You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

迁移至Spring Boot 3/Spring 6后Spring配置失效问题求助

Spring Boot 3/Spring 6 迁移后安全配置类失效的解决方案

一、Web安全过滤器链配置失效

你代码里用的antMatchers()在Spring 6 中已被彻底废弃,属于过时API,不会再生效,必须替换为requestMatchers()。

修改后的代码:

@EnableWebSecurity
public class ClientSecurityConfig {

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http.authorizeHttpRequests(authorize -> authorize.requestMatchers("/any-endpoint").permitAll()
                .anyRequest().authenticated())
            .oauth2Login()
            .and()
            .logout().logoutSuccessUrl("/");
        return http.build();
    }
}

Spring 6 对请求匹配逻辑做了统一规范,antMatchers()、mvcMatchers()这类旧匹配器都被整合到requestMatchers()中,继续用旧API会导致权限规则完全不生效。

二、方法安全配置失效

原@EnableGlobalMethodSecurity注解在Spring 6 中已被标记为废弃,必须替换为@EnableMethodSecurity,否则方法级别的安全注解(比如@PreAuthorize、@Secured)都不会生效。

修改后的代码:

@EnableMethodSecurity(prePostEnabled = true, securedEnabled = true, jsr250Enabled = true)
public class WebSecurityConfig {
}

@EnableMethodSecurity是Spring 6 官方推荐的方法安全启用注解,完全兼容原注解的所有参数配置,直接替换即可恢复功能。

内容的提问来源于stack exchange,提问作者Gerardo Roza

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 19:47:12