Spring Boot项目中WebSecurityConfigurerAdapter类找不到的解决方案
问题描述
尝试在Spring Boot 3.1.5项目中使用WebSecurityConfigurerAdapter配置Spring Security时,出现编译错误:
java: cannot find symbol symbol: class WebSecurityConfigurerAdapter location: package org.springframework.security.config.annotation.web.configuration
项目的pom.xml配置:
<?xml version="1.0" encoding="UTF-8"?> <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>3.1.5</version> <relativePath/> <!-- lookup parent from repository --> </parent> <groupId>com.bilolbek</groupId> <artifactId>checkSecurity</artifactId> <version>0.0.1-SNAPSHOT</version> <name>checkSecurity</name> <description>Demo project for Spring Boot</description> <properties> <java.version>17</java.version> </properties> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-thymeleaf</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.thymeleaf.extras</groupId> <artifactId>thymeleaf-extras-springsecurity6</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-test</artifactId> <scope>test</scope> </dependency> </dependencies> <build> <plugins> <plugin> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-maven-plugin</artifactId> <configuration> <image> <builder>paketobuildpacks/builder-jammy-base:latest</builder> </image> </configuration> </plugin> </plugins> </build> </project>
原配置类代码:
package com.bilolbek.checkSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter{ }
根据官方说明:
In Spring Security 5.7.0-M2 we deprecated the WebSecurityConfigurerAdapter, as we encourage users to move towards a component-based security configuration.
曾尝试添加以下无效依赖:
<dependency> <groupid>org.springframework.security</groupid> <artifactid>spring-security-config</artifactid> <version>4.1.3.release</version> </dependency>
解决方案
1. 弃用旧配置方式,改用组件式配置
Spring Security 6.x(Spring Boot 3.x集成版本)已完全移除WebSecurityConfigurerAdapter,需通过定义@Bean的方式配置安全规则。
2. 修改SecurityConfig配置类
示例基础配置如下:
package com.bilolbek.checkSecurity; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.core.userdetails.User; import org.springframework.security.core.userdetails.UserDetails; import org.springframework.security.core.userdetails.UserDetailsService; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; import org.springframework.security.crypto.password.PasswordEncoder; import org.springframework.security.provisioning.InMemoryUserDetailsManager; import org.springframework.security.web.SecurityFilterChain; @Configuration @EnableWebSecurity public class SecurityConfig { // 配置安全过滤链,定义请求授权规则 @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth .requestMatchers("/", "/home").permitAll() // 允许访问公开路径 .anyRequest().authenticated() // 其他请求需认证 ) .formLogin(form -> form .loginPage("/login") // 自定义登录页(可选) .permitAll() ) .logout(logout -> logout .permitAll() ); return http.build(); } // 配置用户信息(示例为内存用户,可替换为数据库查询逻辑) @Bean public UserDetailsService userDetailsService() { UserDetails user = User.withUsername("user") .password(passwordEncoder().encode("password")) .roles("USER") .build(); return new InMemoryUserDetailsManager(user); } // 配置密码编码器 @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } }
3. 移除无效依赖
删除手动添加的spring-security-config 4.1.3.release依赖,Spring Boot父依赖已自动管理Spring Security的版本,低版本依赖会导致版本冲突,无法解决问题。
关键说明
- Spring Security从5.7版本开始弃用
WebSecurityConfigurerAdapter,6.x版本彻底移除该类,转而推荐组件式配置(通过@Bean定义SecurityFilterChain、UserDetailsService等核心组件)。 - Spring Boot 3.x系列集成的是Spring Security 6.x,因此无法找到
WebSecurityConfigurerAdapter类,必须使用新的配置方式。
内容的提问来源于stack exchange,提问作者Bilolbek Rayimov
相关产品推荐
相关产品推荐

