Spring Boot 3.2.0中localhost访问被拒问题求助
问题描述
- 日志提示:
缓存未命中:请求分发至'/hello'(之前为null)。正在执行MatchableHandlerMapping查找。该信息仅在WARN级别记录一次,在TRACE级别每次都会记录。 - 配置Spring Security白名单
/hello、/register后,访问localhost仍收到**"ACCESS TO LOCALHOST DENIED"**提示,无法实现预期的可访问效果 - 使用Spring Boot 3.2.0,已将所有依赖版本调整为等于或低于该版本
安全配置代码
package com.springsec.springsecurityclient.config; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.WebSecurityConfigurer; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configurers.AbstractHttpConfigurer; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; import org.springframework.security.crypto.password.PasswordEncoder; import org.springframework.security.web.SecurityFilterChain; import org.springframework.web.cors.CorsConfiguration; import org.springframework.web.cors.UrlBasedCorsConfigurationSource; import java.util.Arrays; import static org.springframework.transaction.TransactionDefinition.withDefaults; @Configuration @EnableWebSecurity public class WebSecurityConfig { private static final String[] WHITE_LIST_URLS = { "/hello", "/register" }; @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(11); } @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .cors() .and() .csrf() .disable() .authorizeRequests() .requestMatchers(WHITE_LIST_URLS).permitAll(); return http.build(); }
pom.xml依赖
<?xml version="1.0" encoding="UTF-8"?> <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>3.2.0</version> <relativePath/> <!-- lookup parent from repository --> </parent> <groupId>com.springsec</groupId> <artifactId>spring-security-client</artifactId> <version>0.0.1-SNAPSHOT</version> <name>spring-security-client</name> <description>Demo project for Spring security</description> <properties> <java.version>17</java.version> </properties> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-data-jpa</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>com.mysql</groupId> <artifactId>mysql-connector-j</artifactId> <scope>runtime</scope> </dependency> <dependency> <groupId>org.projectlombok</groupId> <artifactId>lombok</artifactId> <optional>true</optional> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-client</artifactId> </dependency> <dependency> <groupId>org.springframework</groupId> <artifactId>spring-webflux</artifactId> </dependency> <dependency> <groupId>io.projectreactor.netty</groupId> <artifactId>reactor-netty</artifactId> </dependency> <dependency> <groupId>javax.xml.bind</groupId> <artifactId>jaxb-api</artifactId> <version>2.3.0</version> </dependency> <dependency> <groupId>javax.xml.bind</groupId> <artifactId>jaxb-api</artifactId> <version>2.3.1</version> </dependency> <!-- https://mvnrepository.com/artifact/org.javassist/javassist --> <dependency> <groupId>org.javassist</groupId> <artifactId>javassist</artifactId> <version>3.20.0-GA</version> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-config</artifactId> <version>3.2.0.RELEASE</version> </dependency> <dependency> <groupId>javax.servlet</groupId> <artifactId>javax.servlet-api</artifactId> <version>3.1.0</version> <!-- You can adjust the version based on your requirements --> <scope>provided</scope> </dependency> </dependencies> <build> <plugins> <plugin> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-maven-plugin</artifactId> <configuration> <excludes> <exclude> <groupId>org.projectlombok</groupId> <artifactId>lombok</artifactId> </exclude> </excludes> </configuration> </plugin> </plugins> </build> </project>
解决方案
1. 修复SecurityFilterChain配置问题
Spring Boot 3.x对应Spring Security 6.x,authorizeRequests()已过时,且当前配置存在语法不完整、逻辑缺失的问题,修改如下:
@Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .cors(cors -> cors.configurationSource(corsConfigurationSource())) .csrf(AbstractHttpConfigurer::disable) .authorizeHttpRequests(auth -> auth .requestMatchers(WHITE_LIST_URLS).permitAll() .anyRequest().authenticated() ); return http.build(); } // 补充CORS配置Bean,解决跨域访问限制 @Bean public CorsConfigurationSource corsConfigurationSource() { CorsConfiguration configuration = new CorsConfiguration(); configuration.setAllowedOrigins(Arrays.asList("http://localhost:8080")); // 根据实际前端地址调整 configuration.setAllowedMethods(Arrays.asList("GET", "POST", "PUT", "DELETE", "OPTIONS")); configuration.setAllowedHeaders(Arrays.asList("*")); configuration.setAllowCredentials(true); UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource(); source.registerCorsConfiguration("/**", configuration); return source; }
2. 清理pom.xml中的冗余/冲突依赖
- 移除重复的
jaxb-api依赖,保留一个即可(推荐2.3.1版本) - 移除手动添加的
spring-security-config:Spring Boot Starter Security已包含该依赖,手动指定版本会引发冲突 - 移除
javax.servlet-api:Spring Boot Starter Web已兼容当前版本的Servlet API,低版本依赖会导致冲突 - 若未使用WebFlux,可移除
spring-webflux和reactor-netty依赖,减少不必要的包引入
清理后的依赖示例:
<dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-data-jpa</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>com.mysql</groupId> <artifactId>mysql-connector-j</artifactId> <scope>runtime</scope> </dependency> <dependency> <groupId>org.projectlombok</groupId> <artifactId>lombok</artifactId> <optional>true</optional> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-client</artifactId> </dependency> <dependency> <groupId>javax.xml.bind</groupId> <artifactId>jaxb-api</artifactId> <version>2.3.1</version> </dependency> <dependency> <groupId>org.javassist</groupId> <artifactId>javassist</artifactId> <version>3.20.0-GA</version> </dependency> </dependencies>
3. 处理HandlerMapping日志提示
日志中的缓存未命中提示是Spring MVC的正常日志,若要消除WARN级别提示,可在application.properties中调整日志级别:
logging.level.org.springframework.web.servlet.handler.AbstractHandlerMapping=TRACE
该日志不影响功能,仅为Spring查找请求处理器时的调试信息,无需过度关注。
4. 验证修复效果
修改配置后重启项目,访问/hello或/register确认可正常访问;访问其他路径会触发认证逻辑(跳转登录页或返回401),符合预期配置。
内容的提问来源于stack exchange,提问作者Nishanth M
相关产品推荐
相关产品推荐

