You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security与端口转发配置下静态资源访问403问题排查求助

Got it, let's break down this problem step by step—this sounds like a mix of reverse proxy header handling and incomplete static resource rules in Spring Security, plus some caching quirks causing the randomness. Here's what you need to check and fix:

1. Tell Spring Boot to recognize forwarded requests

Since you're forwarding port 80 to 9090, Spring Boot might not be aware that these are proxied requests, which can throw off Spring Security's context checks (like determining the request's real origin or port).

Add this to your application.properties (or equivalent YAML):

server.forward-headers-strategy=NATIVE

If you're on an older Spring Boot version (<2.2), use server.use-forward-headers=true instead. This lets Spring Boot respect headers like X-Forwarded-For and X-Forwarded-Proto that your proxy (Nginx/iptables) should be sending.

2. Double-check your Spring Security static resource whitelisting

Even though direct 9090 access works, your whitelist might be missing some paths (like favicon.ico or specific image extensions) that only cause issues when proxied. Let's make sure all static assets are explicitly allowed:

For older WebSecurityConfigurerAdapter style:

@Override
public void configure(WebSecurity web) throws Exception {
    web.ignoring()
        // Cover all common static resource paths and extensions
        .antMatchers("/css/**", "/js/**", "/images/**", "/favicon.ico",
                     "/**/*.html", "/**/*.css", "/**/*.js",
                     "/**/*.png", "/**/*.jpg", "/**/*.gif", "/**/*.svg");
}
@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
    http.authorizeHttpRequests(auth -> auth
            // Allow static resources first
            .requestMatchers("/css/**", "/js/**", "/images/**", "/favicon.ico",
                             "/**/*.html", "/**/*.css", "/**/*.js",
                             "/**/*.png", "/**/*.jpg", "/**/*.gif", "/**/*.svg").permitAll()
            // Secure all other requests
            .anyRequest().authenticated()
        )
        // Add your other config (form login, CSRF, etc.) here
        .formLogin(form -> form.permitAll());
    
    return http.build();
}

Don't forget favicon.ico—it's easy to overlook, and missing it will throw a 403 every time. Also, Linux is case-sensitive, so make sure your resource filenames match exactly what's in your code (e.g., Favicon.ico vs favicon.ico are different!).

3. Verify your port forwarding configuration

If you're using Nginx to forward traffic, make sure it's passing the correct headers to Spring Boot. Here's a minimal working Nginx config snippet:

server {
    listen 80;
    server_name your-domain-or-ip;

    location / {
        proxy_pass http://localhost:9090;
        # These headers are critical for Spring to recognize proxied requests
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

If you're using iptables for forwarding, remember that the request's source IP will show as 127.0.0.1 to Spring Boot. If your Security config has IP restrictions, you'll need to whitelist 127.0.0.1:

// Add this to your HttpSecurity config
http.requestMatcher(new IpAddressMatcher("127.0.0.1"));

4. Fix the randomness issue

The inconsistent behavior is almost certainly due to caching—either browser cache holding old 403 responses, or Spring Boot's static resource cache.

  • Force a hard refresh in your browser (Ctrl+Shift+R) to clear local cache.
  • For development, disable Spring's resource cache to rule out stale assets:
spring.web.resources.cache.cachecontrol.no-store=true
spring.web.resources.cache.cachecontrol.no-cache=true

For production, you can set proper cache headers later, but this will help during debugging.

Final Checklist

  1. Enable forwarded header handling in Spring Boot
  2. Whitelist all static resource paths/extensions in Security
  3. Confirm your proxy (Nginx/iptables) passes correct headers
  4. Clear browser/Spring cache and check for filename case issues

This should resolve the 403 errors, including the random ones you're seeing.

内容的提问来源于stack exchange,提问作者Rodrigo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 09:37:44