Spring Security中antMatchers失效,登录路由仍触发JWT认证
Spring Security登录端点仍触发JwtFilter的问题
我在开发Spring Security认证API时碰到个问题:已经基于OncePerRequestFilter完成了JWT登录、注册的路由配置,但用户用用户名密码访问登录接口时,依然会执行JwtFilter的doFilter方法——API还是会尝试获取JWT Bearer Token。
我按如下方式配置了SecurityConfig.java,但antMatchers对/api/v0/auth/login路径的放行并未如预期生效:
SecurityConfig.java
@Configuration @AllArgsConstructor @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { private final AppUserService appUserService; private final BCryptPasswordEncoder bCryptPasswordEncoder; @Autowired private JwtFilter jwtFilter; @Override protected void configure(HttpSecurity http) throws Exception { http .csrf().disable(); http .authorizeRequests() .antMatchers("/api-docs", "/swagger").permitAll() .antMatchers("/api/v0/auth/login").permitAll() .antMatchers("/h2-console/**").permitAll() .anyRequest() .authenticated(); http.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS); http.addFilterBefore(this.jwtFilter, UsernamePasswordAuthenticationFilter.class); } @Override protected void configure(AuthenticationManagerBuilder auth) throws Exception { auth.authenticationProvider(this.daoAuthenticationProvider()); } @Bean public DaoAuthenticationProvider daoAuthenticationProvider() { DaoAuthenticationProvider provider = new DaoAuthenticationProvider(); provider.setPasswordEncoder(this.bCryptPasswordEncoder); provider.setUserDetailsService(this.appUserService); return provider; } }
AuthController.java
@RestController @AllArgsConstructor @RequestMapping(path = "/api/v0/auth") public class AuthController { @Autowired private AuthService authService; @PostMapping("/login") public ResponseEntity<AuthResponse> login(@RequestBody LoginRequest request) throws Exception { AuthResponse response = this.authService.login(request); return ResponseEntity.ok().body(response); } // ..... 其他代码 }
目前的现象是:访问/api-docs、/swagger时API不会触发认证,但访问/api/v0/auth/login时却会触发,登录请求的日志显示已经进入了JwtFilter:
JwtFilter.java
@Component public class JwtFilter extends OncePerRequestFilter { private Logger log = LoggerFactory.getLogger(JwtFilter.class); @Override protected void doFilterInternal( HttpServletRequest request, HttpServletResponse response, FilterChain filterChain) throws ServletException, IOException { String authorization = request.getHeader("Authorization"); String token = null; String userName = null; log.info("@@ doFilterInternal: {}", authorization); // JWT解析与认证逻辑 filterChain.doFilter(request, response); } }
登录请求日志:
2023-01-22 09:49:06.716 INFO 15780 --- [nio-8080-exec-1] c.h.s.config.security.filter.JwtFilter : @@ doFilterInternal: null
我已经把登录端点加入了antMatchers的放行列表,认为应该跳过认证且不会输出这条日志,请问我遗漏了什么?
内容的提问来源于stack exchange,提问作者Gwenda Thomas
相关产品推荐
相关产品推荐

