如何在Spring Security中禁用浏览器认证弹窗(Spring Boot 3.0.2)
禁用Swagger页面的浏览器认证弹窗(Spring Boot 3.0.2)
这个弹窗通常是Spring Security拦截了Swagger相关路径,或是Swagger自身配置了Basic认证导致的,以下是对应解决方案:
1. 放行Spring Security对Swagger路径的拦截
如果项目集成了Spring Security,需要在Security配置中开放Swagger相关的静态资源和接口路径:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.web.SecurityFilterChain; @Configuration public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http.authorizeHttpRequests(auth -> auth // 放行Swagger UI及API文档相关路径 .requestMatchers("/swagger-ui/**", "/v3/api-docs/**", "/swagger-resources/**", "/swagger-resources") .permitAll() // 其余接口保持原有认证规则 .anyRequest().authenticated() ); // Swagger测试场景下可关闭CSRF保护 http.csrf(csrf -> csrf.disable()); return http.build(); } }
2. 关闭Swagger自身的Basic认证
如果是Swagger UI自身启用了Basic认证,可通过配置文件关闭:
application.yml配置:
springdoc: swagger-ui: basic-auth: enabled: false
application.properties配置:
springdoc.swagger-ui.basic-auth.enabled=false
注意:Spring Boot 3.0+不再兼容旧的Springfox Swagger依赖,建议使用
springdoc-openapi-starter-webmvc-ui作为Swagger依赖,确保版本匹配(如2.0.x版本)。
内容的提问来源于stack exchange,提问作者Prabakaran A
相关产品推荐
相关产品推荐

