You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security 6中SecurityFilterChain配置问题及H2控制台无法访问求助

问题描述

我正在使用Spring Boot 3.0.6和Spring Security 6搭建小型项目,原有的WebSecurityConfigurerAdapter已被弃用,需改用SecurityFilterChain。但网上示例用法混乱,antMatchers、mvcMatchers已被弃用,官方文档也缺乏明确指引。当前配置导致H2控制台无法访问,希望获取明确的配置规范,包括Lambda DSL的使用方法。

当前SecurityConfiguration代码

package com.example.myproj.security;

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.authentication.AuthenticationManager;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.util.matcher.AntPathRequestMatcher;

import static org.springframework.security.config.Customizer.withDefaults;

@Configuration
@EnableWebSecurity
public class SecurityConfiguration {

    @Autowired
    private UserDetailsService userDetailsService;

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests()
                .requestMatchers(new AntPathRequestMatcher("/h2-console/**")).permitAll()
                .and() 
            .authorizeHttpRequests()
                .requestMatchers("/users/**")
                .permitAll()
                .and()
            .httpBasic();
        return http.build();
    }
}

application.properties中H2配置

spring.datasource.url=jdbc:h2:mem:testdb
spring.datasource.driverClassName=org.h2.Driver
spring.datasource.username=sa
spring.datasource.password=
spring.jpa.database-platform=org.hibernate.dialect.H2Dialect

pom.xml依赖配置

<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
    <modelVersion>4.0.0</modelVersion>
    <parent>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-parent</artifactId>
        <version>3.0.6</version>
        <relativePath/> <!-- lookup parent from repository -->
    </parent>
    <groupId>com.example</groupId>
    <artifactId>myproj</artifactId>
    <version>0.0.1-SNAPSHOT</version>
    <name>myproj</name>
    <description>Demo project for Spring Boot and Spring Security</description>
    <properties>
        <java.version>17</java.version>
    </properties>
    <dependencies>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-data-jpa</artifactId>
        </dependency>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-security</artifactId>
        </dependency>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-web</artifactId>
        </dependency>

        <dependency>
            <groupId>com.h2database</groupId>
            <artifactId>h2</artifactId>
            <scope>runtime</scope>
        </dependency>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-test</artifactId>
            <scope>test</scope>
        </dependency>
        <dependency>
            <groupId>org.springframework.security</groupId>
            <artifactId>spring-security-test</artifactId>
            <scope>test</scope>
        </dependency>
    </dependencies>

    <build>
        <plugins>
            <plugin>
                <groupId>org.springframework.boot</groupId>
                <artifactId>spring-boot-maven-plugin</artifactId>
            </plugin>
        </plugins>
    </build>

</project>
解决方案

核心问题分析

你的配置存在两个关键问题导致H2控制台无法访问:

  1. 多次调用authorizeHttpRequests()会覆盖之前的权限规则,导致部分配置失效
  2. H2控制台依赖iframe渲染内容,Spring Security默认开启的X-Frame-Options保护会阻止iframe加载

规范的SecurityFilterChain配置(Lambda DSL风格)

以下是符合Spring Security 6规范的配置,同时解决H2控制台访问问题:

package com.example.myproj.security;

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configurers.AbstractHttpConfigurer;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.util.matcher.AntPathRequestMatcher;

@Configuration
@EnableWebSecurity
public class SecurityConfiguration {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            // 禁用CSRF保护(H2控制台表单提交不支持CSRF令牌)
            .csrf(AbstractHttpConfigurer::disable)
            // 禁用X-Frame-Options,允许H2控制台的iframe加载
            .headers(headers -> headers.frameOptions(frame -> frame.disable()))
            // 使用Lambda DSL统一配置权限规则
            .authorizeHttpRequests(auth -> auth
                .requestMatchers(new AntPathRequestMatcher("/h2-console/**")).permitAll()
                .requestMatchers("/users/**").permitAll()
                // 其余所有请求需认证
                .anyRequest().authenticated()
            )
            // 启用HTTP Basic认证
            .httpBasic();

        return http.build();
    }
}

关键配置说明

  • Lambda DSL风格:通过链式调用+Lambda表达式替代传统的.and()拼接,代码结构更清晰,避免配置覆盖问题
  • CSRF禁用:H2控制台的原生表单不支持CSRF令牌,必须禁用该保护才能正常提交操作
  • X-Frame-Options禁用:Spring Security默认设置X-Frame-Options: DENY,会阻止H2控制台的iframe渲染,需显式禁用
  • 统一权限配置:所有路径规则都集中在authorizeHttpRequests()的Lambda参数中,避免多次调用导致的规则覆盖
  • 路径匹配:使用requestMatchers替代已弃用的antMatchers/mvcMatchers,可直接传入路径字符串或AntPathRequestMatcher实例

补充H2控制台启用配置

在application.properties中添加以下配置,确保H2控制台可访问:

# 启用H2控制台
spring.h2.console.enabled=true
# 设置H2控制台访问路径
spring.h2.console.path=/h2-console

内容的提问来源于stack exchange,提问作者anyname

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 01:07:57