使用oauth2ResourceServer创建securityFilterChain Bean报错求助
问题解决步骤
1. 补充缺失的核心依赖
BearerTokenResolver类属于spring-security-oauth2-resource-server模块,你的pom.xml中缺少这个依赖,这是启动失败的直接原因。需要添加该依赖,且不要手动指定版本,让Spring Boot的依赖管理自动匹配版本:
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-resource-server</artifactId> </dependency>
2. 移除冲突的手动版本指定
你手动指定了spring-security-oauth2-jose的版本6.1.4,这会和Spring Boot自动管理的Spring Security版本产生冲突。Spring Boot的spring-boot-starter-security和spring-boot-starter-oauth2-resource-server已经包含了该依赖,直接删除这段手动指定的依赖即可:
<!-- 删除这一段 --> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-oauth2-jose</artifactId> <version>6.1.4</version> </dependency>
3. 验证依赖版本兼容性
你的spring-xsuaa版本是3.1.3,该版本仅支持Spring Boot 3.x。如果项目使用Spring Boot 2.x,需要将spring-xsuaa降级到2.x系列(比如2.12.11),否则会出现版本兼容问题。
4. 修正SecurityConfig中的过时API(可选但推荐)
如果你的Spring Security版本是6.x,authorizeRequests和antMatchers已被标记为过时,建议替换为新的API:
@Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http.authorizeHttpRequests(authz -> authz .requestMatchers("/welcome").permitAll() .requestMatchers("/user").hasAuthority("Readscratch") .anyRequest().authenticated()) .oauth2ResourceServer(oauth2 -> oauth2.jwt() .jwtAuthenticationConverter(getJwtAuthenticationConverter())); return http.build(); }
完成以上步骤后,重新构建并启动项目,即可解决启动失败的问题。
内容的提问来源于stack exchange,提问作者Ciube
相关产品推荐
相关产品推荐

