弃用WebSecurityConfigurerAdapter后如何注册多个AuthenticationProvider
不使用WebSecurityConfigurerAdapter注册多个AuthenticationProvider的方案
在Spring Security 5.7+版本中,WebSecurityConfigurerAdapter被弃用,推荐使用基于Bean的配置方式来注册多个AuthenticationProvider,具体有两种常用实现方式:
方式一:直接将AuthenticationProvider注册为Spring Bean
只要把自定义的AuthenticationProvider声明为@Bean,Spring Security会自动将它们纳入全局的AuthenticationManager中,无需额外手动组装:
@Configuration public class SecurityConfig { // 注册OTP认证提供者 @Bean public AuthenticationProvider otpAuthenticationProvider() { OtpAuthenticationProvider provider = new OtpAuthenticationProvider(); // 此处添加provider的配置逻辑,比如绑定用户校验服务等 return provider; } // 注册用户名密码认证提供者 @Bean public AuthenticationProvider usernamePasswordAuthenticationProvider() { DaoAuthenticationProvider provider = new DaoAuthenticationProvider(); provider.setUserDetailsService(userDetailsService()); provider.setPasswordEncoder(passwordEncoder()); return provider; } // 配套的UserDetailsService示例 @Bean public UserDetailsService userDetailsService() { return new InMemoryUserDetailsManager( User.withUsername("user") .password(passwordEncoder().encode("password")) .roles("USER") .build() ); } // 配套的PasswordEncoder示例 @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } // 配置安全过滤链 @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth .anyRequest().authenticated() ) .formLogin(form -> form.permitAll()); // 根据实际需求配置登录方式 return http.build(); } }
方式二:手动构建AuthenticationManager并添加多个Provider
如果需要更精细地控制AuthenticationManager的构建逻辑,可以手动通过AuthenticationManagerBuilder组装多个AuthenticationProvider,再将其注册为Bean:
@Configuration public class SecurityConfig { private final OtpAuthenticationProvider otpAuthenticationProvider; private final UsernamePasswordAuthenticationProvider usernamePasswordAuthenticationProvider; // 构造注入自定义的Provider实例 public SecurityConfig(OtpAuthenticationProvider otpAuthenticationProvider, UsernamePasswordAuthenticationProvider usernamePasswordAuthenticationProvider) { this.otpAuthenticationProvider = otpAuthenticationProvider; this.usernamePasswordAuthenticationProvider = usernamePasswordAuthenticationProvider; } // 手动构建AuthenticationManager @Bean public AuthenticationManager authenticationManager(AuthenticationManagerBuilder authBuilder) throws Exception { authBuilder .authenticationProvider(otpAuthenticationProvider) .authenticationProvider(usernamePasswordAuthenticationProvider); return authBuilder.build(); } // 在安全过滤链中指定使用自定义的AuthenticationManager @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http, AuthenticationManager authenticationManager) throws Exception { http .authorizeHttpRequests(auth -> auth .anyRequest().authenticated() ) .authenticationManager(authenticationManager) // 关联自定义的AuthenticationManager .formLogin(form -> form.permitAll()); return http.build(); } }
补充说明
- 方式一适用于大多数常规场景,Spring Security会自动完成Provider的收集和管理;
- 方式二更适合需要自定义
AuthenticationManager其他配置(比如设置父级Manager、调整认证逻辑顺序)的场景; - 两种方式中,
SecurityFilterChain是核心配置节点,用于定义请求授权规则、登录方式等安全策略。
内容的提问来源于stack exchange,提问作者Ali Shirvani
相关产品推荐
相关产品推荐

