You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用oauth2ResourceServer创建securityFilterChain Bean报错求助

问题解决步骤

1. 补充缺失的核心依赖

BearerTokenResolver类属于spring-security-oauth2-resource-server模块,你的pom.xml中缺少这个依赖,这是启动失败的直接原因。需要添加该依赖,且不要手动指定版本,让Spring Boot的依赖管理自动匹配版本:

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-oauth2-resource-server</artifactId>
</dependency>

2. 移除冲突的手动版本指定

你手动指定了spring-security-oauth2-jose的版本6.1.4,这会和Spring Boot自动管理的Spring Security版本产生冲突。Spring Boot的spring-boot-starter-security和spring-boot-starter-oauth2-resource-server已经包含了该依赖,直接删除这段手动指定的依赖即可:

<!-- 删除这一段 -->
<dependency>
    <groupId>org.springframework.security</groupId>
    <artifactId>spring-security-oauth2-jose</artifactId>
    <version>6.1.4</version>
</dependency>

3. 验证依赖版本兼容性

你的spring-xsuaa版本是3.1.3,该版本仅支持Spring Boot 3.x。如果项目使用Spring Boot 2.x,需要将spring-xsuaa降级到2.x系列(比如2.12.11),否则会出现版本兼容问题。

4. 修正SecurityConfig中的过时API(可选但推荐)

如果你的Spring Security版本是6.x,authorizeRequests和antMatchers已被标记为过时,建议替换为新的API:

@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
    http.authorizeHttpRequests(authz -> authz
                    .requestMatchers("/welcome").permitAll()
                    .requestMatchers("/user").hasAuthority("Readscratch")
                    .anyRequest().authenticated())
            .oauth2ResourceServer(oauth2 -> oauth2.jwt()
                    .jwtAuthenticationConverter(getJwtAuthenticationConverter()));
    return http.build();
}

完成以上步骤后,重新构建并启动项目,即可解决启动失败的问题。

内容的提问来源于stack exchange,提问作者Ciube

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 10:55:21