You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security 6自定义过滤器触发403禁止访问错误求助

问题分析:Spring Security 6中Http403ForbiddenEntryPoint报错原因

测试Spring Security 6自定义认证过滤器时,DEBUG日志持续出现Http403ForbiddenEntryPoint - Pre-authenticated entry point called. Rejecting access错误,目前过滤器暂未实现认证逻辑。

访问端点时的日志信息

14:23:02.619 [http-nio-8080-exec-2] INFO  o.s.web.servlet.DispatcherServlet - Completed initialization in 1 ms
14:23:04.923 [http-nio-8080-exec-2] DEBUG o.s.security.web.FilterChainProxy - Securing GET /hello
14:23:04.928 [http-nio-8080-exec-2] DEBUG o.s.s.w.a.AnonymousAuthenticationFilter - Set SecurityContextHolder to anonymous SecurityContext
14:23:04.943 [http-nio-8080-exec-2] DEBUG o.s.s.w.s.HttpSessionRequestCache - Saved request http://localhost:8080/hello?continue to session
14:23:04.943 [http-nio-8080-exec-2] DEBUG o.s.s.w.a.Http403ForbiddenEntryPoint - Pre-authenticated entry point called. Rejecting access
14:23:05.504 [http-nio-8080-exec-2] DEBUG o.s.security.web.FilterChainProxy - Securing GET /error
14:23:05.505 [http-nio-8080-exec-2] DEBUG o.s.s.w.a.AnonymousAuthenticationFilter - Set SecurityContextHolder to anonymous SecurityContext
14:23:05.505 [http-nio-8080-exec-2] DEBUG o.s.s.w.s.HttpSessionRequestCache - Saved request http://localhost:8080/error?continue to session
14:23:05.505 [http-nio-8080-exec-2] DEBUG o.s.s.w.a.Http403ForbiddenEntryPoint - Pre-authenticated entry point called. Rejecting access

相关配置代码

SecurityConfig类

@Configuration
@EnableWebSecurity
public class SecurityConfig
{
    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http.authorizeHttpRequests(authorize -> authorize
                .anyRequest().authenticated()
        );
        return http.build();
    }
}

TestFilter类

@Configuration
public class TestFilter extends GenericFilterBean {
    @Override
    public void doFilter(
            ServletRequest request,
            ServletResponse response,
            FilterChain chain) throws IOException, ServletException {
        System.out.print("::::::::::::::::::::in the test filter::::::::::::::::::::::");
        chain.doFilter(request, response);
    }
}

DemoApplication类

@SpringBootApplication
@RestController
public class DemoApplication {
    public static void main(String[] args) {
        SpringApplication.run(DemoApplication.class, args);
    }
    @GetMapping("/hello")
    public String hello(@RequestParam(value = "name", defaultValue = "World") String name) {
        return String.format("Hello %s!", name);
    }
}

错误原因及修正方案

错误原因

  1. 自定义过滤器未加入Spring Security过滤器链:TestFilter虽然标注了@Configuration,但并未被添加到Spring Security的过滤器链中,导致认证流程完全不经过该过滤器,直接进入匿名认证环节。
  2. 未配置认证入口:SecurityConfig只要求所有请求必须认证,但未指定任何认证方式(如表单登录、HTTP Basic等),Spring Security在无法获取合法认证信息时,默认使用Http403ForbiddenEntryPoint直接拒绝访问,而非引导用户进行认证。

修正步骤

1. 将自定义过滤器加入Spring Security过滤器链

修改SecurityConfig,注入TestFilter并通过addFilterBefore或addFilterAfter将其添加到过滤器链的合适位置,示例如下:

@Configuration
@EnableWebSecurity
public class SecurityConfig
{
    private final TestFilter testFilter;

    // 构造方法注入TestFilter
    public SecurityConfig(TestFilter testFilter) {
        this.testFilter = testFilter;
    }

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http.authorizeHttpRequests(authorize -> authorize
                .anyRequest().authenticated()
        )
        // 将自定义过滤器添加到AnonymousAuthenticationFilter之前
        .addFilterBefore(testFilter, AnonymousAuthenticationFilter.class);
        return http.build();
    }
}

同时将TestFilter的@Configuration改为@Component,使其被Spring容器管理:

@Component
public class TestFilter extends GenericFilterBean {
    @Override
    public void doFilter(
            ServletRequest request,
            ServletResponse response,
            FilterChain chain) throws IOException, ServletException {
        System.out.print("::::::::::::::::::::in the test filter::::::::::::::::::::::");
        chain.doFilter(request, response);
    }
}

2. 配置认证入口(可选)

如果需要在未认证时引导用户完成认证,可以添加表单登录或HTTP Basic认证配置,示例:

@Bean
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
    http.authorizeHttpRequests(authorize -> authorize
            .anyRequest().authenticated()
    )
    .addFilterBefore(testFilter, AnonymousAuthenticationFilter.class)
    // 开启表单登录,允许所有人访问登录页面
    .formLogin(form -> form.permitAll());
    return http.build();
}

内容的提问来源于stack exchange,提问作者Kishore Paila

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 05:07:57