You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot循环引用及AuthenticationManagerBuilder缺失问题求助

Spring Boot Security配置问题解决方案

问题1:循环引用错误

报错信息:

org.springframework.beans.factory.BeanCurrentlyInCreationException: Error creating bean with name 'securityConfig': Requested bean is currently in creation: Is there an unresolvable circular reference?

问题原因

你的configureGlobal方法直接调用了bCryptPasswordEncoder()这个@Bean注解的方法,Spring创建SecurityConfig Bean的过程中,会尝试生成BCryptPasswordEncoder,但此时SecurityConfig本身还未完成创建,进而触发循环依赖。另外,旧版的configureGlobal配置方式和新版本Spring Security的自动配置逻辑存在冲突。

修复方案

修改SecurityConfig,移除configureGlobal方法,改用Spring Security推荐的配置方式——通过构造方法注入UserService和PasswordEncoder,让Spring自动处理认证逻辑:

package com.example.demo.config;

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.util.matcher.AntPathRequestMatcher;
import com.example.demo.service.UserService;

@Configuration
public class SecurityConfig {

    private final UserService userService;
    private final BCryptPasswordEncoder bCryptPasswordEncoder;

    // 构造方法注入,避免字段注入的潜在问题
    public SecurityConfig(UserService userService, BCryptPasswordEncoder bCryptPasswordEncoder) {
        this.userService = userService;
        this.bCryptPasswordEncoder = bCryptPasswordEncoder;
    }

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http
            .authorizeRequests()
                .requestMatchers(new AntPathRequestMatcher("/register")).permitAll()
                .requestMatchers(new AntPathRequestMatcher("/admin/**")).hasRole("ADMIN")
                .anyRequest().authenticated()
            .and()
            .formLogin().loginPage("/login").permitAll()
            .and()
            .logout().permitAll();
        
        // 如需自定义认证逻辑,可添加此行,否则Spring会自动使用注入的UserService和PasswordEncoder
        // http.userDetailsService(userService).passwordEncoder(bCryptPasswordEncoder);
        
        return http.build();
    }

    @Bean
    public BCryptPasswordEncoder bCryptPasswordEncoder() {
        return new BCryptPasswordEncoder();
    }
}

若坚持使用AuthenticationManagerBuilder,可通过HttpSecurity获取实例进行配置,避免直接注入引发的问题:

@Bean
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
    http
        .authorizeRequests()
            .requestMatchers(new AntPathRequestMatcher("/register")).permitAll()
            .requestMatchers(new AntPathRequestMatcher("/admin/**")).hasRole("ADMIN")
            .anyRequest().authenticated()
        .and()
        .formLogin().loginPage("/login").permitAll()
        .and()
        .logout().permitAll();
    
    // 从HttpSecurity中获取AuthenticationManagerBuilder并配置
    AuthenticationManagerBuilder auth = http.getSharedObject(AuthenticationManagerBuilder.class);
    auth.userDetailsService(userService).passwordEncoder(bCryptPasswordEncoder);
    
    return http.build();
}

问题2:排除安全自动配置后找不到AuthenticationManagerBuilder

报错信息:

Parameter 0 of method configureGlobal in com.example.demo.config.SecurityConfig required a bean of type 'org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder' that could not be found.

问题原因

AuthenticationManagerBuilder由Spring Security的SecurityAutoConfiguration自动配置类创建并注入,你排除该类后,容器中不再存在这个Bean,因此触发报错。

修复方案

不要排除SecurityAutoConfiguration和ManagementWebSecurityAutoConfiguration——你自定义的SecurityConfig会被Spring优先加载,与自动配置逻辑兼容,解决第一个问题后无需排除这些类,应用即可正常运行。

若确实需要调整自动配置,不要直接排除核心类,可通过spring.security.enabled=false完全关闭Security(但不符合你的需求),或针对性调整配置参数,而非移除自动配置基础。


内容的提问来源于stack exchange,提问作者Aniket Kumar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 08:29:55