SpringBoot从2.4升级到3.1后路径匹配报错求解决方案
问题描述
将Spring Boot从2.4版本升级至3.1版本后,调用接口http://localhost:8080/student/123/get时触发如下错误:
org.springframework.web.util.pattern.PatternParseException: No more pattern data allowed after {*...} or ** pattern element
已添加配置spring.mvc.pathmatch.matching-strategy=ANT_PATH_MATCHER,但问题仍未解决。相关代码及依赖如下:
Gradle依赖
implementation 'org.springframework.boot:spring-boot-starter-web:3.2.0' implementation 'org.springframework:spring-websocket:6.1.4' implementation('org.springframework.boot:spring-boot-starter-security:3.2.0')
Security配置类
@Configuration @EnableWebSecurity @EnableMethodSecurity public class JwtSecurityConfig { @Autowired private UserDetailsService userDetailsService; @Autowired private RequestFilter requestFilter; @Autowired private JwtEntryPoint jwtEntryPoint; @Autowired public void globalUserDetails(AuthenticationManagerBuilder auth) throws Exception { auth.userDetailsService(userDetailsService); } @Bean public UserDetailsService userDetailsService() { return new UserDetailsService(); // 注意:此处直接返回接口实例不合法,需替换为自定义实现类 } @Bean public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception { httpSecurity.csrf(csrf -> csrf.disable()).authorizeHttpRequests(auth -> auth .requestMatchers("/student/{studentId}/**").permitAll() .requestMatchers("/{userId}/websocket/**").permitAll() .anyRequest().authenticated()) .exceptionHandling(exp -> exp.authenticationEntryPoint(jwtEntryPoint)) .sessionManagement(sess -> sess.sessionCreationPolicy(SessionCreationPolicy.STATELESS)) .addFilterBefore(requestFilter, UsernamePasswordAuthenticationFilter.class); return httpSecurity.build(); } }
Controller代码
@RestController @RequestMapping("/student") public class StudentController { @Autowired private StudentRepository repository; @GetMapping(value = "/{studentId}/get") public ResponseEntity<?> getStudent(@PathVariable String studentId) { return repository.findById(studentId); } }
错误原因
Spring Boot 3.x对应的Spring Security 6.x默认使用PathPatternParser处理路径匹配,该规则下不允许在**通配符之后添加任何路径元素。你配置的/student/{studentId}/**写法违反了这一规则,且spring.mvc.pathmatch.matching-strategy仅控制Spring MVC的路径匹配逻辑,不会影响Spring Security的路径匹配策略。
解决方案
方案一:在Security配置中显式使用Ant风格路径匹配器
修改filterChain方法中的requestMatchers,通过AntPathRequestMatcher定义路径:
@Bean public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception { httpSecurity.csrf(csrf -> csrf.disable()).authorizeHttpRequests(auth -> auth .requestMatchers(new AntPathRequestMatcher("/student/{studentId}/**")).permitAll() .requestMatchers(new AntPathRequestMatcher("/{userId}/websocket/**")).permitAll() .anyRequest().authenticated()) .exceptionHandling(exp -> exp.authenticationEntryPoint(jwtEntryPoint)) .sessionManagement(sess -> sess.sessionCreationPolicy(SessionCreationPolicy.STATELESS)) .addFilterBefore(requestFilter, UsernamePasswordAuthenticationFilter.class); return httpSecurity.build(); }
方案二:全局配置Spring Security使用Ant风格路径匹配
在application.properties中添加以下配置:
spring.security.matcher.matching-strategy=ant_path_matcher
添加后,Security配置类中的原有路径写法可保持不变,全局配置会让Spring Security自动使用Ant风格匹配规则。
额外提示
你的UserDetailsService Bean存在逻辑错误:return new UserDetailsService();直接返回接口实例不符合Java规范,需要替换为你自己实现的UserDetailsService子类,否则后续会触发认证相关异常。
内容的提问来源于stack exchange,提问作者Vijay

