You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Cloud Config Client启用服务端Security后无法拉取配置(401错误)

解决Spring Cloud Config Server启用Security后客户端401认证失败问题

我来帮你搞定这个头疼的问题!从你的描述、配置和日志来看,核心问题出在Spring Security的CSRF保护机制以及客户端配置加载顺序上,下面分步骤给你解决思路:

一、核心原因分析

在Spring Boot 2.2.x版本中,Spring Security默认启用了CSRF(跨站请求伪造)保护。而Spring Cloud Config客户端是通过RestTemplate发起HTTP请求获取配置的,这个请求并没有携带CSRF令牌,因此被Config Server的Security拦截,返回401 Unauthorized错误。另外,还有一个常见坑是客户端的配置放错了文件,导致认证信息没有在启动早期加载生效。

二、分步解决方案

1. 关闭Config Server的CSRF保护

Config Server的端点主要是供服务端之间调用,不需要CSRF保护,直接在Security配置类中关闭即可:

@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.csrf().disable() // 关键:关闭CSRF保护
            .authorizeRequests()
            .antMatchers("/**").fullyAuthenticated()
            .and()
            .httpBasic(); // 保留HTTP Basic认证逻辑
    }
}

2. 调整客户端配置文件位置

Spring Cloud Config的客户端配置必须放在bootstrap.yml/bootstrap.properties中,而不是application.yml!因为bootstrap文件会在应用启动的最早期加载,而application.yml加载顺序靠后,导致你的认证信息没有被Config客户端读取到,这是很多开发者容易踩的坑。

修改客户端的bootstrap.yml配置:

spring:
  application:
    name: service
  cloud:
    config:
      uri: http://localhost:8888
      username: root
      password: 1234
      fail-fast: true

3. (可选)手动配置客户端RestTemplate认证拦截器

如果上面两步还没解决问题,可以手动给RestTemplate添加Basic Auth拦截器,确保请求携带认证信息:

@Configuration
public class ConfigClientAuthConfig {
    @Value("${spring.cloud.config.username}")
    private String configUsername;
    @Value("${spring.cloud.config.password}")
    private String configPassword;

    @Bean
    public RestTemplate configRestTemplate() {
        RestTemplate restTemplate = new RestTemplate();
        restTemplate.getInterceptors().add((request, body, execution) -> {
            // 构造Basic Auth头信息
            String authCredentials = configUsername + ":" + configPassword;
            byte[] encodedAuth = Base64.encodeBase64(authCredentials.getBytes(StandardCharsets.UTF_8));
            String authHeader = "Basic " + new String(encodedAuth);
            
            request.getHeaders().set(HttpHeaders.AUTHORIZATION, authHeader);
            return execution.execute(request, body);
        });
        return restTemplate;
    }
}

三、验证步骤

  1. 重启Config Server和客户端应用
  2. 查看客户端启动日志,确认是否出现Located environment的成功日志
  3. 用curl命令测试Config Server端点:curl -u root:1234 http://localhost:8888/service/default,确认返回正常的配置内容

按照上面的步骤调整后,你的客户端应该就能正常拉取Config Server的配置了!

内容的提问来源于stack exchange,提问作者Neco Horne

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 17:47:51