Spring Boot Actuator端点权限异常:已放行但/actuator/metrics仍需认证
问题:已配置Spring Security放行/actuator/**,访问/actuator/metrics仍要求认证
我有一个运行在8081端口的Spring Boot应用,使用如下Spring Security配置:
@Configuration @EnableMethodSecurity public class WebSecurityConfig { // extends WebSecurityConfigurerAdapter { private final JwtUtils jwtUtils; private final UserDetailsServiceImpl userDetailsService; private final AuthEntryPointJwt unauthorizedHandler; public WebSecurityConfig(JwtUtils jwtUtils, UserDetailsServiceImpl userDetailsService, AuthEntryPointJwt unauthorizedHandler) { this.jwtUtils = jwtUtils; this.userDetailsService = userDetailsService; this.unauthorizedHandler = unauthorizedHandler; } @Bean public AuthTokenFilter authenticationJwtTokenFilter() { return new AuthTokenFilter(jwtUtils, userDetailsService); } @Bean public DaoAuthenticationProvider authenticationProvider() { DaoAuthenticationProvider authProvider = new DaoAuthenticationProvider(); authProvider.setUserDetailsService(userDetailsService); authProvider.setPasswordEncoder(passwordEncoder()); return authProvider; } @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http.csrf(AbstractHttpConfigurer::disable) .exceptionHandling(exception -> exception.authenticationEntryPoint(unauthorizedHandler)) .sessionManagement(session -> session.sessionCreationPolicy(SessionCreationPolicy.STATELESS)) .authorizeHttpRequests(auth -> auth.requestMatchers("/api/auth/**").permitAll() .requestMatchers("/actuator/**").permitAll() .requestMatchers("/actuator/metrics").permitAll() .requestMatchers("/api/languages").permitAll() .requestMatchers("/api/actuator/health").permitAll() .requestMatchers("/api/auth/sendMailOTP").permitAll() .requestMatchers("/api/messages/**").permitAll() .requestMatchers("/api/auth/socialSignin").permitAll() .requestMatchers("/api/geoDetails").permitAll() .requestMatchers("/api/legalinfo/**").permitAll() .requestMatchers("/api/legalinfo/*").permitAll() .requestMatchers("/api/legalinfo/eula").permitAll() .requestMatchers("/api/users/uploadFile/**").permitAll() .requestMatchers("/api/users/sendEmail").permitAll() .requestMatchers("/api/legalinfo/privacy").permitAll() .requestMatchers("/api/changeuserpassword").permitAll() .requestMatchers("/api/forgotmypassword").permitAll() .requestMatchers("/api/validateEmail").permitAll() .requestMatchers("/api/checkToken").permitAll() .requestMatchers("/api/checkOTPToken").permitAll() .anyRequest().authenticated() ); http.authenticationProvider(authenticationProvider()); http.addFilterBefore(authenticationJwtTokenFilter(), UsernamePasswordAuthenticationFilter.class); return http.build(); } }
访问http://172.105.90.17:8081/actuator/health时,能正常返回:
{ "status": "UP" }
但访问http://172.105.90.17:8081/actuator/metrics时,收到如下错误响应:
{ "message": "Full authentication is required to access this resource" }
控制台输出日志如下:
2024-01-24 06:47:28.884 DEBUG [] o.s.b.f.s.DefaultListableBeanFactory@registerDependentBeans(952) - Autowiring by type from bean name 'webEndpointServletHandlerMapping' via factory method to bean named 'management.endpoints.web-org.springframework.boot.actuate.autoconfigure.endpoint.web.WebEndpointProperties' 2024-01-24 06:47:28.884 DEBUG [] o.s.b.f.s.DefaultListableBeanFactory@registerDependentBeans(952) - Autowiring by type from bean name 'webEndpointServletHandlerMapping' via factory method to bean named 'environment' 2024-01-24 06:47:28.891 INFO [] o.s.b.a.e.web.EndpointLinksResolver@<init>(58) - Exposing 1 endpoint(s) beneath base path '/actuator' 2024-01-24 06:47:28.905 DEBUG [] o.s.b.f.s.DefaultListableBeanFactory@getSingleton(225) - Creating shared instance of singleton bean 'controllerEndpointHandlerMapping'
为何已在SecurityFilterChain中配置/actuator/**和/actuator/metrics允许所有访问,访问/actuator/metrics仍需认证?
内容的提问来源于stack exchange,提问作者Nunyet Calçada
相关产品推荐
相关产品推荐

