Spring Security 6中SecurityFilterChain配置问题及H2控制台无法访问求助
问题描述
我正在使用Spring Boot 3.0.6和Spring Security 6搭建小型项目,原有的WebSecurityConfigurerAdapter已被弃用,需改用SecurityFilterChain。但网上示例用法混乱,antMatchers、mvcMatchers已被弃用,官方文档也缺乏明确指引。当前配置导致H2控制台无法访问,希望获取明确的配置规范,包括Lambda DSL的使用方法。
当前SecurityConfiguration代码
package com.example.myproj.security; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.authentication.AuthenticationManager; import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.core.userdetails.UserDetailsService; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.util.matcher.AntPathRequestMatcher; import static org.springframework.security.config.Customizer.withDefaults; @Configuration @EnableWebSecurity public class SecurityConfiguration { @Autowired private UserDetailsService userDetailsService; @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests() .requestMatchers(new AntPathRequestMatcher("/h2-console/**")).permitAll() .and() .authorizeHttpRequests() .requestMatchers("/users/**") .permitAll() .and() .httpBasic(); return http.build(); } }
application.properties中H2配置
spring.datasource.url=jdbc:h2:mem:testdb spring.datasource.driverClassName=org.h2.Driver spring.datasource.username=sa spring.datasource.password= spring.jpa.database-platform=org.hibernate.dialect.H2Dialect
pom.xml依赖配置
<?xml version="1.0" encoding="UTF-8"?> <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>3.0.6</version> <relativePath/> <!-- lookup parent from repository --> </parent> <groupId>com.example</groupId> <artifactId>myproj</artifactId> <version>0.0.1-SNAPSHOT</version> <name>myproj</name> <description>Demo project for Spring Boot and Spring Security</description> <properties> <java.version>17</java.version> </properties> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-data-jpa</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>com.h2database</groupId> <artifactId>h2</artifactId> <scope>runtime</scope> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-test</artifactId> <scope>test</scope> </dependency> </dependencies> <build> <plugins> <plugin> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-maven-plugin</artifactId> </plugin> </plugins> </build> </project>
解决方案
核心问题分析
你的配置存在两个关键问题导致H2控制台无法访问:
- 多次调用
authorizeHttpRequests()会覆盖之前的权限规则,导致部分配置失效 - H2控制台依赖iframe渲染内容,Spring Security默认开启的X-Frame-Options保护会阻止iframe加载
规范的SecurityFilterChain配置(Lambda DSL风格)
以下是符合Spring Security 6规范的配置,同时解决H2控制台访问问题:
package com.example.myproj.security; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configurers.AbstractHttpConfigurer; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.util.matcher.AntPathRequestMatcher; @Configuration @EnableWebSecurity public class SecurityConfiguration { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http // 禁用CSRF保护(H2控制台表单提交不支持CSRF令牌) .csrf(AbstractHttpConfigurer::disable) // 禁用X-Frame-Options,允许H2控制台的iframe加载 .headers(headers -> headers.frameOptions(frame -> frame.disable())) // 使用Lambda DSL统一配置权限规则 .authorizeHttpRequests(auth -> auth .requestMatchers(new AntPathRequestMatcher("/h2-console/**")).permitAll() .requestMatchers("/users/**").permitAll() // 其余所有请求需认证 .anyRequest().authenticated() ) // 启用HTTP Basic认证 .httpBasic(); return http.build(); } }
关键配置说明
- Lambda DSL风格:通过链式调用+Lambda表达式替代传统的
.and()拼接,代码结构更清晰,避免配置覆盖问题 - CSRF禁用:H2控制台的原生表单不支持CSRF令牌,必须禁用该保护才能正常提交操作
- X-Frame-Options禁用:Spring Security默认设置
X-Frame-Options: DENY,会阻止H2控制台的iframe渲染,需显式禁用 - 统一权限配置:所有路径规则都集中在
authorizeHttpRequests()的Lambda参数中,避免多次调用导致的规则覆盖 - 路径匹配:使用
requestMatchers替代已弃用的antMatchers/mvcMatchers,可直接传入路径字符串或AntPathRequestMatcher实例
补充H2控制台启用配置
在application.properties中添加以下配置,确保H2控制台可访问:
# 启用H2控制台 spring.h2.console.enabled=true # 设置H2控制台访问路径 spring.h2.console.path=/h2-console
内容的提问来源于stack exchange,提问作者anyname
相关产品推荐
相关产品推荐

