You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 3.2.0配置Basic Auth后Postman无法访问接口的问题

解决Spring Boot 3.2.0中Postman使用Basic Auth无法访问接口的问题

你的问题出在Security配置仅启用了表单登录(formLogin),这是为浏览器访问场景设计的认证流程。当Postman通过Basic Auth发送请求时,Spring Security会默认将未认证请求重定向到登录表单页面,不会解析Basic Auth里的凭证。

解决方法是在Security配置中启用HTTP Basic认证,同时可以调整异常处理逻辑,让API请求返回标准的未认证状态码而非登录页面:

修改securityFilterChain方法,添加httpBasic配置:

@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity httpSecurity) throws Exception {
    return httpSecurity.csrf(AbstractHttpConfigurer::disable)
            .authorizeHttpRequests(auth -> auth.requestMatchers("/health", "/api/v1/user/new").permitAll()
                    .requestMatchers("/**").authenticated())
            .formLogin(AbstractAuthenticationFilterConfigurer::permitAll)
            // 启用HTTP Basic认证,处理Postman的Basic Auth凭证
            .httpBasic(Customizer.withDefaults())
            // 可选:让未认证的API请求返回401,而非重定向到登录页面
            .exceptionHandling(ex -> ex.authenticationEntryPoint(new HttpStatusEntryPoint(HttpStatus.UNAUTHORIZED)))
            .build();
}

修改说明:

  • httpBasic(Customizer.withDefaults()):启用HTTP Basic认证机制,Spring Security会自动解析请求头中的Authorization: Basic xxx凭证,完成认证流程
  • exceptionHandling配置:覆盖默认的重定向行为,当请求未认证时直接返回401 Unauthorized状态码,更符合API接口的交互预期,避免Postman收到登录表单的HTML内容

修改后重启应用,Postman使用Basic Auth即可正常访问/user接口。

内容的提问来源于stack exchange,提问作者Dany

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 04:06:35