You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot中使用@EnableWebFluxSecurity注解启动报错:HttpSecurity Bean缺失问题咨询

解决Spring Boot中@EnableWebFluxSecurity启动报错的问题

你的问题核心是Servlet和WebFlux环境的Security自动配置冲突了,让我一步步帮你理清原因并解决:

问题根源分析

从错误日志和你的依赖可以看出:

  • 你引入了spring-boot-starter-webflux(响应式Web框架),但同时又加了spring-boot-starter-jetty(Servlet容器)
  • Spring Boot检测到Servlet容器(Jetty)的存在,会自动启用Servlet环境的Security自动配置(SpringBootWebSecurityConfiguration),这个配置需要依赖Servlet版的HttpSecurity bean
  • 但你用的是WebFlux的@EnableWebFluxSecurity,配置的是响应式的ServerHttpSecurity,两者环境不匹配,导致找不到HttpSecurity bean的报错

另外你后来添加的configure(HttpSecurity)方法是Servlet环境的配置,这反而加剧了冲突,因为WebFlux环境下不需要这个bean。

解决方案

方案1:移除Servlet容器依赖(推荐)

WebFlux默认使用Netty作为嵌入式服务器,不需要Servlet容器。如果你是要搭建纯响应式WebFlux应用,直接移除Jetty依赖:

<!-- 移除这个依赖 -->
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-jetty</artifactId>
</dependency>

然后保留你的WebFlux Security配置类即可:

@Configuration
@EnableWebFluxSecurity
open class ArticleWebSecurityConfig {
    @Bean
    open fun springSecurityFilterChain(http: ServerHttpSecurity): SecurityWebFilterChain = http
        .csrf().disable()
        .authorizeExchange()
        .anyExchange()
        .permitAll()
        .and()
        .build()
}

方案2:强制使用WebFlux环境(如果必须保留Jetty)

如果你因为某些原因需要保留Jetty(比如要在Servlet容器中运行WebFlux),需要明确告诉Spring Boot以WebFlux环境启动,同时排除Servlet的Security自动配置:

  1. 在启动类上添加@EnableWebFlux并排除Servlet Security自动配置:
@SpringBootApplication(exclude = [SpringBootWebSecurityConfiguration::class])
@EnableWebFlux
open class YourApplication

fun main(args: Array<String>) {
    runApplication<YourApplication>(*args)
}
  1. 确保只保留你的WebFlux Security配置类,删除之前添加的configure(HttpSecurity)方法。

方案3:切换到Servlet环境(如果不需要WebFlux)

如果你的应用其实不需要响应式WebFlux,只是误引入了依赖,可以把spring-boot-starter-webflux换成spring-boot-starter-web,然后使用Servlet版的Security配置:

<!-- 替换webflux为web -->
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-web</artifactId>
</dependency>

对应的Security配置改为:

@Configuration
@EnableWebSecurity
open class ArticleWebSecurityConfig {
    @Bean
    open fun configure(http: HttpSecurity): SecurityFilterChain {
        http
            .csrf().disable()
            .authorizeRequests()
            .anyRequest().permitAll()
        return http.build()
    }
}

验证

选好方案后,删除多余的配置代码,重新启动应用,应该就能正常启动了。

内容的提问来源于stack exchange,提问作者mahan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 02:42:35