You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SpringBoot Security配置报错:PatternParseException问题求助

问题分析与解决

错误原因

报错org.springframework.web.util.pattern.PatternParseException: No more pattern data allowed after {*...} or ** pattern element的直接原因是requestMatchers("**/auth/**")使用了非法的路径匹配模式。

Spring路径匹配规则规定:**(匹配任意层级目录)作为模式元素时,其后不能追加任何其他路径内容。**/auth/**中第一个**后还跟着/auth/**,违反了该规则,导致路径模式解析失败,触发500错误。

修正方案

根据你的需求(放行所有/auth相关接口),将路径模式修改为以下正确写法之一:

1. 匹配所有以/auth开头的路径(常规场景)

适用于/auth/login、/auth/register这类以/auth为根路径的接口:

.requestMatchers("/auth/**")

2. 匹配任意位置包含/auth的路径

适用于/api/auth/token、/admin/auth/verify这类中间包含/auth的接口:

.requestMatchers("/**/auth/**")

修正后的SecurityFilterChain代码

@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {

    http
            .csrf().disable()
            .authorizeRequests()
            // 替换为正确的路径模式
            .requestMatchers("/auth/**")
            .permitAll()
            .anyRequest()
            .authenticated()
            .and()
            .sessionManagement()
            .sessionCreationPolicy(SessionCreationPolicy.STATELESS)
            .and()
            .authenticationProvider(authenticationProvider())
            .addFilterBefore(jwtAuthFilter,  UsernamePasswordAuthenticationFilter.class);

    return http.build();
}

额外验证项

  • 确认JwtAuthFilter已正确实现并注入,避免过滤器逻辑异常
  • 检查UserDao.findUserByEmail(email)能正常返回UserDetails实例,无查询失败或空指针问题
  • 确保用户注册时密码已通过BCryptPasswordEncoder加密,避免认证时密码匹配失败

内容的提问来源于stack exchange,提问作者RajMazing

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 14:53:12