Spring Boot Admin客户端注册遇CSRF令牌缺失403错误求解决
Spring Boot Admin客户端注册CSRF 403错误解决方案
问题根源
你遇到的An expected CSRF token cannot be found错误,是因为服务端的Spring Security CSRF保护拦截了客户端的注册请求。客户端向服务端发送的注册请求是POST类型,服务端默认启用CSRF防护,但未对SBA的注册端点/instances做豁免处理。
具体解决方法
方法1:豁免注册端点的CSRF校验(推荐生产环境使用)
修改服务端的Spring Security配置类,针对/instances端点关闭CSRF校验,同时保留其他端点的防护:
@Configuration public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http.authorizeRequests() // 放行SBA注册端点和监控端点,可根据实际权限需求调整 .antMatchers("/instances", "/actuator/**").permitAll() .anyRequest().authenticated() .and() .formLogin() // 保留SBA默认登录页面 .and() .csrf() .ignoringAntMatchers("/instances"); // 豁免注册接口的CSRF校验 } // 配置服务端认证用户(需与客户端配置的username/password一致) @Override protected void configure(AuthenticationManagerBuilder auth) throws Exception { auth.inMemoryAuthentication() .withUser("admin") .password("{noop}admin") .roles("ADMIN"); } }
方法2:全局关闭CSRF(仅测试环境推荐)
如果是测试场景,可直接关闭服务端全局CSRF防护(生产环境不建议):
@Configuration public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http.authorizeRequests() .anyRequest().authenticated() .and() .formLogin() .and() .csrf().disable(); // 全局关闭CSRF } // 认证用户配置同上 }
额外检查项
- 确认服务端配置的认证账号(
admin/admin)与客户端配置完全一致,避免因认证失败导致的403。 - 确保服务端已放行
/actuator/**端点,否则客户端的健康检查、指标上报等请求也会被拦截。
内容的提问来源于stack exchange,提问作者shifty
相关产品推荐
相关产品推荐

