You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SpringBoot从2.4升级到3.1后路径匹配报错求解决方案

问题解决:Spring Boot 3.x升级后路径匹配错误 "No more pattern data allowed after {*...} or ** pattern element"

问题描述

将Spring Boot从2.4版本升级至3.1版本后,调用接口http://localhost:8080/student/123/get时触发如下错误:

org.springframework.web.util.pattern.PatternParseException: No more pattern data allowed after {*...} or ** pattern element

已添加配置spring.mvc.pathmatch.matching-strategy=ANT_PATH_MATCHER,但问题仍未解决。相关代码及依赖如下:

Gradle依赖

implementation 'org.springframework.boot:spring-boot-starter-web:3.2.0'
implementation 'org.springframework:spring-websocket:6.1.4'
implementation('org.springframework.boot:spring-boot-starter-security:3.2.0')

Security配置类

@Configuration
@EnableWebSecurity
@EnableMethodSecurity
public class JwtSecurityConfig {
    @Autowired
    private UserDetailsService userDetailsService;

    @Autowired
    private RequestFilter requestFilter;

    @Autowired
    private JwtEntryPoint jwtEntryPoint;

    @Autowired
    public void globalUserDetails(AuthenticationManagerBuilder auth) throws Exception {
        auth.userDetailsService(userDetailsService);
    }

    @Bean
    public UserDetailsService userDetailsService() {
        return new UserDetailsService(); // 注意:此处直接返回接口实例不合法,需替换为自定义实现类
    }

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception {
        httpSecurity.csrf(csrf -> csrf.disable()).authorizeHttpRequests(auth -> auth
                .requestMatchers("/student/{studentId}/**").permitAll()
                .requestMatchers("/{userId}/websocket/**").permitAll()
                .anyRequest().authenticated())
                .exceptionHandling(exp -> exp.authenticationEntryPoint(jwtEntryPoint))
                .sessionManagement(sess -> sess.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
                .addFilterBefore(requestFilter, UsernamePasswordAuthenticationFilter.class);
        return httpSecurity.build();
    }
}

Controller代码

@RestController
@RequestMapping("/student")
public class StudentController {

    @Autowired
    private StudentRepository repository;

    @GetMapping(value = "/{studentId}/get")
    public ResponseEntity<?> getStudent(@PathVariable String studentId) {
        return repository.findById(studentId);
    }
}

错误原因

Spring Boot 3.x对应的Spring Security 6.x默认使用PathPatternParser处理路径匹配,该规则下不允许在**通配符之后添加任何路径元素。你配置的/student/{studentId}/**写法违反了这一规则,且spring.mvc.pathmatch.matching-strategy仅控制Spring MVC的路径匹配逻辑,不会影响Spring Security的路径匹配策略。

解决方案

方案一:在Security配置中显式使用Ant风格路径匹配器

修改filterChain方法中的requestMatchers,通过AntPathRequestMatcher定义路径:

@Bean
public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception {
    httpSecurity.csrf(csrf -> csrf.disable()).authorizeHttpRequests(auth -> auth
            .requestMatchers(new AntPathRequestMatcher("/student/{studentId}/**")).permitAll()
            .requestMatchers(new AntPathRequestMatcher("/{userId}/websocket/**")).permitAll()
            .anyRequest().authenticated())
            .exceptionHandling(exp -> exp.authenticationEntryPoint(jwtEntryPoint))
            .sessionManagement(sess -> sess.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
            .addFilterBefore(requestFilter, UsernamePasswordAuthenticationFilter.class);
    return httpSecurity.build();
}

方案二:全局配置Spring Security使用Ant风格路径匹配

在application.properties中添加以下配置:

spring.security.matcher.matching-strategy=ant_path_matcher

添加后,Security配置类中的原有路径写法可保持不变,全局配置会让Spring Security自动使用Ant风格匹配规则。

额外提示

你的UserDetailsService Bean存在逻辑错误:return new UserDetailsService();直接返回接口实例不符合Java规范,需要替换为你自己实现的UserDetailsService子类,否则后续会触发认证相关异常。

内容的提问来源于stack exchange,提问作者Vijay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 00:15:53