anyExchange().authenticated()实际作用探究:为何添加前后无差异?
探究
anyExchange().authenticated()的实际作用 本文探究anyExchange().authenticated()的实际作用,以下是最小可复现示例(MRE):
项目依赖配置(pom.xml)
<?xml version="1.0" encoding="UTF-8"?> <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>3.2.2</version> <relativePath/> <!-- lookup parent from repository --> </parent> <groupId>com.example</groupId> <artifactId>security-mre</artifactId> <version>0.0.1-SNAPSHOT</version> <name>security-mre</name> <description>security-mre</description> <properties> <java.version>17</java.version> </properties> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-webflux</artifactId> </dependency> <dependency> <groupId>org.projectlombok</groupId> <artifactId>lombok</artifactId> <optional>true</optional> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>io.projectreactor</groupId> <artifactId>reactor-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-test</artifactId> <scope>test</scope> </dependency> </dependencies> <build> <plugins> <plugin> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-maven-plugin</artifactId> <configuration> <excludes> <exclude> <groupId>org.projectlombok</groupId> <artifactId>lombok</artifactId> </exclude> </excludes> </configuration> </plugin> </plugins> </build> </project>
初始控制器代码
package com.example.securitymre.controller; import com.example.securitymre.data.Hello; import org.springframework.web.bind.annotation.GetMapping; import org.springframework.web.bind.annotation.RestController; @RestController public class HelloController { @GetMapping("/hello") public Hello getHello() { return new Hello(); } }
初始数据类代码
package com.example.securitymre.data; import lombok.Getter; import lombok.NoArgsConstructor; @NoArgsConstructor @Getter public class Hello { private final String message = "Hello!"; }
初始测试结果
我几乎没写什么代码,也没有配置安全规则,但执行以下命令时:
curl -i localhost:8080/hello
返回结果:
HTTP/1.1 401 Unauthorized WWW-Authenticate: Basic realm="Realm" Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: 0 X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 0 Referrer-Policy: no-referrer content-length: 0
未认证状态下已无法访问应用
实验2:添加安全配置并测试
修改数据类Hello
package com.example.securitymre.data; import lombok.Getter; import lombok.NoArgsConstructor; @NoArgsConstructor @Getter public class Hello { private String message = "Hello!"; public Hello(String message) { this.message = message; } }
修改控制器,添加新接口
package com.example.securitymre.controller; import com.example.securitymre.data.Hello; import org.springframework.web.bind.annotation.GetMapping; import org.springframework.web.bind.annotation.RestController; @RestController public class HelloController { @GetMapping("/hello") public Hello getHello() { return new Hello(); } @GetMapping("/secured-hello") public Hello getSecuredHello() { return new Hello("Secured hello!"); } }
添加包含anyExchange().authenticated()的安全配置类
package com.example.securitymre.config; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.reactive.EnableWebFluxSecurity; import org.springframework.security.config.web.server.ServerHttpSecurity; import org.springframework.security.web.server.SecurityWebFilterChain; @Configuration @EnableWebFluxSecurity public class SecurityConfig { @Bean public SecurityWebFilterChain securityFilterChain(ServerHttpSecurity security) { return security .authorizeExchange(authorizeExchangeSpec -> authorizeExchangeSpec .pathMatchers("/hello").permitAll() .anyExchange()/* by "any" we mean GET /secured-hello */.authenticated() ) .build(); } }
实验2测试结果
curl -i localhost:8080/hello
返回:
HTTP/1.1 200 OK Content-Type: application/json Content-Length: 20 Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: 0 X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 0 Referrer-Policy: no-referrer {"message":"Hello!"}
curl -i localhost:8080/secured-hello
返回:
HTTP/1.1 401 Unauthorized WWW-Authenticate: Basic realm="Realm" Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: 0 X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 0 Referrer-Policy: no-referrer content-length: 0
移除anyExchange().authenticated()后的测试
修改安全配置类
package com.example.securitymre.config; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.reactive.EnableWebFluxSecurity; import org.springframework.security.config.web.server.ServerHttpSecurity; import org.springframework.security.web.server.SecurityWebFilterChain; @Configuration @EnableWebFluxSecurity public class SecurityConfig { @Bean public SecurityWebFilterChain securityFilterChain(ServerHttpSecurity security) { return security .authorizeExchange(authorizeExchangeSpec -> authorizeExchangeSpec .pathMatchers("/hello").permitAll() ) .build(); } }
测试结果
curl -i localhost:8080/hello
返回:
HTTP/1.1 200 OK Content-Type: application/json Content-Length: 20 Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: 0 X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 0 Referrer-Policy: no-referrer {"message":"Hello!"}
curl -i localhost:8080/secured-hello
返回:
HTTP/1.1 401 Unauthorized WWW-Authenticate: Basic realm="Realm" Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: 0 X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 0 Referrer-Policy: no-referrer content-length: 0
两种配置的测试结果完全一致。
我经验有限,但之前参与的项目中都包含anyRequest().authenticated()这类配置。现在发现它似乎是默认规则,看不出实际作用。
请问我是否忽略了什么?anyExchange().authenticated()到底有什么实际作用?
内容的提问来源于stack exchange,提问作者Sergey Zolotarev
相关产品推荐
相关产品推荐

