Spring Boot 1.5.8中CSRF禁用失效及Basic Auth配置问题解决
Spring Boot 1.5.8 + Spring Security Basic Auth 403 CSRF问题及自定义密码失效解决
问题场景
环境:Spring Boot 1.5.8 + Spring Security
需求:测试Basic Authentication
初始操作:
- 配置中通过
.csrf().disable()禁用CSRF - 通过
@SpringBootApplication(exclude = SecurityAutoConfiguration.class)排除自动配置,避免生成默认密码
遇到的问题:
- Postman发送带Basic Auth的POST请求返回403,提示:
Invalid CSRF Token 'null' was found on the request parameter '_csrf' or header 'X-CSRF-TOKEN'
- 调整配置类继承
WebSecurityConfigurerAdapter后,CSRF问题解决,但自定义密码验证失效 - 最终添加会话管理策略
SessionCreationPolicy.STATELESS后,配置正常运行
问题分析与解决逻辑
1. 禁用CSRF仍报错的原因
Spring Boot 1.5.x中,若未显式继承 WebSecurityConfigurerAdapter 做自定义配置,仅零散配置CSRF禁用规则,会导致该配置未被Spring Security正确加载,默认的CSRF防护依然生效。
2. 继承WebSecurityConfigurerAdapter后密码失效的原因
继承该类后,Spring Security会启用自定义配置,但默认会话管理是有状态的,Basic Auth在有状态会话模式下,可能出现认证上下文未正确绑定的情况,导致自定义密码验证逻辑无法生效。
3. STATELESS会话策略的作用
设置 SessionCreationPolicy.STATELESS 后,Spring Security不会创建或依赖HTTP会话,每次请求都需要重新完成认证,完全符合Basic Auth的无状态特性,同时确保自定义认证逻辑正常执行。
完整配置代码
1. Spring Boot启动类
@SpringBootApplication(exclude = {SecurityAutoConfiguration.class}) public class BasicAuthDemoApplication { public static void main(String[] args) { SpringApplication.run(BasicAuthDemoApplication.class, args); } }
2. Spring Security配置类
import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; import org.springframework.security.config.http.SessionCreationPolicy; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; @Configuration @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(AuthenticationManagerBuilder auth) throws Exception { // 示例:内存存储自定义用户,实际可替换为数据库查询逻辑 auth.inMemoryAuthentication() .passwordEncoder(new BCryptPasswordEncoder()) .withUser("admin") .password(new BCryptPasswordEncoder().encode("admin123")) .roles("ADMIN"); } @Override protected void configure(HttpSecurity http) throws Exception { http .csrf().disable() // 明确禁用CSRF .authorizeRequests() .anyRequest().authenticated() // 所有请求需认证 .and() .httpBasic() // 启用Basic Auth认证方式 .and() .sessionManagement() .sessionCreationPolicy(SessionCreationPolicy.STATELESS); // 设置无状态会话 } }
pom.xml依赖配置
<parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>1.5.8.RELEASE</version> <relativePath/> </parent> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> </dependencies>
内容的提问来源于stack exchange,提问作者Giovanni Grana
相关产品推荐
相关产品推荐

