配置Spring Security permitAll后访问h2-console仍报403的排查与解决
Spring Security配置:H2控制台访问403问题解决
我配置了以下Spring Security代码:
@Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http.authorizeHttpRequests((authz) -> authz .requestMatchers("/actuator/**").permitAll() .requestMatchers("/h2-console/**").permitAll() .anyRequest().authenticated() ); http.csrf(AbstractHttpConfigurer::disable); http.headers((headers) -> headers .frameOptions((frame) -> frame .disable() ) ); return http.build(); }
但访问h2-console端点时收到403错误:
curl -v http://localhost:8080/h2-console * Trying 127.0.0.1:8080... * Connected to localhost (127.0.0.1) port 8080 (#0) ... * Mark bundle as not supporting multiuse < HTTP/1.1 403
如果将.anyRequest().authenticated()修改为.anyRequest().permitAll(),功能完全正常。现在需要调整配置,让h2-console及其所有子路径可访问,其他路径均需认证。
更新
根据建议尝试了以下配置:
@Configuration public class AppConfig { private static RequestMatcher h2ConsoleRequestMatcher() { return new RequestMatcher() { @Override public boolean matches(HttpServletRequest request) { String path = request.getServletPath(); return path.startsWith("/h2-console"); } }; } @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { // TODO: 2021-10-13 - remove permitAll() and add proper security http.authorizeHttpRequests((authz) -> authz .requestMatchers("/actuator/**").permitAll() .requestMatchers("/h2-console/**").permitAll() .anyRequest().authenticated() ); http.csrf((csrf) -> csrf.ignoringRequestMatchers(h2ConsoleRequestMatcher()) .csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse()) ); http.headers((headers) -> headers .frameOptions( HeadersConfigurer.FrameOptionsConfig::disable ) ); return http.build(); } @Bean public FilterRegistrationBean<CorsFilter> corsFilter() { CorsConfiguration corsConfig = new CorsConfiguration(); corsConfig.setAllowCredentials(true); corsConfig.addAllowedOrigin("http://localhost:3000"); corsConfig.addAllowedHeader("*"); corsConfig.addAllowedMethod("*"); UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource(); source.registerCorsConfiguration("/**", corsConfig); FilterRegistrationBean<CorsFilter> bean = new FilterRegistrationBean<>(new CorsFilter(source)); bean.setOrder(0); return bean; } }
但仍收到403错误:
curl http://localhost:8080/h2-console -v * Trying 127.0.0.1:8080... * Connected to localhost (127.0.0.1) port 8080 (#0) > GET /h2-console HTTP/1.1 > Host: localhost:8080 > User-Agent: curl/7.87.0 > Accept: */* > * Mark bundle as not supporting multiuse < HTTP/1.1 403
最终可用配置
感谢采纳的答案,以下是调整后可正常运行的版本:
@Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http.authorizeHttpRequests((authz) -> authz .requestMatchers(new AntPathRequestMatcher("/actuator/**")).permitAll() .requestMatchers(new AntPathRequestMatcher("/h2-console/**")).permitAll() .anyRequest().authenticated() ); http.csrf((csrf) -> csrf.ignoringRequestMatchers(new AntPathRequestMatcher("/h2-console/**")) .csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse()) ); http.headers((headers) -> headers .frameOptions( HeadersConfigurer.FrameOptionsConfig::disable ) ); return http.build(); }
内容的提问来源于stack exchange,提问作者Jackie
相关产品推荐
相关产品推荐

