You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot RabbitMQ反序列化未授权类异常解决求助

Spring Boot集成RabbitMQ反序列化权限问题解决

问题场景

在Spring Boot项目中使用RabbitMQ,发送端与接收端代码如下:

发送端代码

@Component
@AllArgsConstructor
public class UserSender {

    private final RabbitTemplate rabbitTemplate;

    public String send() {
        User user = new User(1L, "Tom", "123");
        rabbitTemplate.convertAndSend("userQueue", user);
        return "user sender sent: " + user;
    }
}

接收端代码

@Component
public class UserReceiver {

    @RabbitListener(queues = "userQueue")
    @RabbitHandler
    private void process(User user) {
        System.out.println("received user: " + user);
    }
}

启动项目时抛出反序列化权限异常:

Caused by: java.lang.SecurityException: Attempt to deserialize unauthorized class com.example.lab06.entity.User; add allowed class name patterns to the message converter or, if you trust the message orginiator, set environment variable 'SPRING_AMQP_DESERIALIZATION_TRUST_ALL' or system property 'spring.amqp.deserialization.trust.all' to true

尝试在application.properties中配置spring.amqp.deserialization.trust.all=true,但IDE提示配置项无法识别:

Cannot resolve configuration property 'spring.amqp.deserialization.trust.all'

解决方案

1. 检查并升级版本

spring.amqp.deserialization.trust.all这个全局配置项是**Spring AMQP 2.3+(对应Spring Boot 2.4+)**版本才新增的。如果你的项目版本低于这个范围,配置项会无法被识别。

  • 若可以升级项目版本,直接在application.properties中添加:
    spring.amqp.deserialization.trust.all=true
    
    也可以通过设置环境变量SPRING_AMQP_DESERIALIZATION_TRUST_ALL=true,或者在启动时添加JVM参数:
    -Dspring.amqp.deserialization.trust.all=true
    

2. 自定义消息转换器(安全推荐)

如果不想全局信任所有类,或者项目版本不支持全局配置,推荐通过自定义Jackson消息转换器,指定允许反序列化的类或包:

创建RabbitMQ配置类:

import org.springframework.amqp.support.converter.Jackson2JsonMessageConverter;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import com.example.lab06.entity.User;

@Configuration
public class RabbitMQConfig {

    @Bean
    public Jackson2JsonMessageConverter jackson2JsonMessageConverter() {
        Jackson2JsonMessageConverter converter = new Jackson2JsonMessageConverter();
        // 方式1:添加单个允许的实体类
        converter.addAllowedList(User.class);
        // 方式2:添加整个包下的类(支持通配符)
        // converter.addAllowedList("com.example.lab06.entity.*");
        return converter;
    }

    @Bean
    public RabbitTemplate rabbitTemplate(ConnectionFactory connectionFactory, Jackson2JsonMessageConverter converter) {
        RabbitTemplate rabbitTemplate = new RabbitTemplate(connectionFactory);
        // 设置自定义的消息转换器
        rabbitTemplate.setMessageConverter(converter);
        return rabbitTemplate;
    }
}

3. 旧版本全局信任方案

如果是Spring AMQP 2.3以下版本,想要全局信任所有类,可以通过设置消息转换器的trustedPackages为*:

@Configuration
public class RabbitMQConfig {

    @Bean
    public Jackson2JsonMessageConverter jackson2JsonMessageConverter() {
        Jackson2JsonMessageConverter converter = new Jackson2JsonMessageConverter();
        // 信任所有包下的类
        converter.setTrustedPackages("*");
        return converter;
    }

    @Bean
    public RabbitTemplate rabbitTemplate(ConnectionFactory connectionFactory, Jackson2JsonMessageConverter converter) {
        RabbitTemplate rabbitTemplate = new RabbitTemplate(connectionFactory);
        rabbitTemplate.setMessageConverter(converter);
        return rabbitTemplate;
    }
}

内容的提问来源于stack exchange,提问作者Mingfei

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 02:23:10