Spring Security与端口转发配置下静态资源访问403问题排查求助
Got it, let's break down this problem step by step—this sounds like a mix of reverse proxy header handling and incomplete static resource rules in Spring Security, plus some caching quirks causing the randomness. Here's what you need to check and fix:
1. Tell Spring Boot to recognize forwarded requests
Since you're forwarding port 80 to 9090, Spring Boot might not be aware that these are proxied requests, which can throw off Spring Security's context checks (like determining the request's real origin or port).
Add this to your application.properties (or equivalent YAML):
server.forward-headers-strategy=NATIVE
If you're on an older Spring Boot version (<2.2), use server.use-forward-headers=true instead. This lets Spring Boot respect headers like X-Forwarded-For and X-Forwarded-Proto that your proxy (Nginx/iptables) should be sending.
2. Double-check your Spring Security static resource whitelisting
Even though direct 9090 access works, your whitelist might be missing some paths (like favicon.ico or specific image extensions) that only cause issues when proxied. Let's make sure all static assets are explicitly allowed:
For older WebSecurityConfigurerAdapter style:
@Override public void configure(WebSecurity web) throws Exception { web.ignoring() // Cover all common static resource paths and extensions .antMatchers("/css/**", "/js/**", "/images/**", "/favicon.ico", "/**/*.html", "/**/*.css", "/**/*.js", "/**/*.png", "/**/*.jpg", "/**/*.gif", "/**/*.svg"); }
For modern SecurityFilterChain (Spring Boot 2.7+ recommended):
@Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http.authorizeHttpRequests(auth -> auth // Allow static resources first .requestMatchers("/css/**", "/js/**", "/images/**", "/favicon.ico", "/**/*.html", "/**/*.css", "/**/*.js", "/**/*.png", "/**/*.jpg", "/**/*.gif", "/**/*.svg").permitAll() // Secure all other requests .anyRequest().authenticated() ) // Add your other config (form login, CSRF, etc.) here .formLogin(form -> form.permitAll()); return http.build(); }
Don't forget favicon.ico—it's easy to overlook, and missing it will throw a 403 every time. Also, Linux is case-sensitive, so make sure your resource filenames match exactly what's in your code (e.g., Favicon.ico vs favicon.ico are different!).
3. Verify your port forwarding configuration
If you're using Nginx to forward traffic, make sure it's passing the correct headers to Spring Boot. Here's a minimal working Nginx config snippet:
server { listen 80; server_name your-domain-or-ip; location / { proxy_pass http://localhost:9090; # These headers are critical for Spring to recognize proxied requests proxy_set_header Host $host; proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header X-Forwarded-Proto $scheme; } }
If you're using iptables for forwarding, remember that the request's source IP will show as 127.0.0.1 to Spring Boot. If your Security config has IP restrictions, you'll need to whitelist 127.0.0.1:
// Add this to your HttpSecurity config http.requestMatcher(new IpAddressMatcher("127.0.0.1"));
4. Fix the randomness issue
The inconsistent behavior is almost certainly due to caching—either browser cache holding old 403 responses, or Spring Boot's static resource cache.
- Force a hard refresh in your browser (Ctrl+Shift+R) to clear local cache.
- For development, disable Spring's resource cache to rule out stale assets:
spring.web.resources.cache.cachecontrol.no-store=true spring.web.resources.cache.cachecontrol.no-cache=true
For production, you can set proper cache headers later, but this will help during debugging.
Final Checklist
- Enable forwarded header handling in Spring Boot
- Whitelist all static resource paths/extensions in Security
- Confirm your proxy (Nginx/iptables) passes correct headers
- Clear browser/Spring cache and check for filename case issues
This should resolve the 403 errors, including the random ones you're seeing.
内容的提问来源于stack exchange,提问作者Rodrigo

