Spring Security配置匹配含点(.)URL报错,求正确匹配模式
问题解决:Spring Security URL匹配模式修正
你遇到的org.springframework.web.util.pattern.PatternParseException错误,是因为Spring的路径匹配规则不允许**通配符后面再跟其他路径元素——**作为多级路径通配符,要么放在路径末尾(比如/api/**),要么作为独立的路径段存在,所以"/**/Handle"的写法违反了规则。
针对你的需求(仅允许/odata/v4/com.sap.di.remoteHandler.RemoteHandlerServices/Handle,拦截其他所有URL),有两种可行的修正方案:
方案一:精确匹配目标URL(推荐)
直接使用完整的目标路径作为匹配规则,这种方式最精准,不会误匹配其他无关路径:
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { try { http .authorizeHttpRequests(url -> url // 精确匹配需要放行的URL .requestMatchers("/odata/v4/com.sap.di.remoteHandler.RemoteHandlerServices/Handle").authenticated() .anyRequest().denyAll()) .sessionManagement(session -> session .sessionCreationPolicy(SessionCreationPolicy.STATELESS) ) .oauth2ResourceServer(oauth -> oauth .jwt(jwt -> jwt .jwtAuthenticationConverter(getJwtAuthenticationConverter()) ) ) .headers(httpSecurityHeadersConfigurer -> httpSecurityHeadersConfigurer .contentSecurityPolicy(contentSecurityPolicyConfig -> contentSecurityPolicyConfig .policyDirectives(CONTENT_SECURITY_POLICY) ) ); return http.build(); } catch (Exception e) { throw new RuntimeException("Authentication is failed"); } }
方案二:正则匹配所有以/Handle结尾的URL
如果未来需要放行多个类似以/Handle结尾的URL,可以使用正则表达式匹配:
// 需要导入RegexRequestMatcher import org.springframework.security.web.util.matcher.RegexRequestMatcher; public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { try { http .authorizeHttpRequests(url -> url // 正则匹配所有以/Handle结尾的URL .requestMatchers(RegexRequestMatcher.regexMatcher(".*/Handle$")).authenticated() .anyRequest().denyAll()) .sessionManagement(session -> session .sessionCreationPolicy(SessionCreationPolicy.STATELESS) ) .oauth2ResourceServer(oauth -> oauth .jwt(jwt -> jwt .jwtAuthenticationConverter(getJwtAuthenticationConverter()) ) ) .headers(httpSecurityHeadersConfigurer -> httpSecurityHeadersConfigurer .contentSecurityPolicy(contentSecurityPolicyConfig -> contentSecurityPolicyConfig .policyDirectives(CONTENT_SECURITY_POLICY) ) ); return http.build(); } catch (Exception e) { throw new RuntimeException("Authentication is failed"); } }
内容的提问来源于stack exchange,提问作者PDS
相关产品推荐
相关产品推荐

