You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 3中Spring Security配置致Swagger失效求助

问题解决与Spring Boot 3相关变更说明

当前问题修复

你遇到的“Failed to load remote configuration”错误,核心原因是Swagger UI需要请求/v3/api-docs/swagger-config端点加载配置,但该端点未被加入Spring Security的公开访问列表,被拦截后导致配置加载失败。

修复后的Security配置调整

修改filterChain中的requestMatchers,添加/v3/api-docs/swagger-config端点:

@Autowired
private AuthFilter authFilter;

@Bean
@ConditionalOnProperty(name="auth.enabled", havingValue = "true")
public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception {
    return httpSecurity
            .csrf(AbstractHttpConfigurer::disable)
            .sessionManagement(hs -> hs.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
            .authorizeHttpRequests(auth-> auth.requestMatchers(
                    "/swagger/**",
                    "/swagger-ui/**",
                    "/v3/api-docs/**",
                    "/v3/api-docs/swagger-config", // 新增此端点
                    "/swagger-ui/index.html",
                    "/actuator/health"
                )
                .permitAll()
                .anyRequest()
                .authenticated()
            )
            .cors(co-> co.configurationSource(corsConfigurationSource()))
            .addFilterBefore(authFilter, UsernamePasswordAuthenticationFilter.class)
            .build();
}

@Bean
public UrlBasedCorsConfigurationSource corsConfigurationSource() {
    CorsConfiguration configuration = new CorsConfiguration();
    configuration.setAllowedOriginPatterns(List.of("*"));
    configuration.setAllowedMethods(List.of("GET", "PUT", "POST", "DELETE", "PATCH"));
    configuration.setAllowedHeaders(List.of("accept", "Authorization", "Content-Type"));
    configuration.setAllowCredentials(true);

    UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
    source.registerCorsConfiguration("/**", configuration);
    return source;
}

同时需确保Swagger依赖适配Spring Boot 3,Maven依赖应使用:

<dependency>
    <groupId>org.springdoc</groupId>
    <artifactId>springdoc-openapi-starter-webmvc-ui</artifactId>
    <version>2.2.0</version> <!-- 适配Spring Boot 3的版本 -->
</dependency>

Spring Boot 3相关核心变更

1. Swagger(Springdoc)依赖变更

Spring Boot 3基于Jakarta EE规范,旧版springdoc-openapi-ui依赖已不再兼容,必须替换为springdoc-openapi-starter-webmvc-ui(2.x及以上版本),否则会出现类加载异常或Swagger UI无法启动的问题。

2. Spring Security API调整

  • 废弃antMatchers方法,统一使用requestMatchers进行请求路径匹配,匹配规则更严格,需确保通配符(如/**)使用符合预期。
  • 配置风格全面转向Lambda表达式,旧有的链式配置方法(如sessionManagement().sessionCreationPolicy(...))部分被标记为废弃,推荐使用Lambda式写法。

3. Swagger端点新增

Springdoc 2.x为Swagger UI新增了/v3/api-docs/swagger-config端点,用于加载UI的全局配置信息。若未将此端点加入公开访问列表,会直接导致Swagger UI加载配置失败,出现你遇到的错误。

4. CORS配置细节优化

当设置allowCredentials(true)时,新版CorsConfiguration允许使用allowedOriginPatterns(List.of("*"))(旧版allowedOrigins不允许同时设置*和allowCredentials=true),但生产环境建议指定具体域名以保障安全性。

内容的提问来源于stack exchange,提问作者fghf

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 03:26:07