You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot Actuator端点权限异常:已放行但/actuator/metrics仍需认证

问题:已配置Spring Security放行/actuator/**,访问/actuator/metrics仍要求认证

我有一个运行在8081端口的Spring Boot应用,使用如下Spring Security配置:

@Configuration
@EnableMethodSecurity
public class WebSecurityConfig { // extends WebSecurityConfigurerAdapter {

    private final JwtUtils jwtUtils;
    private final UserDetailsServiceImpl userDetailsService;

    private final AuthEntryPointJwt unauthorizedHandler;

    public WebSecurityConfig(JwtUtils jwtUtils,
                             UserDetailsServiceImpl userDetailsService,
                             AuthEntryPointJwt unauthorizedHandler) {

        this.jwtUtils = jwtUtils;
        this.userDetailsService = userDetailsService;
        this.unauthorizedHandler = unauthorizedHandler;
    }

    @Bean
    public AuthTokenFilter authenticationJwtTokenFilter() {
        return new AuthTokenFilter(jwtUtils, userDetailsService);
    }

    @Bean
    public DaoAuthenticationProvider authenticationProvider() {
        DaoAuthenticationProvider authProvider = new DaoAuthenticationProvider();

        authProvider.setUserDetailsService(userDetailsService);
        authProvider.setPasswordEncoder(passwordEncoder());

        return authProvider;
 }

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http.csrf(AbstractHttpConfigurer::disable)
                .exceptionHandling(exception -> exception.authenticationEntryPoint(unauthorizedHandler))
                .sessionManagement(session -> session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
                .authorizeHttpRequests(auth ->
                        auth.requestMatchers("/api/auth/**").permitAll()
                                .requestMatchers("/actuator/**").permitAll()
                                .requestMatchers("/actuator/metrics").permitAll()
                                .requestMatchers("/api/languages").permitAll()
                                .requestMatchers("/api/actuator/health").permitAll()
                                .requestMatchers("/api/auth/sendMailOTP").permitAll()
                                .requestMatchers("/api/messages/**").permitAll()
                                .requestMatchers("/api/auth/socialSignin").permitAll()
                                .requestMatchers("/api/geoDetails").permitAll()
                                .requestMatchers("/api/legalinfo/**").permitAll()
                                .requestMatchers("/api/legalinfo/*").permitAll()
                                .requestMatchers("/api/legalinfo/eula").permitAll()
                                .requestMatchers("/api/users/uploadFile/**").permitAll()
                                .requestMatchers("/api/users/sendEmail").permitAll()
                                .requestMatchers("/api/legalinfo/privacy").permitAll()
                                .requestMatchers("/api/changeuserpassword").permitAll()
                                .requestMatchers("/api/forgotmypassword").permitAll()
                                .requestMatchers("/api/validateEmail").permitAll()
                                .requestMatchers("/api/checkToken").permitAll()
                                .requestMatchers("/api/checkOTPToken").permitAll()
                                .anyRequest().authenticated()
                );

        http.authenticationProvider(authenticationProvider());
        http.addFilterBefore(authenticationJwtTokenFilter(), UsernamePasswordAuthenticationFilter.class);

        return http.build();
    }
}

访问http://172.105.90.17:8081/actuator/health时,能正常返回:

{
  "status": "UP"
}

但访问http://172.105.90.17:8081/actuator/metrics时,收到如下错误响应:

{
  "message": "Full authentication is required to access this resource"
}

控制台输出日志如下:

2024-01-24 06:47:28.884 DEBUG [] o.s.b.f.s.DefaultListableBeanFactory@registerDependentBeans(952) - Autowiring by type from bean name 'webEndpointServletHandlerMapping' via factory method to bean named 'management.endpoints.web-org.springframework.boot.actuate.autoconfigure.endpoint.web.WebEndpointProperties'
2024-01-24 06:47:28.884 DEBUG [] o.s.b.f.s.DefaultListableBeanFactory@registerDependentBeans(952) - Autowiring by type from bean name 'webEndpointServletHandlerMapping' via factory method to bean named 'environment'
2024-01-24 06:47:28.891 INFO  [] o.s.b.a.e.web.EndpointLinksResolver@<init>(58) - Exposing 1 endpoint(s) beneath base path '/actuator'
2024-01-24 06:47:28.905 DEBUG [] o.s.b.f.s.DefaultListableBeanFactory@getSingleton(225) - Creating shared instance of singleton bean 'controllerEndpointHandlerMapping'

为何已在SecurityFilterChain中配置/actuator/**和/actuator/metrics允许所有访问,访问/actuator/metrics仍需认证?


内容的提问来源于stack exchange,提问作者Nunyet Calçada

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 12:24:52