Spring Security中antMatchers已废弃,如何放行静态文件夹与CSS文件?
在最新Spring Security中放行静态资源的正确配置方法
你当前代码里的静态资源路径配置存在问题,../static/css 这类写法不符合Spring Boot静态资源的访问规则——默认情况下,src/main/resources/static 下的资源可直接通过 /css/**、/images/** 这类路径访问,不需要带上static前缀,更不能使用相对路径../。
针对最新版Spring Security(6.x+),antMatchers已被废弃,替代方案是使用requestMatchers,同时有两种主流配置方式:
方法一:通过HttpSecurity放行静态资源
直接在SecurityFilterChain中用requestMatchers匹配静态资源路径并允许匿名访问,修改后的代码如下:
package com.example.config; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.crypto.password.PasswordEncoder; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.util.matcher.AntPathRequestMatcher; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; import com.example.service.CustomUserDetailsService; @Configuration public class SecurityConfig { @Autowired CustomUserDetailsService customUserDetailsServcie; @Bean public static PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http.csrf().disable() .authorizeHttpRequests(auth -> auth // 放行静态资源和指定页面 .requestMatchers("/registration", "/password-request", "/reset-password", "/home", "/css/**", "/images/**") .permitAll() // 其他所有请求需要认证 .anyRequest().authenticated()) .formLogin(form -> form .loginPage("/login") .loginProcessingUrl("/login") .defaultSuccessUrl("/home", true) .permitAll()) .logout(logout -> logout .invalidateHttpSession(true) .clearAuthentication(true) .logoutRequestMatcher(new AntPathRequestMatcher("/logout")) .logoutSuccessUrl("/login?logout") .permitAll()); return http.build(); } public void configureGlobal(AuthenticationManagerBuilder auth) throws Exception { auth.userDetailsService(customUserDetailsServcie).passwordEncoder(passwordEncoder()); } }
方法二:通过WebSecurity忽略静态资源(推荐)
这种方式会让静态资源请求直接绕过Spring Security的过滤器链,性能更优。需要注入WebSecurity并配置忽略规则:
package com.example.config; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.builders.WebSecurity; import org.springframework.security.crypto.password.PasswordEncoder; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.util.matcher.AntPathRequestMatcher; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; import com.example.service.CustomUserDetailsService; @Configuration public class SecurityConfig { @Autowired CustomUserDetailsService customUserDetailsServcie; @Bean public static PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } // 配置WebSecurity忽略静态资源 public void configure(WebSecurity web) throws Exception { web.ignoring() .requestMatchers("/css/**", "/images/**"); } @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http.csrf().disable() .authorizeHttpRequests(auth -> auth .requestMatchers("/registration", "/password-request", "/reset-password", "/home") .permitAll() .anyRequest().authenticated()) .formLogin(form -> form .loginPage("/login") .loginProcessingUrl("/login") .defaultSuccessUrl("/home", true) .permitAll()) .logout(logout -> logout .invalidateHttpSession(true) .clearAuthentication(true) .logoutRequestMatcher(new AntPathRequestMatcher("/logout")) .logoutSuccessUrl("/login?logout") .permitAll()); return http.build(); } public void configureGlobal(AuthenticationManagerBuilder auth) throws Exception { auth.userDetailsService(customUserDetailsServcie).passwordEncoder(passwordEncoder()); } }
关键说明:
- 路径
/css/**表示匹配css目录下的所有文件及子目录资源,/images/**同理。 - 方法二的
web.ignoring()优先级更高,静态资源不会经过任何Spring Security拦截处理,更适合静态资源较多的场景。
内容的提问来源于stack exchange,提问作者Sumit Singh Rawat
相关产品推荐
相关产品推荐

