Spring Boot禁用CSRF仍返回403:未找到预期CSRF令牌
Spring Boot禁用CSRF后仍返回403 Forbidden问题
我在Spring Boot应用的filterChain中已禁用CSRF,但所有请求仍返回403 Forbidden,提示**"找不到预期的CSRF令牌"**。
原项目代码
SecurityFilterChain Bean代码
@Bean public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception { httpSecurity .csrf().disable() .sessionManagement() .sessionCreationPolicy(SessionCreationPolicy.STATELESS) .and() .authorizeHttpRequests() .requestMatchers("/auth/login").permitAll() .anyRequest().authenticated() .and() .addFilterBefore(new JwtTokenFilter(jwtTokenProvider), UsernamePasswordAuthenticationFilter.class); return httpSecurity.build(); }
JwtTokenFilter类代码
@AllArgsConstructor public class JwtTokenFilter extends GenericFilterBean { private final JwtTokenProvider jwtTokenProvider; @Override public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException { String bearerToken = ((HttpServletRequest) servletRequest).getHeader("Authorization"); if (bearerToken != null && bearerToken.startsWith("Bearer ")) { bearerToken = bearerToken.substring(7); } if (bearerToken != null && jwtTokenProvider.validateToken(bearerToken)) { Authentication authentication = jwtTokenProvider.getAuthentication(bearerToken); if (authentication != null) { SecurityContextHolder.getContext().setAuthentication(authentication); } } filterChain.doFilter(servletRequest, servletResponse); } }
DEBUG日志
2023-04-14T11:38:34.554+03:00 DEBUG 13404 --- [ctor-http-nio-2] o.s.w.s.a.HttpWebHandlerAdapter : [1cc1175d-1] HTTP POST "/auth/login" 2023-04-14T11:38:34.713+03:00 DEBUG 13404 --- [ parallel-1] o.s.w.s.s.DefaultWebSessionManager : Created new WebSession. 2023-04-14T11:38:34.783+03:00 DEBUG 13404 --- [ctor-http-nio-2] o.s.w.s.a.HttpWebHandlerAdapter : [1cc1175d-1] Completed 403 FORBIDDEN
更新:空项目复现问题
我创建了仅包含filterChain和模拟控制器的空项目,问题依然存在:
控制器代码
@Controller public class AController { @PostMapping(path = "/auth/login") public ResponseEntity<String> login(){ return ResponseEntity.ok().build(); } }
配置类代码
@Configuration @EnableWebSecurity(debug = true) public class AConfiguration { @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .csrf().disable(); return http.build(); } }
应用类代码
@SpringBootApplication public class SecurityConfigurationApplication { public static void main(String[] args) { SpringApplication.run(SecurityConfigurationApplication.class, args); } }
请求信息
POST http://localhost:8080/auth/login Content-Length: 0 Connection: Keep-Alive User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) Accept-Encoding: br,deflate,gzip,x-gzip
响应信息
POST http://localhost:8080/auth/login HTTP/1.1 403 Forbidden Content-Type: text/plain Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: 0 X-Content-Type-Options: nosniff X-Frame-Options: DENY X-XSS-Protection: 0 Referrer-Policy: no-referrer content-length: 38 找不到预期的CSRF令牌 Response code: 403 (Forbidden); Time: 154ms (154 ms); Content length: 38 bytes (38 B)
我在类似问题中未找到可行解决方案。
内容的提问来源于stack exchange,提问作者Vlad
相关产品推荐
相关产品推荐

