You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在现有Spring Boot 3项目中集成Spring for GraphQL时遇到问题

Spring Boot 3集成Spring for GraphQL启动错误排查

一、依赖配置(pom.xml片段)

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-graphql</artifactId>
</dependency>
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-web</artifactId>
</dependency>
<dependency>
    <groupId>org.springframework</groupId>
    <artifactId>spring-webflux</artifactId>
    <scope>test</scope>
</dependency>
<dependency>
  <groupId>org.springframework.graphql</groupId>
  <artifactId>spring-graphql-test</artifactId>
  <scope>test</scope>
</dependency>
<dependency>
  <groupId>org.springframework.boot</groupId>
  <artifactId>spring-boot-starter-security</artifactId>
</dependency>

二、安全配置代码

@Configuration
@EnableWebSecurity
public class WebSecurityConfig {

    @Value("${password:MISSING")
    private String endpointPassword;

    @Autowired
    public void configureGlobal(final AuthenticationManagerBuilder auth) throws Exception {
        auth.inMemoryAuthentication()
                .withUser("user").password(passwordEncoder().encode(endpointPassword))
                .authorities("ROLE_USER");
    }

    @Bean
    SecurityFilterChain filterChain(final HttpSecurity http) throws Exception {
        http.authorizeHttpRequests()
                .requestMatchers("/swagger-ui/**", "/swagger-ui.html").permitAll()
                .requestMatchers("/graphql", "/graphiql", "/vendor/**").permitAll()
                .anyRequest().authenticated().and().httpBasic();

        http.csrf().disable();
        http.headers().xssProtection().disable();
        return http.build();
    }

    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }

}

三、错误堆栈(中文翻译)

启动时触发的核心错误堆栈如下:

org.springframework.beans.factory.BeanCreationException: 创建名为 'webSecurityConfig' 的 Bean 时出错:注入自动依赖项失败
    at org.springframework.beans.factory.annotation.AutowiredAnnotationBeanPostProcessor.postProcessProperties(AutowiredAnnotationBeanPostProcessor.java:410)
    ...(省略非关键堆栈信息)
Caused by: org.springframework.beans.factory.BeanCreationException: 创建名为 'configureGlobal' 的 Bean 时出错:初始化方法调用失败
    at org.springframework.beans.factory.annotation.InitDestroyAnnotationBeanPostProcessor.postProcessBeforeInitialization(InitDestroyAnnotationBeanPostProcessor.java:154)
    ...(省略非关键堆栈信息)
Caused by: java.lang.IllegalArgumentException: 无法解析值 "${password:MISSING" 中的占位符
    at org.springframework.util.PropertyPlaceholderHelper.parseStringValue(PropertyPlaceholderHelper.java:178)
    ...(省略非关键堆栈信息)
Caused by: java.lang.IllegalStateException: 未终止的占位符表达式 "${password:MISSING"
    at org.springframework.util.PropertyPlaceholderHelper.parseStringValue(PropertyPlaceholderHelper.java:162)
    ...(省略非关键堆栈信息)

四、问题分析与解决方案

1. 核心语法错误:@Value表达式未闭合

安全配置中@Value("${password:MISSING")缺少闭合的},导致Spring无法正确解析配置占位符,直接引发启动失败。

修复方法:
修正@Value注解的表达式:

@Value("${password:MISSING}")
private String endpointPassword;

2. Spring Security 3.x配置方式优化(可选)

Spring Boot 3推荐使用UserDetailsService替代AuthenticationManagerBuilder的内存认证配置方式,避免潜在兼容性问题:

优化后的配置示例:

@Configuration
@EnableWebSecurity
public class WebSecurityConfig {

    @Value("${password:MISSING}")
    private String endpointPassword;

    @Bean
    public UserDetailsService userDetailsService() {
        UserDetails user = User.withUsername("user")
                .password(passwordEncoder().encode(endpointPassword))
                .roles("USER")
                .build();
        return new InMemoryUserDetailsManager(user);
    }

    @Bean
    SecurityFilterChain filterChain(final HttpSecurity http) throws Exception {
        http.authorizeHttpRequests()
                .requestMatchers("/swagger-ui/**", "/swagger-ui.html", "/graphql", "/graphiql", "/vendor/**").permitAll()
                .anyRequest().authenticated()
                .and()
                .httpBasic();

        http.csrf().disable();
        http.headers().xssProtection().disable();
        return http.build();
    }

    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }

}

3. 验证GraphQL端点访问权限

确保/graphql、/graphiql等端点在SecurityFilterChain中被正确设置为permitAll(),避免认证拦截影响调试。

内容的提问来源于stack exchange,提问作者user22143675

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 00:55:22