如何配置使浏览器无需Token即可访问Swagger-UI?
问题描述
通过Postman可正常请求Swagger相关接口,但浏览器访问http://localhost:8080/swagger-ui/index.html时,因系统要求Token而报错。
项目配置信息
pom.xml
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> <version>2.7.4</version> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>org.springdoc</groupId> <artifactId>springdoc-openapi-ui</artifactId> <version>1.6.14</version> </dependency>
主类
@SpringBootApplication public class ExampleMain { public static void main(String[] args) { SpringApplication.run(ExampleMain.class, args); } }
Security配置类
@Configuration @EnableWebSecurity public class SecurityConfig { private JwtConverter wtConverter; public SecurityConfig(JwtConverter jwtConverter) { this.jwtConverter = jwtConverter; } @Bean public SecurityFilterChain configure(HttpSecurity http) throws Exception { http .authorizeRequests() .antMatchers("/swagger-ui/**").permitAll() .anyRequest().authenticated() .and() .oauth2ResourceServer() .jwt() .jwtAuthenticationConverter(jwtConverter); return http.build(); } }
解决方法
修正变量拼写错误
当前SecurityConfig类中存在变量名拼写错误:private JwtConverter wtConverter;应改为private JwtConverter jwtConverter;,否则会导致依赖注入异常,直接影响配置生效。放行Swagger UI全量必要接口
SpringDoc Swagger UI不仅需要访问/swagger-ui/**路径,还需要获取openapi文档数据的/v3/api-docs/**接口,部分场景下还需放行/swagger-ui.html。修改Security配置的授权规则:@Bean public SecurityFilterChain configure(HttpSecurity http) throws Exception { http .authorizeRequests() .antMatchers("/swagger-ui/**", "/v3/api-docs/**", "/swagger-ui.html").permitAll() .anyRequest().authenticated() .and() .oauth2ResourceServer() .jwt() .jwtAuthenticationConverter(jwtConverter); return http.build(); }关闭CSRF防护(可选)
若浏览器访问仍存在异常,可能是CSRF拦截导致Swagger UI请求失败。可临时关闭CSRF防护(生产环境需根据业务场景评估风险):@Bean public SecurityFilterChain configure(HttpSecurity http) throws Exception { http .csrf().disable() .authorizeRequests() .antMatchers("/swagger-ui/**", "/v3/api-docs/**", "/swagger-ui.html").permitAll() .anyRequest().authenticated() .and() .oauth2ResourceServer() .jwt() .jwtAuthenticationConverter(jwtConverter); return http.build(); }
验证
修改配置后重启服务,再次访问http://localhost:8080/swagger-ui/index.html即可正常加载页面。若需调用需认证的接口,可通过页面右上角的Authorize按钮输入Token完成授权。
内容的提问来源于stack exchange,提问作者kernel
相关产品推荐
相关产品推荐

