You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

弃用WebSecurityConfigurerAdapter后如何注册多个AuthenticationProvider

不使用WebSecurityConfigurerAdapter注册多个AuthenticationProvider的方案

在Spring Security 5.7+版本中,WebSecurityConfigurerAdapter被弃用,推荐使用基于Bean的配置方式来注册多个AuthenticationProvider,具体有两种常用实现方式:

方式一:直接将AuthenticationProvider注册为Spring Bean

只要把自定义的AuthenticationProvider声明为@Bean,Spring Security会自动将它们纳入全局的AuthenticationManager中,无需额外手动组装:

@Configuration
public class SecurityConfig {

    // 注册OTP认证提供者
    @Bean
    public AuthenticationProvider otpAuthenticationProvider() {
        OtpAuthenticationProvider provider = new OtpAuthenticationProvider();
        // 此处添加provider的配置逻辑,比如绑定用户校验服务等
        return provider;
    }

    // 注册用户名密码认证提供者
    @Bean
    public AuthenticationProvider usernamePasswordAuthenticationProvider() {
        DaoAuthenticationProvider provider = new DaoAuthenticationProvider();
        provider.setUserDetailsService(userDetailsService());
        provider.setPasswordEncoder(passwordEncoder());
        return provider;
    }

    // 配套的UserDetailsService示例
    @Bean
    public UserDetailsService userDetailsService() {
        return new InMemoryUserDetailsManager(
            User.withUsername("user")
                .password(passwordEncoder().encode("password"))
                .roles("USER")
                .build()
        );
    }

    // 配套的PasswordEncoder示例
    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }

    // 配置安全过滤链
    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .anyRequest().authenticated()
            )
            .formLogin(form -> form.permitAll()); // 根据实际需求配置登录方式

        return http.build();
    }
}

方式二:手动构建AuthenticationManager并添加多个Provider

如果需要更精细地控制AuthenticationManager的构建逻辑,可以手动通过AuthenticationManagerBuilder组装多个AuthenticationProvider,再将其注册为Bean:

@Configuration
public class SecurityConfig {

    private final OtpAuthenticationProvider otpAuthenticationProvider;
    private final UsernamePasswordAuthenticationProvider usernamePasswordAuthenticationProvider;

    // 构造注入自定义的Provider实例
    public SecurityConfig(OtpAuthenticationProvider otpAuthenticationProvider,
                          UsernamePasswordAuthenticationProvider usernamePasswordAuthenticationProvider) {
        this.otpAuthenticationProvider = otpAuthenticationProvider;
        this.usernamePasswordAuthenticationProvider = usernamePasswordAuthenticationProvider;
    }

    // 手动构建AuthenticationManager
    @Bean
    public AuthenticationManager authenticationManager(AuthenticationManagerBuilder authBuilder) throws Exception {
        authBuilder
            .authenticationProvider(otpAuthenticationProvider)
            .authenticationProvider(usernamePasswordAuthenticationProvider);
        return authBuilder.build();
    }

    // 在安全过滤链中指定使用自定义的AuthenticationManager
    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http, AuthenticationManager authenticationManager) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .anyRequest().authenticated()
            )
            .authenticationManager(authenticationManager) // 关联自定义的AuthenticationManager
            .formLogin(form -> form.permitAll());

        return http.build();
    }
}

补充说明

  • 方式一适用于大多数常规场景,Spring Security会自动完成Provider的收集和管理;
  • 方式二更适合需要自定义AuthenticationManager其他配置(比如设置父级Manager、调整认证逻辑顺序)的场景;
  • 两种方式中,SecurityFilterChain是核心配置节点,用于定义请求授权规则、登录方式等安全策略。

内容的提问来源于stack exchange,提问作者Ali Shirvani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 07:57:22