You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

启用样式时Spring Security请求返回403错误求助

问题描述
  • 当前页面已通过ADMIN_ROLE授权,点击页面上的“锁定用户”按钮发送PATCH请求时,返回403错误
  • 页面加载style.css时会触发该问题,禁用样式则无此异常

HTML元信息

<meta charset="UTF-8">
<title>Users</title>
<link rel="stylesheet" type="text/css" href="/css/style.css">

PATCH请求表单代码

<form th:action="@{'/users/' + ${user.userId} + '?lock=1'}" method="post">
  <input type="hidden" name="_method" value="patch">
  <button class="page_button" type="submit">Lock user</button>
</form>

服务器安全跟踪日志

2024-05-08T16:12:13.191+04:00 TRACE 103408 --- [fin-man-api] [nio-8080-exec-9] o.s.security.web.FilterChainProxy        : Securing PATCH /users/a77246cc-3353-4480-936f-d2d6ef9a706d?lock=1
2024-05-08T16:12:13.192+04:00 DEBUG 103408 --- [fin-man-api] [nio-8080-exec-9] o.s.security.web.csrf.CsrfFilter         : Invalid CSRF token found for https://localhost:8080/users/a77246cc-3353-4480-936f-d2d6ef9a706d?lock=1
2024-05-08T16:12:13.192+04:00 DEBUG 103408 --- [fin-man-api] [nio-8080-exec-9] o.s.s.w.access.AccessDeniedHandlerImpl   : Responding with 403 status code
2024-05-08T16:12:13.192+04:00 TRACE 103408 --- [fin-man-api] [nio-8080-exec-9] o.s.security.web.FilterChainProxy        : Trying to match request against DefaultSecurityFilterChain [RequestMatcher=any request, Filters=
2024-05-08T16:12:13.192+04:00 DEBUG 103408 --- [fin-man-api] [nio-8080-exec-9] o.s.security.web.FilterChainProxy        : Securing POST /error?lock=1
2024-05-08T16:12:13.193+04:00 TRACE 103408 --- [fin-man-api] [nio-8080-exec-9] .s.s.w.c.SupplierDeferredSecurityContext : Created SecurityContextImpl [Null authentication]
2024-05-08T16:12:13.193+04:00 TRACE 103408 --- [fin-man-api] [nio-8080-exec-9] o.s.s.w.a.AnonymousAuthenticationFilter  : Set SecurityContextHolder to AnonymousAuthenticationToken [Principal=anonymousUser, Credentials=[PROTECTED], Authenticated=true, Details=WebAuthenticationDetails [RemoteIpAddress=0:0:0:0:0:0:0:1, SessionId=651448C2F40E52F1E955B65F3CF7ADBC], Granted Authorities=[ROLE_ANONYMOUS]]
2024-05-08T16:12:13.193+04:00 TRACE 103408 --- [fin-man-api] [nio-8080-exec-9] o.s.security.web.FilterChainProxy        : Invoking ExceptionTranslationFilter (13/16)
2024-05-08T16:12:13.193+04:00 TRACE 103408 --- [fin-man-api] [nio-8080-exec-9] o.s.security.web.FilterChainProxy        : Invoking JwtRequestFilter (14/16)
2024-05-08T16:12:13.193+04:00 TRACE 103408 --- [fin-man-api] [nio-8080-exec-9] o.s.security.web.FilterChainProxy        : Invoking JwtRefreshFilter (15/16)
2024-05-08T16:12:13.193+04:00 TRACE 103408 --- [fin-man-api] [nio-8080-exec-9] o.s.security.web.FilterChainProxy        : Invoking AuthorizationFilter (16/16)
2024-05-08T16:12:13.193+04:00 TRACE 103408 --- [fin-man-api] [nio-8080-exec-9] estMatcherDelegatingAuthorizationManager : Authorizing SecurityContextHolderAwareRequestWrapper[ FirewalledRequest[ org.apache.catalina.core.ApplicationHttpRequest@5168821]]
2024-05-08T16:12:13.193+04:00 TRACE 103408 --- [fin-man-api] [nio-8080-exec-9] estMatcherDelegatingAuthorizationManager : Checking authorization on SecurityContextHolderAwareRequestWrapper[ FirewalledRequest[ org.apache.catalina.core.ApplicationHttpRequest@5168821]] using org.springframework.security.config.annotation.web.configurers.AuthorizeHttpRequestsConfigurer$$Lambda$1886/0x0000022711c49800@7ea871b5
2024-05-08T16:12:13.193+04:00 DEBUG 103408 --- [fin-man-api] [nio-8080-exec-9] o.s.security.web.FilterChainProxy        : Secured POST /error?lock=1
2024-05-08T16:12:13.203+04:00 TRACE 103408 --- [fin-man-api] [io-8080-exec-10] o.s.security.web.FilterChainProxy        : Trying to match request against DefaultSecurityFilterChain [RequestMatcher=any request, Filters=
2024-05-08T16:12:13.204+04:00 DEBUG 103408 --- [fin-man-api] [io-8080-exec-10] o.s.security.web.FilterChainProxy        : Securing GET /css/style.css
2024-05-08T16:12:13.204+04:00 TRACE 103408 --- [fin-man-api] [io-8080-exec-10] o.s.s.w.a.www.BasicAuthenticationFilter  : Found username 'admin@mail.com' in Basic Authorization header
2024-05-08T16:12:13.204+04:00 TRACE 103408 --- [fin-man-api] [io-8080-exec-10] .s.s.w.c.SupplierDeferredSecurityContext : Created SecurityContextImpl [Null authentication]
2024-05-08T16:12:13.204+04:00 TRACE 103408 --- [fin-man-api] [io-8080-exec-10] o.s.s.authentication.ProviderManager     : Authenticating request with DaoAuthenticationProvider (1/1)
Hibernate: select u1_0.id,u1_0.email,u1_0.account_is_locked,u1_0.account_is_enabled,u1_0.password,u1_0.user_id from users_table u1_0 where u1_0.email=?
Hibernate: select r1_0.id,r1_1.role_id,r1_1.role_name from role_user r1_0 join roles_table r1_1 on r1_1.role_id=r1_0.role_id where r1_0.id=?
2024-05-08T16:12:13.480+04:00 DEBUG 103408 --- [fin-man-api] [io-8080-exec-10] o.s.s.a.dao.DaoAuthenticationProvider    : Authenticated user
2024-05-08T16:12:13.480+04:00 DEBUG 103408 --- [fin-man-api] [io-8080-exec-10] .s.ChangeSessionIdAuthenticationStrategy : Changed session id from 651448C2F40E52F1E955B65F3CF7ADBC
2024-05-08T16:12:13.481+04:00 TRACE 103408 --- [fin-man-api] [io-8080-exec-10] s.CompositeSessionAuthenticationStrategy : Preparing session with CsrfAuthenticationStrategy (2/2)
2024-05-08T16:12:13.481+04:00 DEBUG 103408 --- [fin-man-api] [io-8080-exec-10] o.s.s.w.csrf.CsrfAuthenticationStrategy  : Replaced CSRF Token
2024-05-08T16:12:13.481+04:00 TRACE 103408 --- [fin-man-api] [io-8080-exec-10] o.s.security.web.FilterChainProxy        : Invoking ExceptionTranslationFilter (13/16)
2024-05-08T16:12:13.481+04:00 TRACE 103408 --- [fin-man-api] [io-8080-exec-10] o.s.security.web.FilterChainProxy        : Invoking JwtRequestFilter (14/16)
2024-05-08T16:12:13.481+04:00 TRACE 103408 --- [fin-man-api] [io-8080-exec-10] o.s.security.web.FilterChainProxy        : Invoking JwtRefreshFilter (15/16)
2024-05-08T16:12:13.481+04:00 TRACE 103408 --- [fin-man-api] [io-8080-exec-10] o.s.security.web.FilterChainProxy        : Invoking AuthorizationFilter (16/16)
2024-05-08T16:12:13.481+04:00 TRACE 103408 --- [fin-man-api] [io-8080-exec-10] estMatcherDelegatingAuthorizationManager : Authorizing SecurityContextHolderAwareRequestWrapper[ org.springframework.security.web.header.HeaderWriterFilter$HeaderWriterRequest@2102ea33]
2024-05-08T16:12:13.481+04:00 TRACE 103408 --- [fin-man-api] [io-8080-exec-10] estMatcherDelegatingAuthorizationManager : Checking authorization on SecurityContextHolderAwareRequestWrapper[ org.springframework.security.web.header.HeaderWriterFilter$HeaderWriterRequest@2102ea33] using org.springframework.security.config.annotation.web.configurers.AuthorizeHttpRequestsConfigurer$$Lambda$1886/0x0000022711c49800@7ea871bz
2024-05-08T16:12:13.481+04:00 DEBUG 103408 --- [fin-man-api] [io-8080-exec-10] o.s.security.web.FilterChainProxy        : Secured GET /css/style.css

