You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security 6迁移报错:antMatchers及相关类弃用问题咨询

迁移Spring Security OAuth2配置至Spring Cloud 3/Spring Security 6

原配置代码

public class SecurityConfig extends ResourceServerConfigurerAdapter {
  
  @Override
  public void configure(final HttpSecurity http) throws Exception {

    http.authorizeRequests()
        .antMatchers(permittedAntMatchers())
        .permitAll();

    http.authorizeRequests().antMatchers("/**").authenticated();

    final OAuth2AuthenticationEntryPoint obj =
        new OAuth2AuthenticationEntryPoint();

    http.exceptionHandling().authenticationEntryPoint(obj);
  }
}

遇到的错误

  • org.springframework.security.oauth2.config.annotation.web.configuration.ResourceServerConfigurerAdapter 已废弃
  • 无法解析 ExpressionInterceptUrlRegistry 中的 antMatchers 方法
  • org.springframework.security.oauth2.provider.error.OAuth2AuthenticationEntryPoint 已废弃

迁移后的完整配置

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.authentication.www.BasicAuthenticationEntryPoint;
import org.springframework.security.oauth2.server.resource.web.BearerTokenAuthenticationEntryPoint;

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        // 配置请求授权规则
        http.authorizeHttpRequests(auth -> auth
                .requestMatchers(permittedAntMatchers())
                .permitAll()
                .anyRequest()
                .authenticated()
        );

        // 配置异常处理(替换废弃的OAuth2AuthenticationEntryPoint)
        http.exceptionHandling(exceptions -> exceptions
                // 资源服务器场景推荐使用BearerTokenAuthenticationEntryPoint,返回OAuth2规范响应
                .authenticationEntryPoint(new BearerTokenAuthenticationEntryPoint())
                // 若不需要OAuth2规范响应,可改用基础认证入口点
                // .authenticationEntryPoint(new BasicAuthenticationEntryPoint())
        );

        // 启用OAuth2资源服务器配置(必须添加,否则认证逻辑不生效)
        http.oauth2ResourceServer(oauth2 -> oauth2
                .jwt() // 若使用JWT令牌,启用此配置;若为 opaque 令牌则改用 .opaqueToken()
        );

        return http.build();
    }

    // 保留原有的允许路径定义方法
    private String[] permittedAntMatchers() {
        return new String[]{"/public/**", "/actuator/health"};
    }
}

关键迁移说明

  1. 替换废弃的ResourceServerConfigurerAdapter
    Spring Security 6移除了适配器模式,改用基于Bean的配置:

    • 添加@Configuration和@EnableWebSecurity注解
    • 通过创建SecurityFilterChain类型的Bean,替代原有的configure(HttpSecurity)重写方法
  2. 替换antMatchers方法

    • authorizeRequests()被替换为authorizeHttpRequests()
    • antMatchers()被替换为requestMatchers()
    • 用anyRequest()替代原有的"/**"全局匹配,简化配置逻辑
  3. 替换废弃的OAuth2AuthenticationEntryPoint

    • 资源服务器场景优先使用BearerTokenAuthenticationEntryPoint,它会返回符合OAuth2规范的错误响应(如携带WWW-Authenticate响应头)
    • 若不需要OAuth2规范响应,可选择Spring Security原生的入口点类(如BasicAuthenticationEntryPoint)
  4. 必须启用OAuth2资源服务器配置
    新增oauth2ResourceServer()配置块,根据令牌类型选择jwt()或opaqueToken(),确保认证逻辑正常生效

内容的提问来源于stack exchange,提问作者Peter Penzov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 03:22:23