You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot禁用CSRF仍返回403:未找到预期CSRF令牌

Spring Boot禁用CSRF后仍返回403 Forbidden问题

我在Spring Boot应用的filterChain中已禁用CSRF,但所有请求仍返回403 Forbidden,提示**"找不到预期的CSRF令牌"**。

原项目代码

SecurityFilterChain Bean代码

@Bean
public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception {
    httpSecurity
            .csrf().disable()
            .sessionManagement()
            .sessionCreationPolicy(SessionCreationPolicy.STATELESS)
            .and()
            .authorizeHttpRequests()
            .requestMatchers("/auth/login").permitAll()
            .anyRequest().authenticated()
            .and()
            .addFilterBefore(new JwtTokenFilter(jwtTokenProvider), UsernamePasswordAuthenticationFilter.class);
    return httpSecurity.build();
}

JwtTokenFilter类代码

@AllArgsConstructor
public class JwtTokenFilter extends GenericFilterBean {

    private final JwtTokenProvider jwtTokenProvider;

    @Override
    public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {
        String bearerToken = ((HttpServletRequest) servletRequest).getHeader("Authorization");
        if (bearerToken != null && bearerToken.startsWith("Bearer ")) {
            bearerToken = bearerToken.substring(7);
        }
        if (bearerToken != null && jwtTokenProvider.validateToken(bearerToken)) {
            Authentication authentication = jwtTokenProvider.getAuthentication(bearerToken);
            if (authentication != null) {
                SecurityContextHolder.getContext().setAuthentication(authentication);
            }
        }
        filterChain.doFilter(servletRequest, servletResponse);
    }
}

DEBUG日志

2023-04-14T11:38:34.554+03:00 DEBUG 13404 --- [ctor-http-nio-2] o.s.w.s.a.HttpWebHandlerAdapter          : [1cc1175d-1] HTTP POST "/auth/login"
2023-04-14T11:38:34.713+03:00 DEBUG 13404 --- [     parallel-1] o.s.w.s.s.DefaultWebSessionManager       : Created new WebSession.
2023-04-14T11:38:34.783+03:00 DEBUG 13404 --- [ctor-http-nio-2] o.s.w.s.a.HttpWebHandlerAdapter          : [1cc1175d-1] Completed 403 FORBIDDEN

更新:空项目复现问题

我创建了仅包含filterChain和模拟控制器的空项目,问题依然存在:

控制器代码

@Controller
public class AController {
    @PostMapping(path = "/auth/login")
    public ResponseEntity<String> login(){
        return ResponseEntity.ok().build();
    }
}

配置类代码

@Configuration
@EnableWebSecurity(debug = true)
public class AConfiguration {
    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http
                .csrf().disable();
        return http.build();
    }
}

应用类代码

@SpringBootApplication
public class SecurityConfigurationApplication {

    public static void main(String[] args) {
        SpringApplication.run(SecurityConfigurationApplication.class, args);
    }

}

请求信息

POST http://localhost:8080/auth/login
Content-Length: 0
Connection: Keep-Alive
User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5)
Accept-Encoding: br,deflate,gzip,x-gzip

响应信息

POST http://localhost:8080/auth/login

HTTP/1.1 403 Forbidden
Content-Type: text/plain
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-XSS-Protection: 0
Referrer-Policy: no-referrer
content-length: 38

找不到预期的CSRF令牌

Response code: 403 (Forbidden); Time: 154ms (154 ms); Content length: 38 bytes (38 B)

我在类似问题中未找到可行解决方案。

内容的提问来源于stack exchange,提问作者Vlad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 17:07:34