You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security 6中WebSecurityConfiguration引发循环依赖问题求助

Spring Security 6 循环依赖问题求助

环境信息

  • 技术栈:Spring Boot + Spring Security 6
  • 开发环境:Spring Tool Suite 4.18.0.RELEASE、Java 17、Ubuntu 22.04
  • 模板引擎:Thymeleaf
  • 打包方式:STS中通过Maven打包为可执行Jar

问题描述

原本打算在SecurityConfiguration.java中使用WebSecurityConfigurerAdapter,但IDE未提供该选项,于是改用WebSecurityConfiguration,结果出现循环依赖问题,依赖循环图如下:

The dependencies of some of the beans in the application context form a cycle:

┌─────┐
|  securityConfiguration (field private org.springframework.security.config.annotation.web.builders.HttpSecurity org.springframework.security.config.annotation.web.configuration.WebSecurityConfiguration.httpSecurity)
↑     ↓
|  org.springframework.security.config.annotation.web.configuration.HttpSecurityConfiguration.httpSecurity defined in class path resource [org/springframework/security/config/annotation/web/configuration/HttpSecurityConfiguration.class]
└─────┘

曾在application.properties中设置spring.main.allow-circular-reference=true作为临时解决方案,但打包为可执行Jar后问题复现。同时SecurityConfiguration需要提供BCryptPasswordEncoder给EmpServiceImpl.java使用,尝试添加@Lazy注解无效,恳请帮助解决。

相关代码

安全配置类 SecurityConfiguration

package com.kastamer.sbtl.config;

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.context.annotation.Lazy;
import org.springframework.context.annotation.PropertySource;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfiguration;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.util.matcher.AntPathRequestMatcher;

import com.kastamer.sbtl.service.EmpService;

@Configuration
@PropertySource(value = "classpath:application.properties")
@EnableWebSecurity
public class SecurityConfiguration extends WebSecurityConfiguration {

//  public EmpService empService;
    
//  @Lazy --> NO EFFECT
    @Bean
    public BCryptPasswordEncoder passwordEncoder() {
        // TODO Auto-generated method stub
        return new BCryptPasswordEncoder();
    }
    
//  @Lazy --> NO EFFECT
    @Bean
    public SecurityFilterChain configure(HttpSecurity http) throws Exception {
        // TODO Auto-generated method stub
        AuthenticationManagerBuilder authManBuild = http.getSharedObject(AuthenticationManagerBuilder.class);
        
        http.authorizeHttpRequests((requests) -> requests.requestMatchers(
                "/registrasi",
                "/js**",
                "/css**",
                "/img**")
                .permitAll().anyRequest().authenticated())
        .formLogin((form) -> form.loginPage("/login").permitAll())
        .logout((logout) -> logout.invalidateHttpSession(true).clearAuthentication(true).logoutRequestMatcher(new AntPathRequestMatcher("/logout")).logoutSuccessUrl("/login?logout").permitAll());
        
        return http.build();
    }
}

服务实现类 EmpServiceImpl

package com.kastamer.sbtl.service;

import java.util.Arrays;
import java.util.Collection;
import java.util.List;
import java.util.Optional;
import java.util.stream.Collectors;

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.annotation.Lazy;
import org.springframework.data.domain.Page;
import org.springframework.data.domain.PageRequest;
import org.springframework.data.domain.Pageable;
import org.springframework.data.domain.Sort;
import org.springframework.security.core.GrantedAuthority;
import org.springframework.security.core.authority.SimpleGrantedAuthority;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UsernameNotFoundException;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.stereotype.Service;

import com.kastamer.sbtl.model.EmpRole;
import com.kastamer.sbtl.model.Employee;
import com.kastamer.sbtl.repository.EmployeeRepository;
import com.kastamer.sbtl.web.dto.EmpRegistrationDTO;

@Service
public class EmpServiceImpl implements EmpService {

    @Autowired
    private EmployeeRepository empRepDAO;
    
    @Autowired
    private BCryptPasswordEncoder passwordEncoder;

    //@Autowired //THIS is ADDITION to AVOID CIRCULAR REFERENCE --> ANNOTATION NO EFFECT
    //public EmpServiceImpl(@Lazy EmployeeRepository empRepDAO) { //ANNOTATION '@Lazy' is ADDITION to AVOID CIRCULAR REFERENCE --> ANNOTATION NO EFFECT
    public EmpServiceImpl(EmployeeRepository empRepDAO) {
        super();
        this.empRepDAO = empRepDAO;
    }

