You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot POST请求认证时遭遇401 Unauthorized问题求助

问题排查:Spring Security POST请求401与登录500错误

场景与配置

使用Spring Boot开发API并通过Postman测试,配置带角色的Spring Security认证,核心配置如下:

public SecurityFilterChain securityFilterChain(HttpSecurity httpSecurity) throws Exception{
        httpSecurity.
                csrf(csrf->csrf.ignoringRequestMatchers("/Register"))
                .authorizeHttpRequests(
                (auth) -> {
                    auth.requestMatchers("/Register" , "/api/PostJob").permitAll();
                    auth.requestMatchers("/api/candidate/**").hasRole("candidate");
                    auth.requestMatchers("/api/Recruiters/**" ).hasRole("recruiter");
                    auth.requestMatchers("/api/job/**").hasRole("admin");
                    auth.anyRequest().authenticated();
                }

        ).formLogin(AbstractAuthenticationFilterConfigurer::permitAll).
                httpBasic(withDefaults());
         return httpSecurity.build();
    }

注册接口实现:

@PostMapping
public ResponseEntity<Person> createPerson(@RequestBody Person person){
    System.out.println(person);
    person.password = passwordEncoder.encode(person.password);
    Person person1 = personDetailService.createPerson(person);
   return ResponseEntity.status(HttpStatus.CREATED).body(person1);
}

问题现象

  • 对/Register或/api/PostJob发送GET请求正常,但POST请求返回401(未授权)
  • 尝试禁用/忽略CSRF令牌后问题依旧
  • 手动在数据库插入凭证并登录时,出现500错误

相关日志

2024-05-10T00:19:21.958+01:00 DEBUG 4295 --- [jobquest] [nio-8080-exec-7] o.s.security.web.FilterChainProxy        : Securing POST /error
2024-05-10T00:19:21.958+01:00 DEBUG 4295 --- [jobquest] [nio-8080-exec-7] o.s.s.w.a.AnonymousAuthenticationFilter  : Set SecurityContextHolder to anonymous SecurityContext
2024-05-10T00:19:21.958+01:00 DEBUG 4295 --- [jobquest] [nio-8080-exec-7] s.w.a.DelegatingAuthenticationEntryPoint : Trying to match using And [Not [RequestHeaderRequestMatcher [expectedHeaderName=X-Requested-With, expectedHeaderValue=XMLHttpRequest]], MediaTypeRequestMatcher [contentNegotiationStrategy=org.springframework.web.accept.ContentNegotiationManager@706c2726, matchingMediaTypes=[application/xhtml+xml, image/*, text/html, text/plain], useEquals=false, ignoredMediaTypes=[*/*]]]
2024-05-10T00:19:21.958+01:00 DEBUG 4295 --- [jobquest] [nio-8080-exec-7] s.w.a.DelegatingAuthenticationEntryPoint : Trying to match using Or [RequestHeaderRequestMatcher [expectedHeaderName=X-Requested-With, expectedHeaderValue=XMLHttpRequest], And [Not [MediaTypeRequestMatcher [contentNegotiationStrategy=org.springframework.web.accept.ContentNegotiationManager@706c2726, matchingMediaTypes=[text/html], useEquals=false, ignoredMediaTypes=[]]], MediaTypeRequestMatcher [contentNegotiationStrategy=org.springframework.web.accept.ContentNegotiationManager@706c2726, matchingMediaTypes=[application/atom+xml, application/x-www-form-urlencoded, application/json, application/octet-stream, application/xml, multipart/form-data, text/xml], useEquals=false, ignoredMediaTypes=[*/*]]], MediaTypeRequestMatcher [contentNegotiationStrategy=org.springframework.web.accept.ContentNegotiationManager@706c2726, matchingMediaTypes=[*/*], useEquals=true, ignoredMediaTypes=[]]]
2024-05-10T00:19:21.958+01:00 DEBUG 4295 --- [jobquest] [nio-8080-exec-7] s.w.a.DelegatingAuthenticationEntryPoint : Match found! Executing org.springframework.security.web.authentication.DelegatingAuthenticationEntryPoint@1ae2028d
2024-05-10T00:19:21.958+01:00 DEBUG 4295 --- [jobquest] [nio-8080-exec-7] s.w.a.DelegatingAuthenticationEntryPoint : Trying to match using RequestHeaderRequestMatcher [expectedHeaderName=X-Requested-With, expectedHeaderValue=XMLHttpRequest]
2024-05-10T00:19:21.958+01:00 DEBUG 4295 --- [jobquest] [nio-8080-exec-7] s.w.a.DelegatingAuthenticationEntryPoint : No match found. Using default entry point org.springframework.security.web.authentication.www.BasicAuthenticationEntryPoint@2b63fdbc

排查与解决步骤

1. 确认请求路径匹配

  • 检查注册接口的类级别@RequestMapping:当前注册方法仅用@PostMapping,未指定路径,需确保类上的@RequestMapping路径为/Register,否则实际请求路径与Security配置的/Register不匹配,导致POST请求未被放行。
  • 注意路径大小写:Spring Security的requestMatchers大小写敏感,确认Postman请求的路径(如/Register vs /register)与配置完全一致。

2. 补全CSRF忽略配置

当前仅忽略了/Register的CSRF校验,但/api/PostJob的POST请求同样需要排除CSRF拦截,修改配置如下:

csrf(csrf->csrf.ignoringRequestMatchers("/Register", "/api/PostJob"))

3. 修复登录500错误

  • 密码加密问题:手动插入数据库的密码必须是加密后的字符串(通过passwordEncoder.encode("明文密码")生成),若直接存入明文,认证时会因密码匹配失败抛出异常导致500。
  • 角色前缀问题:hasRole("candidate")会自动为角色添加ROLE_前缀,需确保数据库中存储的角色为ROLE_candidate,或改用hasAuthority("candidate")替代hasRole(无需前缀)。
  • 检查UserDetailsService实现:确认personDetailService.loadUserByUsername方法正确返回UserDetails对象,包含正确的权限信息。

4. 调试请求流程

日志显示拦截的是POST /error,说明原请求可能触发了错误页面转发。可开启Spring Security的DEBUG级日志,查看实际请求路径是否被正确匹配到permitAll规则,定位拦截环节。

内容的提问来源于stack exchange,提问作者Youssef Elhejjioui

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 04:08:13