You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Gateway MVC路由转发失败及鉴权相关技术咨询

Spring Gateway MVC 问题解答

一、/api/** 转发404问题排查

可能的遗漏点

  1. 后端接口路径不匹配
    你的配置中StripPrefix=1会移除请求的/api前缀,比如访问http://localhost:8088/api/test会被转发到http://localhost:8090/test。如果后端实际接口路径是/api/test,必然返回404,请确认后端接口是否不带/api前缀。

  2. 网关端口配置错误
    检查网关的server.port是否确实设置为8088,若未配置则默认是8080,此时访问8088会因网关未监听该端口导致请求无法处理。

  3. 路由匹配优先级问题
    若存在其他路由规则且优先级高于当前backend路由,会导致请求未匹配到这条转发规则。Spring Gateway MVC中路由按配置顺序匹配,先配置的优先级更高,可调整路由顺序或明确指定优先级解决。

调试方法

  • 开启调试日志
    在application.yaml中添加日志配置,查看请求的路由匹配、转发详情:

    logging:
      level:
        org.springframework.cloud.gateway: DEBUG
        org.springframework.web.servlet.mvc.method.annotation: DEBUG
    

    日志会显示请求匹配的路由ID、转发后的URL、请求头信息,可直接定位转发是否正确。

  • 直接验证后端接口
    用Postman或curl直接访问http://localhost:8090/{endpoint},确认后端接口本身能正常返回200,排除后端自身问题。

  • 简化配置测试
    先去掉Method断言和StripPrefix过滤器,仅保留Path=/api/**和uri配置,测试是否能转发成功,逐步排查具体配置项问题。

二、网关作为统一鉴权入口的可行性

完全可行。Spring Gateway MVC结合Spring Security可实现:

  • 所有请求先经过网关鉴权逻辑,验证通过后再转发至后端API;
  • 鉴权失败时直接返回自定义错误(如401 Unauthorized、403 Forbidden),无需转发到后端。

三、传递JWT实现后端MethodSecurity & 避免自动跳转登录页

实现步骤

  1. 配置Spring Security禁用默认登录跳转
    自定义SecurityFilterChain,关闭表单登录和HTTP Basic认证,替换默认认证失败处理逻辑,返回JSON错误:

    @Configuration
    public class SecurityConfig {
        @Bean
        public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
            http
                .csrf(csrf -> csrf.disable())
                .authorizeHttpRequests(auth -> auth
                    .requestMatchers("/api/**").authenticated()
                    .anyRequest().permitAll()
                )
                .formLogin(form -> form.disable())
                .httpBasic(basic -> basic.disable())
                .exceptionHandling(ex -> ex
                    .authenticationEntryPoint((request, response, authException) -> {
                        response.setStatus(HttpStatus.UNAUTHORIZED.value());
                        response.setContentType(MediaType.APPLICATION_JSON_VALUE);
                        response.getWriter().write("{\"code\":401,\"msg\":\"未授权\"}");
                    })
                );
            return http.build();
        }
    }
    
  2. 添加JWT认证过滤器
    自定义过滤器从请求头(如Authorization: Bearer {token})提取JWT,验证令牌有效性、过期时间、签名等,验证通过后将认证信息存入SecurityContext:

    @Component
    public class JwtAuthenticationFilter extends OncePerRequestFilter {
        @Override
        protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain filterChain) throws ServletException, IOException {
            String authHeader = request.getHeader("Authorization");
            if (authHeader != null && authHeader.startsWith("Bearer ")) {
                String token = authHeader.substring(7);
                // 实现JWT验证逻辑,解析令牌获取用户信息、权限
                // 示例:验证通过后创建Authentication对象
                UsernamePasswordAuthenticationToken authentication = 
                    new UsernamePasswordAuthenticationToken("username", null, Collections.emptyList());
                SecurityContextHolder.getContext().setAuthentication(authentication);
            }
            filterChain.doFilter(request, response);
        }
    }
    

    将过滤器添加到SecurityFilterChain中:

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http, JwtAuthenticationFilter jwtFilter) throws Exception {
        http
            // 其他配置
            .addFilterBefore(jwtFilter, UsernamePasswordAuthenticationFilter.class);
        return http.build();
    }
    
  3. 传递JWT到后端
    Spring Gateway MVC默认会转发请求头,只要网关请求包含Authorization头,转发到后端时该头会被保留。后端可通过@RequestHeader("Authorization")获取令牌,或配置Spring Security的JWT认证自动解析令牌,结合@PreAuthorize等注解实现MethodSecurity。

注意事项

  • 确保网关和后端使用相同的JWT密钥、解析规则,避免令牌在后端无法验证;
  • 若需修改请求头,可在网关过滤器中添加或调整请求头,比如传递自定义用户信息头到后端。

内容的提问来源于stack exchange,提问作者learningProgrammer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 10:25:17