You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring多端点认证配置问题:Basic Auth与OAuth2共存失效排查

问题排查与修复方案

核心问题分析

  • 过滤器链职责与顺序混乱:原配置中Order(1)的Basic Auth链绑定了/test2、/test3,而Order(2)的OAuth2链未明确管辖路径,导致请求匹配逻辑完全颠倒。同时未使用securityMatcher限定每个过滤器链的作用范围,多个链会对所有请求生效,引发冲突。
  • OAuth2链缺少授权规则:原filterChainOauth未配置authorizeHttpRequests,无法对/test2、/test3触发OAuth2认证。
  • LoginPage配置错误:将OAuth2的登录页指向/test1(Basic Auth端点),导致认证跳转逻辑混乱。
  • 内存用户重复:configureGlobal中添加了两个相同用户名的用户,后添加的会覆盖前一个,无法正常使用多用户。

修复后的完整代码

@Configuration
@EnableWebSecurity
public class SecurityConfigOauth {

    // 负责/test1的Basic Auth过滤器链,优先级更高(Order(1))
    @Bean
    @Order(1)
    public SecurityFilterChain filterChainHTTPBasic(HttpSecurity http) throws Exception {
        http
                // 限定此链仅处理/test1开头的请求
                .securityMatcher("/test1/**")
                .authorizeHttpRequests(authz -> authz
                        .anyRequest().authenticated())
                .csrf().disable()
                .httpBasic(withDefaults());
        return http.build();
    }

    // 负责/test2、/test3的OAuth2过滤器链,优先级次之(Order(2))
    @Bean
    @Order(2)
    public SecurityFilterChain filterChainOauth(HttpSecurity http) throws Exception {
        http
                // 限定此链仅处理/test2、/test3开头的请求
                .securityMatcher("/test2/**", "/test3/**")
                .headers().frameOptions().sameOrigin()
                .and()
                .csrf().disable()
                .authorizeHttpRequests(authz -> authz
                        .anyRequest().authenticated())
                .oauth2Login(withDefaults()); // 使用默认登录页,或指定合法的OAuth2登录端点

        return http.build();
    }

    @Bean
    DefaultOAuth2AuthorizationRequestResolver pkceResolver(ClientRegistrationRepository clientRegistrationRepository) {
        DefaultOAuth2AuthorizationRequestResolver resolver = new
                DefaultOAuth2AuthorizationRequestResolver(clientRegistrationRepository,
                OAuth2AuthorizationRequestRedirectFilter.DEFAULT_AUTHORIZATION_REQUEST_BASE_URI);
        resolver.setAuthorizationRequestCustomizer(OAuth2AuthorizationRequestCustomizers.withPkce());
        return resolver;
    }

    @Autowired
    public void configureGlobal(AuthenticationManagerBuilder auth) throws Exception {
        auth
                .inMemoryAuthentication()
                // 修正重复用户名问题,使用不同用户名
                .withUser("user1").password("test").roles("FIRST")
                .and()
                .withUser("user2").password("test").roles("SECOND");
    }

    @Bean
    public PasswordEncoder passwordEncoder() {
        // 仅用于测试环境,生产环境请使用BCryptPasswordEncoder等强加密方式
        return NoOpPasswordEncoder.getInstance();
    }
}

关键修复点说明

  • 添加securityMatcher:每个过滤器链通过securityMatcher明确指定管辖的请求路径,确保不同认证方式只作用于目标端点,避免过滤器链之间的冲突。
  • 调整过滤器链顺序与职责:让处理/test1的Basic Auth链优先级更高(Order(1)),OAuth2链负责/test2、/test3(Order(2)),匹配需求。
  • 补充OAuth2链的授权规则:添加authorizeHttpRequests(authz -> authz.anyRequest().authenticated()),确保/test2、/test3需要OAuth2认证。
  • 修正LoginPage配置:移除错误的loginPage("/test1"),使用OAuth2默认登录页,或根据实际需求配置合法的OAuth2登录端点。
  • 修复重复用户问题:将内存用户的用户名改为不同值,避免覆盖。

内容的提问来源于stack exchange,提问作者user23736880

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 17:48:13