Spring Security 6.0.1部署Glassfish 6时Bean创建异常求助
解决方案:Spring Security 6.0.1 升级后Bean创建异常修复
问题根源分析
从异常栈可以定位到两个核心问题:
- 请求匹配器依赖缺失:Spring Security 6.0默认使用
MvcRequestMatcher,该组件依赖Spring MVC的DispatcherServlet及相关上下文配置,但你的项目仅配置了JSF的Faces Servlet,缺少Spring MVC核心配置,导致无法初始化该Bean。 - 明文密码不被允许:Spring Security 6.0强制要求密码必须经过编码,你的配置中用户密码为明文格式,不符合新版本安全规范。
具体修复步骤
1. 修改spring-security.xml配置
(1)指定Ant风格请求匹配器
在<http>标签中添加request-matcher="ant",强制使用不依赖Spring MVC的AntPathRequestMatcher:
<beans:beans xmlns="http://www.springframework.org/schema/security" xmlns:beans="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security.xsd"> <http pattern="/securityNone" security="none" request-matcher="ant"/> <http use-expressions="true" request-matcher="ant"> <intercept-url pattern="/**" access="isAuthenticated()" /> <http-basic /> </http> <!-- 配置密码编码器 --> <beans:bean id="passwordEncoder" class="org.springframework.security.crypto.password.NoOpPasswordEncoder" factory-method="getInstance"/> <authentication-manager> <authentication-provider> <user-service password-encoder-ref="passwordEncoder"> <user name="guest" password="123" authorities="ROLE_USER" /> </user-service> </authentication-provider> </authentication-manager> </beans:beans>
(2)添加密码编码器
- 测试环境可使用
NoOpPasswordEncoder(不加密,仅用于调试) - 生产环境必须替换为安全编码器(如
BCryptPasswordEncoder),同时需将用户密码替换为对应加密后的字符串
2. 验证依赖兼容性
你的Spring Framework 6.0.3与Spring Security 6.0.1版本兼容,两者均支持Jakarta EE 9,适配Glassfish 6环境无需调整依赖。
3. 可选:升级web.xml版本(非必须)
若后续引入Spring MVC,可将web-app版本升级至5.0(对应Jakarta EE 9),当前配置下不影响功能:
<web-app version="5.0" xmlns="https://jakarta.ee/xml/ns/jakartaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="https://jakarta.ee/xml/ns/jakartaee https://jakarta.ee/xml/ns/jakartaee/web-app_5_0.xsd">
验证
修改配置后重新部署项目,Bean创建异常将消失,访问项目时会弹出HTTP Basic认证窗口,输入guest/123即可正常访问。
内容的提问来源于stack exchange,提问作者shamin
相关产品推荐
相关产品推荐

