SpringBoot3对接LDAP服务器认证失败问题求助
问题排查与修复方案
一、500内部服务器错误根源:Servlet API依赖冲突
错误日志中的java.lang.NoSuchMethodError: 'java.util.Map jakarta.servlet.SessionCookieConfig.getAttributes()'是核心问题,原因是:
- Spring Boot 3.0.2默认集成Tomcat 10.1.x,该版本依赖Jakarta Servlet 6.0 API,而你手动引入了
jakarta.servlet:jakarta.servlet-api:5.0.0(Servlet 5.0),版本不兼容导致方法缺失。
修复步骤:
直接移除依赖中的implementation 'jakarta.servlet:jakarta.servlet-api:5.0.0',Spring Boot Starter Web会自动引入匹配版本的Servlet API。
二、LDAP认证配置问题排查
1. 上下文源配置错误
你的contextSource()方法使用了@Autowired注解(错误用法),创建Bean应该用@Bean注解;同时未启用连接池配置。修改如下:
@Bean public LdapContextSource contextSource() { LdapContextSource ldapContextSource = new LdapContextSource(); ldapContextSource.setUrl(ldapContextSourceUrl); ldapContextSource.setBase(ldapContextSourceBase); ldapContextSource.setUserDn(userDnPattern); ldapContextSource.setPassword(ldapContextSourcePassword); ldapContextSource.setReferral(ldapContextSourceReferral); // 启用连接池 ldapContextSource.setPooled(Boolean.parseBoolean(ldapContextSourcePooled)); ldapContextSource.afterPropertiesSet(); return ldapContextSource; }
2. 用户DN模式配置错误
LdapBindAuthenticationManagerFactory.setUserDnPatterns()接收的是字符串数组,如果你的userDnPattern是单个模式(比如uid={0},ou=users),需要转为数组传入:
@Bean AuthenticationManager ldapAuthenticationManager(BaseLdapPathContextSource contextSource) { LdapBindAuthenticationManagerFactory factory = new LdapBindAuthenticationManagerFactory(contextSource); // 转为数组格式 factory.setUserDnPatterns(new String[]{userDnPattern}); factory.setUserDetailsContextMapper(new PersonContextMapper()); return factory.createAuthenticationManager(); }
3. 未启用认证拦截逻辑
当前filterChain()配置了permitAll(),所有请求都无需认证,导致LDAP认证逻辑从未触发。需要根据需求配置认证规则,例如:
@Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth // 健康检查接口放行 .requestMatchers("/readiness", "/liveness").permitAll() // 其他所有请求需要认证 .anyRequest().authenticated() ) // 启用HTTP Basic认证(或formLogin()) .httpBasic(Customizer.withDefaults()); return http.build(); }
同时可以移除WebSecurityCustomizer,因为已经在filterChain中配置了健康接口放行。
三、其他依赖优化建议
- Guava版本问题:
com.google.guava:guava:30.0-android是针对Android的版本,与Java 17兼容性不佳,建议替换为JDK兼容版本:implementation 'com.google.guava:guava:31.1-jre' - Elasticsearch依赖:Spring Boot 3.0.2对应的Elasticsearch版本是7.17.9,你当前用的是7.17.4,可以保持一致或升级到匹配版本,避免潜在兼容性问题。
修改后的完整依赖配置
// ==[ PLUGINS ]=============================================================== apply plugin: "org.owasp.dependencycheck" apply plugin: 'java' apply plugin: 'maven-publish' if ( System.getenv().containsKey("JTEST_HOME") ) { apply from: System.getenv('JTEST_HOME') + '/integration/gradle/jtest.gradle' } // ==[ DEPENDENCIES ]========================================================== dependencies { implementation 'org.springframework.boot:spring-boot-starter-data-ldap' implementation 'org.springframework.security:spring-security-ldap' implementation 'org.springframework.boot:spring-boot-starter-data-jdbc' implementation 'org.springframework.boot:spring-boot-starter-data-rest' implementation 'org.springframework.boot:spring-boot-starter-data-jpa' implementation 'org.springframework.boot:spring-boot-starter-web' implementation 'org.springframework.boot:spring-boot-starter-security' implementation 'org.elasticsearch.client:elasticsearch-rest-client:7.17.9' implementation 'org.elasticsearch:elasticsearch:7.17.9' implementation 'org.elasticsearch.client:elasticsearch-rest-high-level-client:7.17.9' implementation 'org.apache.commons:commons-lang3:3.8.1' implementation 'com.google.code.gson:gson:2.10.1' implementation 'com.google.guava:guava:31.1-jre' implementation 'com.microsoft.sqlserver:mssql-jdbc:10.2.0.jre17' developmentOnly 'org.springframework.boot:spring-boot-devtools' testRuntimeOnly 'org.junit.platform:junit-platform-launcher:1.8.2' testImplementation 'junit:junit:4.13.1' testImplementation('org.springframework.boot:spring-boot-starter-test') { exclude group: 'org.junit.vintage', module: 'junit-vintage-engine' } }
内容的提问来源于stack exchange,提问作者kkellogg
相关产品推荐
相关产品推荐

