You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security中springSecurityFilterChain已构建异常求助

Fixing Spring Security's AlreadyBuiltException in Your OAuth2 Configuration

Hey there, let's tackle that frustrating AlreadyBuiltException you're hitting when starting your Spring Security OAuth2 app. I've seen this issue a bunch of times, and it usually boils down to a small misstep in how you're configuring HttpSecurity.

What's Causing the Exception?

The error message This object has already been built tells us that somewhere in your code, you're trying to modify a Spring Security configuration object after it's already been finalized. In your case, this is happening because you're making multiple separate calls to http.authorizeRequests() in your resource server configuration.

Each time you call http.authorizeRequests(), you're getting the same ExpressionUrlAuthorizationConfigurer instance. Once you start defining rules on it, Spring Security starts the process of building the filter chain. If you try to call http.authorizeRequests() again later in the same method, you're trying to modify an object that's already been marked as built—hence the exception.

The Problem in Your Code

Looking at your ResourceServer class's configure(HttpSecurity http) method, you've split your authorization rules into three separate http.authorizeRequests() blocks:

http
    .authorizeRequests()
    .antMatchers("/oauth/token").anonymous();

http
    .authorizeRequests()
    .antMatchers(HttpMethod.GET, "/**")
    .access("#oauth2.hasScope('read')");

http
    .authorizeRequests()
    .antMatchers("/**")
    .access("#oauth2.hasScope('write')");

Each of these calls tries to reconfigure the same authorization builder, which triggers the already-built error.

The Fixed Configuration

The fix is simple—chain all your authorization rules together in a single authorizeRequests() block. This way, you're configuring the builder in one go before it gets finalized. Here's the corrected code:

@Override
public void configure(HttpSecurity http) throws Exception {
    http.csrf().disable()
        .authorizeRequests()
            // Allow anonymous access to the token endpoint first
            .antMatchers("/oauth/token").anonymous()
            // Require 'read' scope for all GET requests
            .antMatchers(HttpMethod.GET, "/**").access("#oauth2.hasScope('read')")
            // Require 'write' scope for all other requests
            .antMatchers("/**").access("#oauth2.hasScope('write')");
}

A Quick Note on Rule Order

Also, make sure you keep your rules in the right order! Spring Security matches rules from top to bottom. So more specific rules (like the /oauth/token and GET-specific rules) need to come before general catch-all rules (like the final /**). If you reverse them, the catch-all will match first, and your more specific rules will never get used.

Give this fix a try, and your app should start up without that annoying AlreadyBuiltException!

内容的提问来源于stack exchange,提问作者Stefano Maglione

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 12:27:45