You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security配置/auths/public/**允许访问仍返回403错误

Spring Boot 3.2.0 + Spring Security JWT 认证:公开路径返回403 Forbidden

使用Spring Boot 3.2.0,基于Spring Security实现JWT认证,已自定义JWT认证过滤器。在Security配置类中通过requestMatchers("/auths/public/**").permitAll()设置该路径允许所有访问,但发送POST请求http://localhost:5000/auths/public/send?message=Hello_Kafka时,仍返回403 Forbidden错误,请求被转发到错误处理器,无法定位原因。

安全配置代码

@Configuration
@EnableWebSecurity
@RequiredArgsConstructor
public class SecurityConfiguration {
    private final JwtAuthenticationFilter jwtAuthenticationFilter;
    private final AuthenticationProvider authenticationProvider;

    @Bean
    SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http.cors(AbstractHttpConfigurer::disable).authorizeHttpRequests((authorizationManagerRequestMatcherRegistry -> authorizationManagerRequestMatcherRegistry
                                .requestMatchers("/auths/inner/**").hasRole(Role.INNER_SERVICE.name())
                                .requestMatchers("/auths/authenticated/**").hasRole(Role.USER.name())
                                .requestMatchers("/auths/public/**").permitAll()
                                .requestMatchers("/actuator/**").permitAll()
                                .anyRequest().permitAll()
        ))
                .sessionManagement(management -> management.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
                .authenticationProvider(authenticationProvider)
                .addFilterBefore(jwtAuthenticationFilter, UsernamePasswordAuthenticationFilter.class);
        return http.build();
    }
}

JWT认证过滤器代码

@Component
@RequiredArgsConstructor
public class JwtAuthenticationFilter extends OncePerRequestFilter {
    private final JwtService jwtService;
    private final UserDetailsService userDetailsService;

    @Override
    protected void doFilterInternal(@NonNull HttpServletRequest request, @NonNull HttpServletResponse response,
            @NonNull FilterChain filterChain) throws ServletException, IOException {
        final String authHeader = request.getHeader("Authorization");
        final String jwt;
        final String userEmail;
        if (authHeader == null || !authHeader.startsWith("Bearer ")) {
            filterChain.doFilter(request, response);
            return;
        }
        jwt = authHeader.substring(7);
        userEmail = jwtService.extractUsername(jwt, true);
        if (userEmail != null && SecurityContextHolder.getContext().getAuthentication() == null) {
            UserDetails userDetails = this.userDetailsService.loadUserByUsername(userEmail);
            if (jwtService.isTokenValid(jwt, userDetails, true)) {
                UsernamePasswordAuthenticationToken authToken = new UsernamePasswordAuthenticationToken(userDetails,
                        null, userDetails.getAuthorities());
                authToken.setDetails(new WebAuthenticationDetailsSource().buildDetails(request));
                SecurityContextHolder.getContext().setAuthentication(authToken);
            }

        }
        filterChain.doFilter(request, response);
    }
}

请求返回结果

{
    "timestamp": "2024-01-15T18:42:16.607+00:00",
    "status": 403,
    "error": "Forbidden",
    "message": "Forbidden",
    "path": "/auths/public/send"
}

相关日志

2024-01-16 00:12:16.495 
d9814d3abe2031bb
2024-01-16T00:12:16.495+05:30  WARN [auth,0ac98fa25129402e7442fba23c5552be,d9814d3abe2031bb] 47661 --- [auth] [http-nio-auto-1-exec-1] [0ac98fa25129402e7442fba23c5552be-d9814d3abe2031bb] o.s.w.s.h.HandlerMappingIntrospector     : Cache miss for ERROR dispatch to '/error' (previous null). Performing MatchableHandlerMapping lookup. This is logged once only at WARN level, and every time at TRACE.
2024-01-16 00:12:16.550 
afab4ea55ae080f6
2024-01-16T00:12:16.550+05:30 DEBUG [auth,0ac98fa25129402e7442fba23c5552be,afab4ea55ae080f6] 47661 --- [auth] [http-nio-auto-1-exec-1] [0ac98fa25129402e7442fba23c5552be-afab4ea55ae080f6] o.s.web.servlet.DispatcherServlet        : "ERROR" dispatch for POST "/error?message=Hello_Kafka", parameters={masked}
2024-01-16 00:12:16.558 
afab4ea55ae080f6
2024-01-16T00:12:16.558+05:30 DEBUG [auth,0ac98fa25129402e7442fba23c5552be,afab4ea55ae080f6] 47661 --- [auth] [http-nio-auto-1-exec-1] [0ac98fa25129402e7442fba23c5552be-afab4ea55ae080f6] s.w.s.m.m.a.RequestMappingHandlerMapping : Mapped to org.springframework.boot.autoconfigure.web.servlet.error.BasicErrorController#error(HttpServletRequest)
2024-01-16 00:12:16.619 
afab4ea55ae080f6
2024-01-16T00:12:16.619+05:30 DEBUG [auth,0ac98fa25129402e7442fba23c5552be,afab4ea55ae080f6] 47661 --- [auth] [http-nio-auto-1-exec-1] [0ac98fa25129402e7442fba23c5552be-afab4ea55ae080f6] o.s.w.s.m.m.a.HttpEntityMethodProcessor  : Using 'application/json', given [*/*] and supported [application/json, application/*+json]
2024-01-16 00:12:16.629 
afab4ea55ae080f6
2024-01-16T00:12:16.629+05:30 DEBUG [auth,0ac98fa25129402e7442fba23c5552be,afab4ea55ae080f6] 47661 --- [auth] [http-nio-auto-1-exec-1] [0ac98fa25129402e7442fba23c5552be-afab4ea55ae080f6] o.s.w.s.m.m.a.HttpEntityMethodProcessor  : Writing [{timestamp=Tue Jan 16 00:12:16 IST 2024, status=403, error=Forbidden, message=Forbidden, path=/auths (truncated)...]
2024-01-16 00:12:16.659 
afab4ea55ae080f6
2024-01-16T00:12:16.659+05:30 DEBUG [auth,0ac98fa25129402e7442fba23c5552be,afab4ea55ae080f6] 47661 --- [auth] [http-nio-auto-1-exec-1] [0ac98fa25129402e7442fba23c5552be-afab4ea55ae080f6] o.s.web.servlet.DispatcherServlet        : Exiting from "ERROR" dispatch, status 403

内容的提问来源于stack exchange,提问作者Soumalya Bhattacharya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 02:09:49