You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security 6 .permitAll()失效:Spring Boot3+Keycloak22鉴权问题

解决Spring Security 6中/auth/**路径permitAll()不生效的问题

问题分析

你配置了requestMatchers("auth/**").permitAll()想让/auth开头的路径绕过认证,但POST请求该路径时仍返回401未授权,核心原因大概率是路径匹配规则不符合Spring Security的要求,也可能伴随CSRF保护的影响。

解决方案

1. 修正路径匹配格式

Spring Security的路径匹配默认基于Servlet上下文,必须以斜杠/开头才能正确匹配请求路径。把"auth/**"改为"/auth/**":

.authorizeHttpRequests(requests -> requests
        .requestMatchers("/auth/**").permitAll()
        .anyRequest().authenticated())

如果需要更精确地指定请求方法(比如仅允许POST请求绕过),可以明确指定:

.requestMatchers(HttpMethod.POST, "/auth/**").permitAll()

2. 排除/auth路径的CSRF保护(可选)

如果后续遇到POST请求返回403的情况,大概率是CSRF保护导致的。可以在CSRF配置中忽略/auth路径:

.csrf(csrf -> csrf
        .csrfTokenRequestHandler(csrfRequestHandler)
        .csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse())
        .ignoringRequestMatchers("/auth/**"))

3. 检查FilterChain优先级(若存在多个配置)

如果项目中有多个SecurityFilterChain Bean,需要确保当前配置的优先级更高,避免请求被其他FilterChain拦截。可以通过@Order注解指定:

@Bean
@Order(1) // 数值越小优先级越高
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
    // 你的配置代码
}

4. 确认应用上下文路径(若有)

如果你的应用配置了server.servlet.context-path(比如/api),那么实际请求路径会是/api/auth/xxx,此时需要把requestMatchers改为"/api/auth/**"。

修改后的完整配置示例

@Bean
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
    CsrfTokenRequestAttributeHandler csrfRequestHandler = new CsrfTokenRequestAttributeHandler();
    csrfRequestHandler.setCsrfRequestAttributeName("_csrf");

    return http
            .cors(Customizer.withDefaults())
            .csrf(csrf -> csrf
                    .csrfTokenRequestHandler(csrfRequestHandler)
                    .csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse())
                    .ignoringRequestMatchers("/auth/**"))
            .authorizeHttpRequests(requests -> requests
                    .requestMatchers("/auth/**").permitAll()
                    .anyRequest().authenticated())
            .oauth2ResourceServer(oauth2 -> oauth2
                    .jwt(jwt -> jwt
                            .jwtAuthenticationConverter(grantedAuthoritiesExtractor())))
            .build();
}

内容的提问来源于stack exchange,提问作者Vinicius Finger

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 03:23:33