You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security中antMatchers已废弃,如何放行静态文件夹与CSS文件?

在最新Spring Security中放行静态资源的正确配置方法

你当前代码里的静态资源路径配置存在问题,../static/css 这类写法不符合Spring Boot静态资源的访问规则——默认情况下,src/main/resources/static 下的资源可直接通过 /css/**、/images/** 这类路径访问,不需要带上static前缀,更不能使用相对路径../。

针对最新版Spring Security(6.x+),antMatchers已被废弃,替代方案是使用requestMatchers,同时有两种主流配置方式:

方法一:通过HttpSecurity放行静态资源

直接在SecurityFilterChain中用requestMatchers匹配静态资源路径并允许匿名访问,修改后的代码如下:

package com.example.config;

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.util.matcher.AntPathRequestMatcher;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import com.example.service.CustomUserDetailsService;

@Configuration
public class SecurityConfig {

    @Autowired
    CustomUserDetailsService customUserDetailsServcie;

    @Bean
    public static PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http.csrf().disable()
            .authorizeHttpRequests(auth -> auth
                // 放行静态资源和指定页面
                .requestMatchers("/registration", "/password-request", "/reset-password", "/home",
                        "/css/**", "/images/**")
                .permitAll()
                // 其他所有请求需要认证
                .anyRequest().authenticated())
            .formLogin(form -> form
                .loginPage("/login")
                .loginProcessingUrl("/login")
                .defaultSuccessUrl("/home", true)
                .permitAll())
            .logout(logout -> logout
                .invalidateHttpSession(true)
                .clearAuthentication(true)
                .logoutRequestMatcher(new AntPathRequestMatcher("/logout"))
                .logoutSuccessUrl("/login?logout")
                .permitAll());
        
        return http.build();
    }

    public void configureGlobal(AuthenticationManagerBuilder auth) throws Exception {
        auth.userDetailsService(customUserDetailsServcie).passwordEncoder(passwordEncoder());
    }
}

方法二:通过WebSecurity忽略静态资源(推荐)

这种方式会让静态资源请求直接绕过Spring Security的过滤器链,性能更优。需要注入WebSecurity并配置忽略规则:

package com.example.config;

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.builders.WebSecurity;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.util.matcher.AntPathRequestMatcher;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import com.example.service.CustomUserDetailsService;

@Configuration
public class SecurityConfig {

    @Autowired
    CustomUserDetailsService customUserDetailsServcie;

    @Bean
    public static PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }

    // 配置WebSecurity忽略静态资源
    public void configure(WebSecurity web) throws Exception {
        web.ignoring()
           .requestMatchers("/css/**", "/images/**");
    }

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http.csrf().disable()
            .authorizeHttpRequests(auth -> auth
                .requestMatchers("/registration", "/password-request", "/reset-password", "/home")
                .permitAll()
                .anyRequest().authenticated())
            .formLogin(form -> form
                .loginPage("/login")
                .loginProcessingUrl("/login")
                .defaultSuccessUrl("/home", true)
                .permitAll())
            .logout(logout -> logout
                .invalidateHttpSession(true)
                .clearAuthentication(true)
                .logoutRequestMatcher(new AntPathRequestMatcher("/logout"))
                .logoutSuccessUrl("/login?logout")
                .permitAll());
        
        return http.build();
    }

    public void configureGlobal(AuthenticationManagerBuilder auth) throws Exception {
        auth.userDetailsService(customUserDetailsServcie).passwordEncoder(passwordEncoder());
    }
}

关键说明:

  • 路径/css/**表示匹配css目录下的所有文件及子目录资源,/images/**同理。
  • 方法二的web.ignoring()优先级更高,静态资源不会经过任何Spring Security拦截处理,更适合静态资源较多的场景。

内容的提问来源于stack exchange,提问作者Sumit Singh Rawat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 03:11:13