You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security中antMatchers失效,登录路由仍触发JWT认证

Spring Security登录端点仍触发JwtFilter的问题

我在开发Spring Security认证API时碰到个问题:已经基于OncePerRequestFilter完成了JWT登录、注册的路由配置,但用户用用户名密码访问登录接口时,依然会执行JwtFilter的doFilter方法——API还是会尝试获取JWT Bearer Token。

我按如下方式配置了SecurityConfig.java,但antMatchers对/api/v0/auth/login路径的放行并未如预期生效:

SecurityConfig.java

@Configuration
@AllArgsConstructor
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {
    private final AppUserService appUserService;
    private final BCryptPasswordEncoder bCryptPasswordEncoder;

    @Autowired
    private JwtFilter jwtFilter;

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
                .csrf().disable();

        http
                .authorizeRequests()
                .antMatchers("/api-docs", "/swagger").permitAll()
                .antMatchers("/api/v0/auth/login").permitAll()
                .antMatchers("/h2-console/**").permitAll()
                .anyRequest()
                .authenticated();

        http.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS);
        http.addFilterBefore(this.jwtFilter, UsernamePasswordAuthenticationFilter.class);
    }

    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        auth.authenticationProvider(this.daoAuthenticationProvider());
    }

    @Bean
    public DaoAuthenticationProvider daoAuthenticationProvider() {
        DaoAuthenticationProvider provider = new DaoAuthenticationProvider();
        provider.setPasswordEncoder(this.bCryptPasswordEncoder);
        provider.setUserDetailsService(this.appUserService);
        return provider;
    }
}

AuthController.java

@RestController
@AllArgsConstructor
@RequestMapping(path = "/api/v0/auth")
public class AuthController {

    @Autowired
    private AuthService authService;

    @PostMapping("/login")
    public ResponseEntity<AuthResponse> login(@RequestBody LoginRequest request) throws Exception {
        AuthResponse response = this.authService.login(request);
        return ResponseEntity.ok().body(response);
    }
// ..... 其他代码
}

目前的现象是:访问/api-docs、/swagger时API不会触发认证,但访问/api/v0/auth/login时却会触发,登录请求的日志显示已经进入了JwtFilter:

JwtFilter.java

@Component
public class JwtFilter extends OncePerRequestFilter {

    private Logger log = LoggerFactory.getLogger(JwtFilter.class);

    @Override
    protected void doFilterInternal(
            HttpServletRequest request,
            HttpServletResponse response,
            FilterChain filterChain) throws ServletException, IOException {

        String authorization = request.getHeader("Authorization");
        String token = null;
        String userName = null;
        log.info("@@ doFilterInternal: {}", authorization);
        
        // JWT解析与认证逻辑

        filterChain.doFilter(request, response);
    }
}

登录请求日志:

2023-01-22 09:49:06.716  INFO 15780 --- [nio-8080-exec-1] c.h.s.config.security.filter.JwtFilter   : @@ doFilterInternal: null

我已经把登录端点加入了antMatchers的放行列表,认为应该跳过认证且不会输出这条日志,请问我遗漏了什么?


内容的提问来源于stack exchange,提问作者Gwenda Thomas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 01:30:23