You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security自定义Header请求匹配器不生效问题咨询

Hey there! Let's figure out why your Spring Security setup isn't blocking requests without the valid my-token header.

First, let's break down the issues in your current code:

1. Your configuration logic is incomplete

Right now, your code tells Spring Security: "Any request that matches CustomHeaderRequestMatcher is allowed" — but you never specified what should happen to requests that don't match this rule. By default, if no explicit rule matches a request, Spring Security will allow it to pass through, which explains why unauthenticated requests are still getting through.

2. Incorrect method annotation

Your configure(HttpSecurity) method uses @Autowired, which is wrong. This method should be an override of the protected method from WebSecurityConfigurerAdapter — using @Autowired here might lead to unexpected behavior (even though you said the matcher is being called, it's not the correct way to hook into Spring Security's configuration flow).


Fixes to get this working correctly

Let's adjust your code to enforce the rule that only requests with a valid my-token: abc header are allowed, and all others are blocked.

Option 1: Explicitly deny non-matching requests

First, fix the configure method to override the parent class method, then add a rule to deny all requests that don't match your header check:

@Configuration
@EnableWebSecurity
public class AppSecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.authorizeRequests()
            // Allow requests that pass your header check
            .requestMatchers(new CustomHeaderRequestMatcher()).permitAll()
            // Deny EVERYTHING else
            .anyRequest().denyAll();
    }
}

Option 2: Use SpEL for a cleaner approach (recommended)

This approach uses Spring Expression Language (SpEL) to directly validate every request against your matcher. First, register your CustomHeaderRequestMatcher as a Spring bean:

@Configuration
@EnableWebSecurity
public class AppSecurityConfig extends WebSecurityConfigurerAdapter {

    // Register your matcher as a bean
    @Bean
    public CustomHeaderRequestMatcher customHeaderRequestMatcher() {
        return new CustomHeaderRequestMatcher();
    }

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.authorizeRequests()
            // Require all requests to pass the matcher's check
            .anyRequest().access("@customHeaderRequestMatcher.matches(request)");
    }
}

This way, every incoming request will be checked against your matches method — if it returns true, access is granted; if false, access is denied.


Why your original code didn't work

Your initial setup only whitelisted requests that matched your header rule, but left all other requests unregulated. Spring Security's rule evaluation stops at the first matching rule, so if a request doesn't hit your requestMatchers rule, there's no other rule to block it. By adding .anyRequest().denyAll() (or using the SpEL approach), you ensure that no request slips through the cracks unless it meets your header requirement.

内容的提问来源于stack exchange,提问作者Amby

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 09:57:30