    @Override
    public UserDetails loadUserByUsername(String username) throws UsernameNotFoundException {
        // TODO Auto-generated method stub
        Employee pegawai = empRepDAO.findByEmail(username);
        
        if (pegawai == null) {
            throw new UsernameNotFoundException("Email atau kata sandi tidak cocok!");
        }
        
        return new org.springframework.security.core.userdetails.User(pegawai.getEmail(), pegawai.getPassword(), mapRolesToAuthority(pegawai.getRoles())); //return null;
    }

    @Override
    public Employee save(EmpRegistrationDTO empRegistrationDTO) {
        // TODO Auto-generated method stub
        Employee karyawan = new Employee(
                empRegistrationDTO.getFullName(),
                empRegistrationDTO.getEmail(),
                passwordEncoder.encode(empRegistrationDTO.getPassword()),
                Arrays.asList(new EmpRole("ROLE_USER")));
        
        return empRepDAO.save(karyawan); //return null;
    }

    @Override
    public void simpanPembaruanData(Employee employee) {
        // TODO Auto-generated method stub
        employee.setPassword(passwordEncoder.encode(employee.getPassword()));
        
        this.empRepDAO.save(employee);
    }
    
    private Collection<? extends GrantedAuthority> mapRolesToAuthority(Collection<EmpRole> roles) {
        // TODO Auto-generated method stub
        return roles.stream().map(role -> new SimpleGrantedAuthority(role.getNamaRole())).collect(Collectors.toList());
    }

    //PART POJOK KARYAWAN
    @Override
    public List<Employee> getAllEmployees() {
        // TODO Auto-generated method stub
        return empRepDAO.findAll(); //return null;
    }

    @Override
    public Employee getEmployeeById(long id) {
        // TODO Auto-generated method stub
        Optional<Employee> optEmp = empRepDAO.findById(id);
        Employee empl = null;
        
        if (optEmp.isPresent()) {
            empl = optEmp.get();
        } else {
            throw new RuntimeException("Karyawan dengan emp_id '" + id + "' tidak bisa ditemukan");
        }
        
        return empl; //return null;
    }

    @Override
    public void deleteEmployeeById(long id) {
        // TODO Auto-generated method stub
        this.empRepDAO.deleteById(id);
    }

    @Override
    public Page<Employee> findPaginated(int pageNo, int pageSize, String sortField, String sortAscOrDesc) {
        // TODO Auto-generated method stub
        Sort runut = sortAscOrDesc.equalsIgnoreCase(Sort.Direction.ASC.name()) ? Sort.by(sortField).ascending() : Sort.by(sortField).descending();
        
        Pageable pageable = PageRequest.of(pageNo - 1, pageSize, runut);
        
        return this.empRepDAO.findAll(pageable); //return null;
    }
}

application.properties 配置文件

# DATASOURCE (DataSourceAutoConfiguration & DataSourceProperties)
spring.datasource.url=jdbc:postgresql://localhost:5432/myDB
spring.datasource.username=[POSTGRES_LOGIN]
spring.datasource.password=[POSTGRES_PASSWORD]
spring.datasource.driver-class-name=org.postgresql.Driver

# The PostgreSQL dialect makes Hibernate generate better Postgresql for the chosen databse
spring.jpa.database-platform=org.hibernate.dialect.PostgreSQLDialect

# Hibernate ddl auto (create, create-drop, validate, update, none --> 'default')
spring.jpa.hibernate.ddl-auto=update

# Prepare logging-time system for Spring-Boot engine & will print logs in console (also work as work-level to monitor generated HQL in console)
logging.level.org.hibernate.sql=debug
logging.level.org.hibernate.type=trace
#spring.jpa.show-sql=true

# Default user login and password for spring security web login page (if spring security is enabled)
#spring.security.user.name=spring
#spring.security.user.password=spring123 
#spring.security.user.roles=USER

spring.main.allow-bean-definition-overriding=true
#spring.main.allow-circular-references=true

内容的提问来源于stack exchange,提问作者falah

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 10:27:04