已尝试的无效方案

  • 将/css/style.css加入permitAll请求列表
  • 关闭该路径的CSRF防护

Spring Security配置代码

http
        .httpBasic(Customizer.withDefaults())
        .csrf(httpSecurityCsrfConfigurer -> httpSecurityCsrfConfigurer
                .ignoringRequestMatchers(disabledCsrfUrl))
        .cors(AbstractHttpConfigurer::disable)
        .with(jwtAuthenticationConfigurer, Customizer.withDefaults())
        .authorizeHttpRequests(auth -> auth
                .requestMatchers("/css/**").permitAll()
                .requestMatchers("/js/**").permitAll()
                .requestMatchers("/img/**").permitAll()
                .requestMatchers("/error", HttpMethod.GET.name()).permitAll()
                .requestMatchers("/api/v1/users/registration", HttpMethod.POST.name()).permitAll()
                .requestMatchers(HttpMethod.GET,getUrl).hasAnyRole("ADMIN", "USER", "MODERATOR")
                .requestMatchers(HttpMethod.POST, postUrl).hasAnyRole("ADMIN", "USER", "MODERATOR")
                .requestMatchers(HttpMethod.DELETE, deleteUrl).hasAnyRole("ADMIN", "USER", "MODERATOR")
                .requestMatchers(HttpMethod.PATCH, patchUrl).hasAnyRole("ADMIN", "USER", "MODERATOR")
                .requestMatchers(moderatorUrl).hasAnyRole("ADMIN","MODERATOR")
                .requestMatchers(adminUrl).hasRole("ADMIN")
                .anyRequest().authenticated())
        .sessionManagement(session -> session
                .sessionCreationPolicy(SessionCreationPolicy.STATELESS)
        )
        .headers(headers -> headers
                .frameOptions(HeadersConfigurer.FrameOptionsConfig::disable)
                .xssProtection(HeadersConfigurer.XXssConfig::disable));

return http.build();

内容的提问来源于stack exchange,提问作者user24933657

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 13:55:52