You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 1.5.8中CSRF禁用失效及Basic Auth配置问题解决

Spring Boot 1.5.8 + Spring Security Basic Auth 403 CSRF问题及自定义密码失效解决

问题场景

环境:Spring Boot 1.5.8 + Spring Security
需求:测试Basic Authentication
初始操作:

  • 配置中通过 .csrf().disable() 禁用CSRF
  • 通过 @SpringBootApplication(exclude = SecurityAutoConfiguration.class) 排除自动配置,避免生成默认密码

遇到的问题:

  1. Postman发送带Basic Auth的POST请求返回403,提示:

Invalid CSRF Token 'null' was found on the request parameter '_csrf' or header 'X-CSRF-TOKEN'

  1. 调整配置类继承 WebSecurityConfigurerAdapter 后,CSRF问题解决,但自定义密码验证失效
  2. 最终添加会话管理策略 SessionCreationPolicy.STATELESS 后,配置正常运行

问题分析与解决逻辑

1. 禁用CSRF仍报错的原因

Spring Boot 1.5.x中,若未显式继承 WebSecurityConfigurerAdapter 做自定义配置,仅零散配置CSRF禁用规则,会导致该配置未被Spring Security正确加载,默认的CSRF防护依然生效。

2. 继承WebSecurityConfigurerAdapter后密码失效的原因

继承该类后,Spring Security会启用自定义配置,但默认会话管理是有状态的,Basic Auth在有状态会话模式下,可能出现认证上下文未正确绑定的情况,导致自定义密码验证逻辑无法生效。

3. STATELESS会话策略的作用

设置 SessionCreationPolicy.STATELESS 后,Spring Security不会创建或依赖HTTP会话,每次请求都需要重新完成认证,完全符合Basic Auth的无状态特性,同时确保自定义认证逻辑正常执行。

完整配置代码

1. Spring Boot启动类

@SpringBootApplication(exclude = {SecurityAutoConfiguration.class})
public class BasicAuthDemoApplication {
    public static void main(String[] args) {
        SpringApplication.run(BasicAuthDemoApplication.class, args);
    }
}

2. Spring Security配置类

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
import org.springframework.security.config.http.SessionCreationPolicy;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;

@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        // 示例:内存存储自定义用户,实际可替换为数据库查询逻辑
        auth.inMemoryAuthentication()
                .passwordEncoder(new BCryptPasswordEncoder())
                .withUser("admin")
                .password(new BCryptPasswordEncoder().encode("admin123"))
                .roles("ADMIN");
    }

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
                .csrf().disable() // 明确禁用CSRF
                .authorizeRequests()
                .anyRequest().authenticated() // 所有请求需认证
                .and()
                .httpBasic() // 启用Basic Auth认证方式
                .and()
                .sessionManagement()
                .sessionCreationPolicy(SessionCreationPolicy.STATELESS); // 设置无状态会话
    }
}

pom.xml依赖配置

<parent>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-parent</artifactId>
    <version>1.5.8.RELEASE</version>
    <relativePath/>
</parent>

<dependencies>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-web</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-security</artifactId>
    </dependency>
</dependencies>

内容的提问来源于stack exchange,提问作者Giovanni Grana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 08:12:26