求
  • 如需针对特定路径配置规则,直接在authorizeHttpRequests()的lambda内用requestMatchers()定义即可

2. 替换access()字符串参数

原SpEL表达式写法的access()在Spring Security 6中需通过AuthorizationManagers.expression()包装:

  • 导入org.springframework.security.authorization.AuthorizationManagers类
  • 将原access("@webSecurityAccess.hasAccess(authentication)")改为:
    .access(AuthorizationManagers.expression("@webSecurityAccess.hasAccess(authentication)"))
    
  • 原WebSecurityAccess类无需修改,仍可通过SpEL引用bean方法实现自定义授权逻辑

3. OAuth2资源服务器与JWT配置

oauth2ResourceServer()和jwt()的配置逻辑不变,仅调整为lambda链式写法:

  • 原.oauth2ResourceServer().jwt()改为lambda形式,如需自定义JWT解析(比如转换Authentication对象),可在jwt()的lambda内添加配置

4. 替代WebSecurityCustomizer

原WebSecurityCustomizer用于忽略actuator/health路径,更推荐通过authorizeHttpRequests()直接配置放行:

.authorizeHttpRequests(auth -> auth
        .requestMatchers("/**/actuator/health").permitAll()
        .anyRequest().access(...)
)

这种方式更符合当前Security的配置风格,便于统一管理所有授权规则。

关键版本变更提示

Spring Boot 3.x对应Spring Security 6.x,核心API变更包括:

  • authorizeRequests() → authorizeHttpRequests()
  • 移除antMatcher(),统一通过requestMatchers()配置路径
  • access()不再接受字符串参数,需通过AuthorizationManagers工具类创建授权规则

内容的提问来源于stack exchange,提问作者ilhan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 15:06:17