You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot整合Spring Security启动报错求助:Autowired依赖注入失败

问题解决:Spring Boot整合Spring Security启动时Autowired注入失败

核心错误原因

从错误堆栈可见,根本问题是版本不兼容:

  • 你使用的Spring Boot版本为3.1.5(基于Jakarta EE规范,Servlet API包名为jakarta.servlet)
  • 但搭配的Spring Security版本是5.7.9(基于旧Java EE规范,Servlet API包名为javax.servlet)

两者依赖的Servlet API包名不匹配,导致WebSecurity类无法实现Jakarta版本的ServletContextAware接口方法,触发AbstractMethodError,进而引发Bean创建失败。

解决方案

1. 统一依赖版本

移除单独指定的Spring Security版本依赖,直接使用Spring Boot提供的spring-boot-starter-security,它会自动匹配与当前Spring Boot版本兼容的Spring Security 6.x版本:

<!-- 替换原有Spring Security依赖 -->
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>

2. 替换废弃的配置方式

Spring Security 6.x已废弃WebSecurityConfigurerAdapter,改用基于SecurityFilterChain Bean的配置方式,修正后的配置类如下:

import jakarta.servlet.http.HttpServletRequest;
import jakarta.servlet.http.HttpServletResponse;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.http.SessionCreationPolicy;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.security.web.AuthenticationEntryPoint;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.http.HttpHeaders;

@Configuration
public class WebSecurityConfiguration {

    @Bean
    public AuthenticationEntryPoint jwtAuthenticationEntryPoint() {
        return (HttpServletRequest request, HttpServletResponse response, AuthenticationException authException) -> {
            response.sendError(HttpServletResponse.SC_UNAUTHORIZED, "Unauthorized");
        };
    }

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http.cors().and().csrf().disable()
                .authorizeHttpRequests(auth -> auth
                        .requestMatchers("/authenticate", "/user/register-new-user").permitAll()
                        .requestMatchers(HttpHeaders.ALLOW).permitAll()
                        .anyRequest().authenticated()
                )
                .exceptionHandling(ex -> ex.authenticationEntryPoint(jwtAuthenticationEntryPoint()))
                .sessionManagement(session -> session.sessionCreationPolicy(SessionCreationPolicy.STATELESS));
        return http.build();
    }

    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }
}

3. 修正认证入口类的API依赖

确保JwtAuthenticationEntryPoint使用Jakarta规范的Servlet API:

import jakarta.servlet.http.HttpServletRequest;
import jakarta.servlet.http.HttpServletResponse;
import org.springframework.security.core.AuthenticationException;
import org.springframework.security.web.AuthenticationEntryPoint;
import java.io.IOException;

public class JwtAuthenticationEntryPoint implements AuthenticationEntryPoint {
    @Override
    public void commence(HttpServletRequest request, HttpServletResponse response,
                         AuthenticationException authException) throws IOException {
        response.sendError(HttpServletResponse.SC_UNAUTHORIZED, "Unauthorized");
    }
}

内容的提问来源于stack exchange,提问作者Gowry Kanth

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 06:25:22