You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security配置匹配含点(.)URL报错,求正确匹配模式

问题解决:Spring Security URL匹配模式修正

你遇到的org.springframework.web.util.pattern.PatternParseException错误,是因为Spring的路径匹配规则不允许**通配符后面再跟其他路径元素——**作为多级路径通配符,要么放在路径末尾(比如/api/**),要么作为独立的路径段存在,所以"/**/Handle"的写法违反了规则。

针对你的需求(仅允许/odata/v4/com.sap.di.remoteHandler.RemoteHandlerServices/Handle,拦截其他所有URL),有两种可行的修正方案:

方案一:精确匹配目标URL(推荐)

直接使用完整的目标路径作为匹配规则,这种方式最精准,不会误匹配其他无关路径:

public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
    try {
        http
            .authorizeHttpRequests(url -> url
                // 精确匹配需要放行的URL
                .requestMatchers("/odata/v4/com.sap.di.remoteHandler.RemoteHandlerServices/Handle").authenticated()
                .anyRequest().denyAll())
            .sessionManagement(session -> session
                .sessionCreationPolicy(SessionCreationPolicy.STATELESS)
            )
            .oauth2ResourceServer(oauth -> oauth
                .jwt(jwt -> jwt
                    .jwtAuthenticationConverter(getJwtAuthenticationConverter())
                )
            )
            .headers(httpSecurityHeadersConfigurer -> httpSecurityHeadersConfigurer
                .contentSecurityPolicy(contentSecurityPolicyConfig -> contentSecurityPolicyConfig
                    .policyDirectives(CONTENT_SECURITY_POLICY)
                )
            );
        return http.build();
    } catch (Exception e) {
        throw new RuntimeException("Authentication is failed");
    }
}

方案二:正则匹配所有以/Handle结尾的URL

如果未来需要放行多个类似以/Handle结尾的URL,可以使用正则表达式匹配:

// 需要导入RegexRequestMatcher
import org.springframework.security.web.util.matcher.RegexRequestMatcher;

public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
    try {
        http
            .authorizeHttpRequests(url -> url
                // 正则匹配所有以/Handle结尾的URL
                .requestMatchers(RegexRequestMatcher.regexMatcher(".*/Handle$")).authenticated()
                .anyRequest().denyAll())
            .sessionManagement(session -> session
                .sessionCreationPolicy(SessionCreationPolicy.STATELESS)
            )
            .oauth2ResourceServer(oauth -> oauth
                .jwt(jwt -> jwt
                    .jwtAuthenticationConverter(getJwtAuthenticationConverter())
                )
            )
            .headers(httpSecurityHeadersConfigurer -> httpSecurityHeadersConfigurer
                .contentSecurityPolicy(contentSecurityPolicyConfig -> contentSecurityPolicyConfig
                    .policyDirectives(CONTENT_SECURITY_POLICY)
                )
            );
        return http.build();
    } catch (Exception e) {
        throw new RuntimeException("Authentication is failed");
    }
}

内容的提问来源于stack exchange,提问作者PDS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 19:47:14