SpringSecurity配置异常:添加@Bean启动失败,移除则不加载配置
SpringSecurity配置启动失败问题排查与解决
问题描述
配置SpringSecurity类时遇到异常:给filterChain方法添加@Bean注解后,应用启动失败,报错提示找不到org.springframework.security.config.annotation.web.builders.HttpSecurity类型的Bean;移除@Bean注解后应用可启动,但安全配置不生效。
报错信息
*************************** APPLICATION FAILED TO START *************************** Description: Parameter 0 of method filterChain in com.xxxxxxxxx.xxxxxxxx.config.integracao.security.SpringSecurityV2 required a bean of type 'org.springframework.security.config.annotation.web.builders.HttpSecurity' that could not be found. Action: Consider defining a bean of type 'org.springframework.security.config.annotation.web.builders.HttpSecurity' in your configuration. Process finished with exit code 1
安全配置代码
@Configuration @EnableGlobalMethodSecurity(prePostEnabled = true) public class SpringSecurityV2 { @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception{ http .httpBasic() .and() .authorizeHttpRequests() .anyRequest().authenticated() .and() .csrf().disable(); return http.build(); } @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } }
pom.xml依赖配置
<?xml version="1.0" encoding="UTF-8"?> <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>2.6.14</version> <relativePath/> <!-- lookup parent from repository --> </parent> <groupId>com.xxxxxxx</groupId> <artifactId>xxxxxxxxxx</artifactId> <version>0.0.1-SNAPSHOT</version> <name>xxxxxxxxxxxx</name> <description>Demo project for Spring Boot</description> <properties> <java.version>11</java.version> <squiggly.version>1.3.18</squiggly.version> </properties> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-data-rest</artifactId> </dependency> <dependency> <groupId>org.firebirdsql.jdbc</groupId> <artifactId>jaybird</artifactId> <version>4.0.8.java11</version> </dependency> <dependency> <groupId>org.postgresql</groupId> <artifactId>postgresql</artifactId> <scope>runtime</scope> </dependency> <dependency> <groupId>com.fasterxml.jackson.dataformat</groupId> <artifactId>jackson-dataformat-xml</artifactId> </dependency> <dependency> <groupId>org.hibernate.orm</groupId> <artifactId>hibernate-community-dialects</artifactId> <version>6.0.0.Alpha9</version> </dependency> <dependency> <groupId>org.hibernate</groupId> <artifactId>hibernate-c3p0</artifactId> <version>3.6.3.Final</version> </dependency> <dependency> <groupId>org.hibernate</groupId> <artifactId>hibernate-commons-annotations</artifactId> <version>3.3.0.ga</version> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-test</artifactId> <scope>test</scope> </dependency> <!-- https://mvnrepository.com/artifact/org.apache.poi/poi --> <dependency> <groupId>org.apache.poi</groupId> <artifactId>poi</artifactId> <version>5.0.0</version> </dependency> <!-- https://mvnrepository.com/artifact/org.apache.poi/poi-ooxml --> <dependency> <groupId>org.apache.poi</groupId> <artifactId>poi-ooxml</artifactId> <version>5.0.0</version> </dependency> <!-- https://mvnrepository.com/artifact/commons-io/commons-io --> <dependency> <groupId>commons-io</groupId> <artifactId>commons-io</artifactId> <version>2.11.0</version> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-core</artifactId> <version>6.0.0</version> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-data-jpa</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-thymeleaf</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-validation</artifactId> </dependency> <dependency> <groupId>com.github.bohnman</groupId> <artifactId>squiggly-filter-jackson</artifactId> <version>1.3.18</version> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter</artifactId> </dependency> <dependency> <groupId>org.projectlombok</groupId> <artifactId>lombok</artifactId> <optional>true</optional> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>net.bytebuddy</groupId> <artifactId>byte-buddy-agent</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-configuration-processor</artifactId> <optional>true</optional> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-configuration-processor</artifactId> <optional>true</optional> </dependency> <dependency> <groupId>org.jetbrains</groupId> <artifactId>annotations</artifactId> <version>RELEASE</version> <scope>compile</scope> </dependency> </dependencies> <build> <plugins> <plugin> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-maven-plugin</artifactId> <configuration> <excludes> <exclude> <groupId>org.projectlombok</groupId> <artifactId>lombok</artifactId> </exclude> </excludes> </configuration> </plugin> </plugins> </build> </project>
问题根源
Spring Boot 2.6.14对应的Spring Security版本是5.7.x,但你手动引入了Spring Security 6.0.0的核心依赖,版本不兼容导致HttpSecurity无法被Spring容器正确识别并注入。
修复步骤
移除冲突的Spring Security依赖
删除pom.xml中手动指定的Spring Security Core依赖:<dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-core</artifactId> <version>6.0.0</version> </dependency>已引入的
spring-boot-starter-security会自动管理适配Spring Boot版本的Spring Security依赖,无需手动指定。保留正确的配置类写法
你的SpringSecurityV2配置类写法符合Spring Security 5.7.x的要求,保留@Configuration、@EnableGlobalMethodSecurity注解,以及两个方法上的@Bean注解即可。重新构建项目
执行Maven命令清理并重新构建,确保依赖更新生效:mvn clean install
验证
重新启动应用,此时安全配置会被正确加载,应用可正常启动并生效所有安全规则。
内容的提问来源于stack exchange,提问作者cesar pereira
相关产品推荐
相关产品推荐

