You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security表达式权限控制:引用Bean遇EL1041E解析异常求助

问题:Spring Security表达式引用Bean方法触发EL解析异常

在Spring Security中尝试通过Web安全表达式引用Bean方法实现基于表达式的权限控制,示例代码如下:

@Component
public class AuthorizationChecker {
    public boolean check(Authentication authentication, HttpServletRequest request) {
        return true;
    }
}

安全配置方法:

@Override
protected void configure(HttpSecurity http) throws Exception {
    http.cors().and().anonymous().disable().authorizeRequests().antMatchers(HttpMethod.POST, "/**")
            .access("@authorizationChecker(authentication, request)").and().oauth2ResourceServer().jwt();
}

启动Spring Boot应用时触发解析异常,报错信息:

EL1041E: After parsing a valid expression, there is still more data in the expression: 'lparen(()'

问题原因

EL解析器报错是因为SpEL表达式语法错误:@authorizationChecker(authentication, request)的写法不符合Spring Security的Bean方法调用规范。@authorizationChecker是获取Bean实例的语法,必须通过.明确指定要调用的方法,否则解析器会将后面的括号误认为是表达式的非法后缀,导致解析失败。

解决办法

修改access方法中的表达式,明确调用Bean的check方法,正确语法为@authorizationChecker.check(authentication, request)。修改后的安全配置代码如下:

@Override
protected void configure(HttpSecurity http) throws Exception {
    http.cors().and().anonymous().disable().authorizeRequests().antMatchers(HttpMethod.POST, "/**")
            .access("@authorizationChecker.check(authentication, request)").and().oauth2ResourceServer().jwt();
}

Spring Security的SpEL规则中,@beanId用于引用Spring容器中的Bean实例,后续必须通过.调用具体方法,这样EL解析器才能正确识别这是一个合法的Bean方法调用表达式。

内容的提问来源于stack exchange,提问作者PDStat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 09:42:08