Spring Security更新后启动失败,遇WebMvcSecurityConfiguration兼容错误
Spring Security升级后WebMvcSecurityConfiguration报错解决
问题背景
将Java课程中的Spring Security示例升级至最新版本,已完成以下操作:
- 更新Maven POM文件
- 将
antMatchers()替换为requestMatchers() - 将
javax包替换为jakarta
但程序启动时出现WebMvcSecurityConfiguration相关错误,报错信息如下:
APPLICATION FAILED TO START Description: An attempt was made to call a method that does not exist. The attempt was made from the following location: org.springframework.security.config.annotation.web.configuration. WebMvcSecurityConfiguration$HandlerMappingIntrospectorCachFilterFactoryBean.getObject(WebMvcSecurityConfiguration.java:183) The following method did not exist: 'jakarta.servlet.Filter org.springframework.web.servlet.handler.HandlerMappingIntrospector.createCacheFilter()' The calling method's class, org.springframework.security.config.annotation.web.configuration.WebMvcSecurityConfiguration $HandlerMappingIntrospectorCachFilterFactoryBean, was loaded from the following location: jar:file:/C:/Users/USERNAME/.m2/repository/org/springframework/security/spring-security- config/6.2.1/spring-security-config-6.2.1.jar!/org/springframework/security/config/annotation/web/configuration /WebMvcSecurityConfiguration$HandlerMappingIntrospectorCachFilterFactoryBean.class The called method's class, org.springframework.web.servlet.handler.HandlerMappingIntrospector, is available from the following locations: jar:file:/C:/Users/USERNAME/.m2/repository/org/springframework/spring-webmvc/6.0.12/spring- webmvc-6.0.12.jar!/org/springframework/web/servlet/handler/HandlerMappingIntrospector.class The called method's class hierarchy was loaded from the following locations: org.springframework.web.servlet.handler.HandlerMappingIntrospector: file:/C:/Users/USERNAME/ .m2/repository/org/springframework/spring-webmvc/6.0.12/spring-webmvc-6.0.12.jar Action: Correct the classpath of your application so that it contains compatible versions of the classes org.springframework.security.config.annotation.web.configuration. WebMvcSecurityConfiguration$HandlerMappingIntrospectorCachFilterFactoryBean and org.springframework.web.servlet.handler.HandlerMappingIntrospector Process finished with exit code 1
当前POM文件内容:
<?xml version="1.0" encoding="UTF-8"?> <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>3.1.4</version> <relativePath/> </parent> <groupId>isi.code</groupId> <artifactId>secure-demo</artifactId> <version>0.0.1-SNAPSHOT</version> <name>secure-demo</name> <description>secure-demo</description> <properties> <java.version>21</java.version> <spring-security.version>6.2.1</spring-security.version> <spring.version>6.1.2</spring.version> </properties> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-data-jpa</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-config</artifactId> </dependency> <dependency> <groupId>com.h2database</groupId> <artifactId>h2</artifactId> </dependency> <dependency> <groupId>org.projectlombok</groupId> <artifactId>lombok</artifactId> </dependency> <dependency> <groupId>jakarta.persistence</groupId> <artifactId>jakarta.persistence-api</artifactId> </dependency> </dependencies> </project>
Maven的clean、install、compile操作均无错误,但启动失败。
问题原因
报错核心是版本不兼容:
- Spring Security 6.2.1依赖Spring Framework 6.1.x及以上版本,其中
HandlerMappingIntrospector类新增了createCacheFilter()方法 - 当前项目中Spring Boot 3.1.4对应的
spring-webmvc版本是6.0.12,该版本没有这个方法,导致调用失败
解决方案
方案一:升级Spring Boot版本(推荐)
将Spring Boot parent版本升级到3.2.x(与Spring Security 6.2.1兼容),同时移除手动指定的Spring Security和Spring版本,由Spring Boot Parent自动管理依赖版本,避免冲突:
修改后的POM文件:
<?xml version="1.0" encoding="UTF-8"?> <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>3.2.1</version> <!-- 升级到兼容的Spring Boot稳定版 --> <relativePath/> </parent> <groupId>isi.code</groupId> <artifactId>secure-demo</artifactId> <version>0.0.1-SNAPSHOT</version> <name>secure-demo</name> <description>secure-demo</description> <properties> <java.version>21</java.version> <!-- 移除手动指定的spring-security.version和spring.version --> </properties> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-data-jpa</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <!-- 移除单独的spring-security-config,starter已包含 --> <dependency> <groupId>com.h2database</groupId> <artifactId>h2</artifactId> </dependency> <dependency> <groupId>org.projectlombok</groupId> <artifactId>lombok</artifactId> </dependency> <!-- 移除jakarta.persistence-api,spring-boot-starter-data-jpa已包含 --> </dependencies> </project>
方案二:降级Spring Security版本
如果不想升级Spring Boot,将Spring Security版本降级到与Spring Boot 3.1.4兼容的6.1.4:
修改POM中的spring-security.version:
<properties> <java.version>21</java.version> <spring-security.version>6.1.4</spring-security.version> <!-- 移除spring.version,保持与Spring Boot 3.1.4默认的6.0.12一致 --> </properties>
操作步骤
- 修改POM文件后,执行
mvn clean install清理并重新构建项目 - 重启应用
内容的提问来源于stack exchange,提问作者baphomet
相关产品推荐
相关产品推荐

