如何配置Spring Boot仅指定端点启用HTTPS,其余用HTTP?
实现方案
要实现仅/receiveFile端点强制HTTPS,其余端点允许HTTP访问,需要分两步操作:同时开启HTTP和HTTPS端口监听,再通过安全规则限制特定端点的访问协议。
1. 配置双端口支持(HTTP + HTTPS)
原配置中server.ssl.enabled=true会强制所有请求走HTTPS,我们需要调整配置并添加代码,让应用同时监听HTTP和HTTPS两个端口。
1.1 更新application.properties配置
保留原SSL配置,新增HTTP端口的配置项:
# HTTP监听端口 server.port=8080 # HTTPS监听端口 server.ssl.port=8443 # 原有SSL配置保持不变 server.ssl.key-store-type=PKCS12 server.ssl.key-store=classpath:keystore/localhost.p12 server.ssl.key-store-password=passwort server.ssl.key-alias=localhost
1.2 添加Tomcat连接器配置类
Spring Boot默认仅支持一个SSL端口,需手动创建配置类注册HTTP的连接器:
import org.apache.catalina.connector.Connector; import org.springframework.boot.web.embedded.tomcat.TomcatServletWebServerFactory; import org.springframework.boot.web.servlet.server.ServletWebServerFactory; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; @Configuration public class HttpHttpsConfig { @Bean public ServletWebServerFactory servletContainer() { TomcatServletWebServerFactory tomcat = new TomcatServletWebServerFactory(); // 注册HTTP端口连接器 tomcat.addAdditionalTomcatConnectors(createHttpConnector()); return tomcat; } private Connector createHttpConnector() { Connector connector = new Connector(TomcatServletWebServerFactory.DEFAULT_PROTOCOL); // 设置HTTP端口,与application.properties中server.port保持一致 connector.setPort(8080); return connector; } }
2. 配置Spring Security强制特定端点走HTTPS
通过Spring Security定义访问规则,限制/receiveFile只能通过HTTPS访问,其余端点允许HTTP或HTTPS。
2.1 添加Spring Security依赖(若未添加)
如果项目尚未引入Spring Security,在Maven的pom.xml中添加依赖:
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency>
2.2 编写安全配置类
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.web.SecurityFilterChain; @Configuration @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth // 根据实际需求调整,这里允许所有端点匿名访问 .anyRequest().permitAll() ) .requiresChannel(channel -> channel // 强制/receiveFile端点只能通过HTTPS访问 .requestMatchers("/receiveFile").requiresSecure() // 其余端点允许HTTP或HTTPS访问 .anyRequest().requiresInsecure() ); return http.build(); } }
测试验证
- 访问
http://localhost:8080/receiveFile会自动重定向到https://localhost:8443/receiveFile - 访问其他端点(如
http://localhost:8080/other)可正常通过HTTP访问,也支持通过https://localhost:8443/other访问
内容的提问来源于stack exchange,提问作者INFORMATIKER IM ALL
相关产品推荐
相关产品推荐

