You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SpringBoot项目webSecurityConfig.xml配置无效,构建报错求助

问题解决步骤

1. 修复webSecurityConfig.xml的命名空间缺失问题

错误提示"找不到元素'http'的声明",核心原因是XML配置文件未引入Spring Security和Spring Beans的命名空间及Schema约束。替换为以下完整配置:

<?xml version="1.0" encoding="UTF-8"?>
<beans:beans xmlns="http://www.springframework.org/schema/security"
             xmlns:beans="http://www.springframework.org/schema/beans"
             xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
             xsi:schemaLocation="http://www.springframework.org/schema/security
                                 http://www.springframework.org/schema/security/spring-security.xsd
                                 http://www.springframework.org/schema/beans
                                 http://www.springframework.org/schema/beans/spring-beans.xsd">

    <http use-expressions="true">
        <intercept-url pattern="/login*" access="isAnonymous()" />
        <intercept-url pattern="/**" access="isAuthenticated()"/>

        <form-login login-page='/login.html'
                    default-target-url="/homepage.html"
                    authentication-failure-url="/login.html?error=true" />
        <logout logout-success-url="/login.html" />
    </http>

    <authentication-manager>
        <authentication-provider>
            <user-service>
                <user name="user1" password="$2a$10$EixZaY3s7vjRTVxS6M/.ueS7vKCTe6U8r0W9XnCqK0aT0aGqFyG9y" authorities="ROLE_USER" />
            </user-service>
            <password-encoder ref="encoder" />
        </authentication-provider>
    </authentication-manager>

    <beans:bean id="encoder"
                class="org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder">
    </beans:bean>

</beans:beans>

注意:配置中的密码是user1Pass经过BCrypt加密后的结果,明文密码无法通过BCrypt验证。你可以通过测试类调用new BCryptPasswordEncoder().encode("user1Pass")生成对应加密值替换。

2. 修复pom.xml中Spring Security依赖版本不一致问题

你的Spring Boot父版本为2.7.18,但手动指定了Spring Security Starter版本为2.3.3.RELEASE,版本不匹配会引发兼容性问题。删除手动指定的version,让父pom自动管理版本:

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
    <!-- 移除手动指定的version,使用父pom管理的同版本依赖 -->
</dependency>

3. 确保配置文件被Spring Boot识别

若未配置,需在启动类上添加注解导入XML文件:

@ImportResource("classpath:webSecurityConfig.xml")

或在application.properties中添加配置:

spring.config.import=classpath:webSecurityConfig.xml

内容的提问来源于stack exchange,提问作者bircastri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 02:09:51