You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security 6角色前缀设置方法及旧代码迁移咨询

问题:Spring Security 6 中设置角色前缀并迁移旧代码

我是Java与Spring Security的新手,Spring Security 6中有大量类和接口已被弃用。我知晓该版本需使用AuthorizationManager,但不清楚如何设置角色前缀。此前用于设置角色前缀的RoleVoter类也已被弃用,现需将以下旧代码迁移至Spring Security 6:

import java.util.List;
import org.aopalliance.intercept.MethodInterceptor;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.security.access.AccessDecisionManager;
import org.springframework.security.access.AccessDecisionVoter;
import org.springframework.security.access.intercept.aopalliance.MethodSecurityInterceptor;
import org.springframework.security.access.vote.AbstractAccessDecisionManager;
import org.springframework.security.access.vote.RoleVoter;
import org.springframework.stereotype.Component;

import jakarta.annotation.PostConstruct;

@Component
public class AccessDecisionManagerCustomizer {

    @Autowired
    protected MethodInterceptor methodSecurityInterceptor;

    @PostConstruct
    public void init() {

        if (methodSecurityInterceptor instanceof MethodSecurityInterceptor) {

            AccessDecisionManager accessDecisionManager = ((MethodSecurityInterceptor) methodSecurityInterceptor).getAccessDecisionManager();
            if (accessDecisionManager instanceof AbstractAccessDecisionManager) {

                List<AccessDecisionVoter<? extends Object>> voters = ((AbstractAccessDecisionManager) accessDecisionManager).getDecisionVoters();
                RoleVoter scopeVoter = new RoleVoter();
                scopeVoter.setRolePrefix("SCOPE_");
                voters.add(scopeVoter);

            } else
                // throw exception here
        } else
            // throw exception here
    }
}

此外,我们自定义OAuth库中的SecurityFilterChain类如下:

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.ComponentScan;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.authentication.AuthenticationProvider;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.oauth2.jwt.JwtDecoder;
import org.springframework.security.oauth2.server.resource.authentication.JwtAuthenticationProvider;
import org.springframework.security.web.access.ExceptionTranslationFilter;

import com.oauth.web.filter.SSOCookieAuthenticationFilter;
import com.oauth.web.security.oauth2.PreAuthAccessDeniedHandler;

@Configuration
@ComponentScan("com.oauth.web")
public class SecurityFilterChain {

    @Autowired
    SSOCookieAuthenticationFilter sSOCookieAuthenticationFilter;

    public void configure(HttpSecurity http) throws Exception {
        http.addFilterAfter(sSOCookieAuthenticationFilter, ExceptionTranslationFilter.class);
        http.exceptionHandling().authenticationEntryPoint(new PreAuthAccessDeniedHandler());
    }
}

项目中继承该类的配置类如下:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.core.env.Environment;
import org.springframework.security.config.Customizer;
import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityCustomizer;
import org.springframework.security.config.annotation.web.configurers.HeadersConfigurer;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.csrf.CookieCsrfTokenRepository;
import org.springframework.security.web.csrf.CsrfTokenRepository;
import static org.springframework.security.config.Customizer.withDefaults;

import com.oauth.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
@EnableMethodSecurity(securedEnabled = true)
public class SSOSecurityConfig extends SecurityFilterChain {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http.headers(headers -> headers.frameOptions(createFrameOptionCustomizer())
                .contentSecurityPolicy(csp -> csp.policyDirectives(CSP)))
                .authorizeHttpRequests(auth -> auth
                        .requestMatchers(EndpointRequest.to(InfoEndpoint.class), EndpointRequest.to(HealthEndpoint.class)).permitAll()
                        .requestMatchers(EndpointRequest.toAnyEndpoint()).authenticated()
                        .requestMatchers("/", "/login**", "/callback/", "/oauth2/authorization/**", "/error**").permitAll()
                        .anyRequest().fullyAuthenticated())
                .httpBasic(withDefaults());
        
        http.csrf(csrf -> csrf.csrfTokenRepository(createCsrfTokenRepository()));
        super.configure(http);
        return http.build();
    }
    
    private CsrfTokenRepository createCsrfTokenRepository() {
        CookieCsrfTokenRepository cookieCsrfTokenRepository = CookieCsrfTokenRepository.withHttpOnlyFalse();
        cookieCsrfTokenRepository.setCookiePath("/");
        return cookieCsrfTokenRepository;
    }

    private Customizer<HeadersConfigurer<HttpSecurity>.FrameOptionsConfig> createFrameOptionCustomizer() {
        if (Arrays.stream(environment.getActiveProfiles()).anyMatch("local"::equalsIgnoreCase)) {
            return HeadersConfigurer.FrameOptionsConfig::disable;
        }
        return HeadersConfigurer.FrameOptionsConfig::sameOrigin;
    }
}

我已查阅官方文档,但未找到Spring Security 6中修改角色前缀的相关内容,恳请各位提供帮助。

内容的提问来源于stack exchange,提问作者Sachin Brar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 15:08:17