Spring Security 6自定义过滤器触发403禁止访问错误求助
问题分析:Spring Security 6中Http403ForbiddenEntryPoint报错原因
测试Spring Security 6自定义认证过滤器时,DEBUG日志持续出现Http403ForbiddenEntryPoint - Pre-authenticated entry point called. Rejecting access错误,目前过滤器暂未实现认证逻辑。
访问端点时的日志信息
14:23:02.619 [http-nio-8080-exec-2] INFO o.s.web.servlet.DispatcherServlet - Completed initialization in 1 ms 14:23:04.923 [http-nio-8080-exec-2] DEBUG o.s.security.web.FilterChainProxy - Securing GET /hello 14:23:04.928 [http-nio-8080-exec-2] DEBUG o.s.s.w.a.AnonymousAuthenticationFilter - Set SecurityContextHolder to anonymous SecurityContext 14:23:04.943 [http-nio-8080-exec-2] DEBUG o.s.s.w.s.HttpSessionRequestCache - Saved request http://localhost:8080/hello?continue to session 14:23:04.943 [http-nio-8080-exec-2] DEBUG o.s.s.w.a.Http403ForbiddenEntryPoint - Pre-authenticated entry point called. Rejecting access 14:23:05.504 [http-nio-8080-exec-2] DEBUG o.s.security.web.FilterChainProxy - Securing GET /error 14:23:05.505 [http-nio-8080-exec-2] DEBUG o.s.s.w.a.AnonymousAuthenticationFilter - Set SecurityContextHolder to anonymous SecurityContext 14:23:05.505 [http-nio-8080-exec-2] DEBUG o.s.s.w.s.HttpSessionRequestCache - Saved request http://localhost:8080/error?continue to session 14:23:05.505 [http-nio-8080-exec-2] DEBUG o.s.s.w.a.Http403ForbiddenEntryPoint - Pre-authenticated entry point called. Rejecting access
相关配置代码
SecurityConfig类
@Configuration @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http.authorizeHttpRequests(authorize -> authorize .anyRequest().authenticated() ); return http.build(); } }
TestFilter类
@Configuration public class TestFilter extends GenericFilterBean { @Override public void doFilter( ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException { System.out.print("::::::::::::::::::::in the test filter::::::::::::::::::::::"); chain.doFilter(request, response); } }
DemoApplication类
@SpringBootApplication @RestController public class DemoApplication { public static void main(String[] args) { SpringApplication.run(DemoApplication.class, args); } @GetMapping("/hello") public String hello(@RequestParam(value = "name", defaultValue = "World") String name) { return String.format("Hello %s!", name); } }
错误原因及修正方案
错误原因
- 自定义过滤器未加入Spring Security过滤器链:TestFilter虽然标注了
@Configuration,但并未被添加到Spring Security的过滤器链中,导致认证流程完全不经过该过滤器,直接进入匿名认证环节。 - 未配置认证入口:SecurityConfig只要求所有请求必须认证,但未指定任何认证方式(如表单登录、HTTP Basic等),Spring Security在无法获取合法认证信息时,默认使用
Http403ForbiddenEntryPoint直接拒绝访问,而非引导用户进行认证。
修正步骤
1. 将自定义过滤器加入Spring Security过滤器链
修改SecurityConfig,注入TestFilter并通过addFilterBefore或addFilterAfter将其添加到过滤器链的合适位置,示例如下:
@Configuration @EnableWebSecurity public class SecurityConfig { private final TestFilter testFilter; // 构造方法注入TestFilter public SecurityConfig(TestFilter testFilter) { this.testFilter = testFilter; } @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http.authorizeHttpRequests(authorize -> authorize .anyRequest().authenticated() ) // 将自定义过滤器添加到AnonymousAuthenticationFilter之前 .addFilterBefore(testFilter, AnonymousAuthenticationFilter.class); return http.build(); } }
同时将TestFilter的@Configuration改为@Component,使其被Spring容器管理:
@Component public class TestFilter extends GenericFilterBean { @Override public void doFilter( ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException { System.out.print("::::::::::::::::::::in the test filter::::::::::::::::::::::"); chain.doFilter(request, response); } }
2. 配置认证入口(可选)
如果需要在未认证时引导用户完成认证,可以添加表单登录或HTTP Basic认证配置,示例:
@Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http.authorizeHttpRequests(authorize -> authorize .anyRequest().authenticated() ) .addFilterBefore(testFilter, AnonymousAuthenticationFilter.class) // 开启表单登录,允许所有人访问登录页面 .formLogin(form -> form.permitAll()); return http.build(); }
内容的提问来源于stack exchange,提问作者Kishore Paila
相关产品推荐
相关产品推荐

