Spring Security自定义Header请求匹配器不生效问题咨询
Hey there! Let's figure out why your Spring Security setup isn't blocking requests without the valid my-token header.
First, let's break down the issues in your current code:
1. Your configuration logic is incomplete
Right now, your code tells Spring Security: "Any request that matches CustomHeaderRequestMatcher is allowed" — but you never specified what should happen to requests that don't match this rule. By default, if no explicit rule matches a request, Spring Security will allow it to pass through, which explains why unauthenticated requests are still getting through.
2. Incorrect method annotation
Your configure(HttpSecurity) method uses @Autowired, which is wrong. This method should be an override of the protected method from WebSecurityConfigurerAdapter — using @Autowired here might lead to unexpected behavior (even though you said the matcher is being called, it's not the correct way to hook into Spring Security's configuration flow).
Fixes to get this working correctly
Let's adjust your code to enforce the rule that only requests with a valid my-token: abc header are allowed, and all others are blocked.
Option 1: Explicitly deny non-matching requests
First, fix the configure method to override the parent class method, then add a rule to deny all requests that don't match your header check:
@Configuration @EnableWebSecurity public class AppSecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http.authorizeRequests() // Allow requests that pass your header check .requestMatchers(new CustomHeaderRequestMatcher()).permitAll() // Deny EVERYTHING else .anyRequest().denyAll(); } }
Option 2: Use SpEL for a cleaner approach (recommended)
This approach uses Spring Expression Language (SpEL) to directly validate every request against your matcher. First, register your CustomHeaderRequestMatcher as a Spring bean:
@Configuration @EnableWebSecurity public class AppSecurityConfig extends WebSecurityConfigurerAdapter { // Register your matcher as a bean @Bean public CustomHeaderRequestMatcher customHeaderRequestMatcher() { return new CustomHeaderRequestMatcher(); } @Override protected void configure(HttpSecurity http) throws Exception { http.authorizeRequests() // Require all requests to pass the matcher's check .anyRequest().access("@customHeaderRequestMatcher.matches(request)"); } }
This way, every incoming request will be checked against your matches method — if it returns true, access is granted; if false, access is denied.
Why your original code didn't work
Your initial setup only whitelisted requests that matched your header rule, but left all other requests unregulated. Spring Security's rule evaluation stops at the first matching rule, so if a request doesn't hit your requestMatchers rule, there's no other rule to block it. By adding .anyRequest().denyAll() (or using the SpEL approach), you ensure that no request slips through the cracks unless it meets your header requirement.
内容的提问来源于stack exchange,提问作者Amby

