Spring Security配置FilterChain时antMatchers()函数不存在求助
Spring Security 中
antMatchers()标红不存在的解决方法 问题描述
我正在学习Spring Security,在配置SecurityFilterChain时,antMatchers()函数被标红提示不存在。使用IntelliJ开发工具,怀疑是pom.xml中缺少依赖,但不确定。以下是我的WebSecurityConfig代码和pom.xml配置:
WebSecurityConfig代码
package com.main.CitaMedica.config; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.http.HttpMethod; import org.springframework.security.config.Customizer; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.http.SessionCreationPolicy; import org.springframework.security.core.userdetails.User; import org.springframework.security.core.userdetails.UserDetailsService; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; import org.springframework.security.provisioning.InMemoryUserDetailsManager; import org.springframework.security.web.SecurityFilterChain; import static org.springframework.security.web.util.matcher.AntPathRequestMatcher.antMatcher; @Configuration @EnableWebSecurity public class WebSecurityConfig{ @Bean public UserDetailsService userDetailsService(BCryptPasswordEncoder bCryptPasswordEncoder) { InMemoryUserDetailsManager manager = new InMemoryUserDetailsManager(); manager.createUser(User.withUsername("user") .password(bCryptPasswordEncoder.encode("user")) .roles("USER") .build()); manager.createUser(User.withUsername("admin") .password(bCryptPasswordEncoder.encode("admin")) .roles("USER","ADMIN") .build()); return manager; } @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http.csrf() .disable() .authorizeRequests() .antMatchers(HttpMethod.DELETE) .hasRole("ADMIN") .antMatchers("/admin/**") .hasAnyRole("ADMIN") .antMatchers("/user/**") .hasAnyRole("USER", "ADMIN") .antMatchers("/login/**") .anonymous() .anyRequest() .authenticated() .and() .httpBasic() .and() .sessionManagement() .sessionCreationPolicy(SessionCreationPolicy.STATELESS); return http.build(); } }
pom.xml配置
<?xml version="1.0" encoding="UTF-8"?> <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>3.0.2</version> <relativePath/> <!-- lookup parent from repository --> </parent> <groupId>com.main</groupId> <artifactId>CitaMedica</artifactId> <version>0.0.1-SNAPSHOT</version> <name>CitaMedica</name> <description>Demo project for Spring Boot</description> <properties> <java.version>17</java.version> </properties> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-data-jpa</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-thymeleaf</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-devtools</artifactId> <scope>runtime</scope> <optional>true</optional> </dependency> <dependency> <groupId>com.oracle.database.jdbc</groupId> <artifactId>ojdbc8</artifactId> <scope>runtime</scope> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.webjars</groupId> <artifactId>bootstrap</artifactId> <version>5.2.3</version> </dependency> <dependency> <groupId>org.projectlombok</groupId> <artifactId>lombok</artifactId> <optional>true</optional> </dependency> <dependency> <groupId>org.mapstruct</groupId> <artifactId>mapstruct</artifactId> <version>1.5.3.Final</version> </dependency> <dependency> <groupId>org.jetbrains</groupId> <artifactId>annotations</artifactId> <version>23.0.0</version> <scope>compile</scope> </dependency> </dependencies> <build> <plugins> <plugin> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-maven-plugin</artifactId> </plugin> <plugin> <groupId>org.apache.maven.plugins</groupId> <artifactId>maven-compiler-plugin</artifactId> <version>3.8.1</version> <configuration> <source>${java.version}</source> <target>${java.version}</target> <annotationProcessorPaths> <path> <groupId>org.mapstruct</groupId> <artifactId>mapstruct-processor</artifactId> <version>1.5.3.Final</version> </path> </annotationProcessorPaths> </configuration> </plugin> </plugins> </build> </project>
问题原因
你使用的Spring Boot 3.0.2对应Spring Security 6.x版本,该版本已经移除了antMatchers()方法,同时authorizeRequests()也被替换为authorizeHttpRequests()。这不是依赖缺失的问题,而是API版本更新导致的语法变化。
解决方法
1. 替换过时API
将authorizeRequests()替换为authorizeHttpRequests(),所有antMatchers()替换为requestMatchers(),并使用Spring Security 6推荐的lambda风格配置:
修改后的filterChain方法:
@Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http.csrf() .disable() .authorizeHttpRequests(auth -> auth .requestMatchers(HttpMethod.DELETE).hasRole("ADMIN") .requestMatchers("/admin/**").hasAnyRole("ADMIN") .requestMatchers("/user/**").hasAnyRole("USER", "ADMIN") .requestMatchers("/login/**").anonymous() .anyRequest().authenticated()) .httpBasic(Customizer.withDefaults()) .sessionManagement(session -> session .sessionCreationPolicy(SessionCreationPolicy.STATELESS)); return http.build(); }
2. 补充缺失的Bean
你的userDetailsService依赖BCryptPasswordEncoder,但当前代码中未定义该Bean,需要添加:
@Bean public BCryptPasswordEncoder bCryptPasswordEncoder() { return new BCryptPasswordEncoder(); }
说明
Spring Security 6.x中,lambda风格的配置更简洁易读,requestMatchers()支持多种匹配规则,包括原antMatchers()的Ant风格路径匹配,无需额外导入匹配器类。
内容的提问来源于stack exchange,提问作者Miguel Ángel
相关产品推荐
相关产品推荐

