You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot Admin客户端注册遇CSRF令牌缺失403错误求解决

Spring Boot Admin客户端注册CSRF 403错误解决方案

问题根源

你遇到的An expected CSRF token cannot be found错误,是因为服务端的Spring Security CSRF保护拦截了客户端的注册请求。客户端向服务端发送的注册请求是POST类型,服务端默认启用CSRF防护,但未对SBA的注册端点/instances做豁免处理。

具体解决方法

方法1:豁免注册端点的CSRF校验(推荐生产环境使用)

修改服务端的Spring Security配置类,针对/instances端点关闭CSRF校验,同时保留其他端点的防护:

@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.authorizeRequests()
                // 放行SBA注册端点和监控端点,可根据实际权限需求调整
                .antMatchers("/instances", "/actuator/**").permitAll()
                .anyRequest().authenticated()
                .and()
                .formLogin() // 保留SBA默认登录页面
                .and()
                .csrf()
                .ignoringAntMatchers("/instances"); // 豁免注册接口的CSRF校验
    }

    // 配置服务端认证用户(需与客户端配置的username/password一致)
    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        auth.inMemoryAuthentication()
                .withUser("admin")
                .password("{noop}admin")
                .roles("ADMIN");
    }
}

方法2:全局关闭CSRF(仅测试环境推荐)

如果是测试场景,可直接关闭服务端全局CSRF防护(生产环境不建议):

@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.authorizeRequests()
                .anyRequest().authenticated()
                .and()
                .formLogin()
                .and()
                .csrf().disable(); // 全局关闭CSRF
    }

    // 认证用户配置同上
}

额外检查项

  • 确认服务端配置的认证账号(admin/admin)与客户端配置完全一致,避免因认证失败导致的403。
  • 确保服务端已放行/actuator/**端点,否则客户端的健康检查、指标上报等请求也会被拦截。

内容的提问来源于stack exchange,提问作者shifty

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 22:40:56