You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置使浏览器无需Token即可访问Swagger-UI?

问题描述

通过Postman可正常请求Swagger相关接口,但浏览器访问http://localhost:8080/swagger-ui/index.html时,因系统要求Token而报错。

项目配置信息

pom.xml

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-web</artifactId>
    <version>2.7.4</version>
</dependency>
<dependency>
        <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>
<dependency>
    <groupId>org.springdoc</groupId>
    <artifactId>springdoc-openapi-ui</artifactId>
    <version>1.6.14</version>
</dependency>

主类

@SpringBootApplication
public class ExampleMain {
    public static void main(String[] args) {
        SpringApplication.run(ExampleMain.class, args);
    }
}

Security配置类

@Configuration
@EnableWebSecurity
public class SecurityConfig {
    private JwtConverter wtConverter;

    public SecurityConfig(JwtConverter jwtConverter) {
        this.jwtConverter = jwtConverter;
    }
    @Bean
    public SecurityFilterChain configure(HttpSecurity http) throws Exception {
        http
            .authorizeRequests()
                .antMatchers("/swagger-ui/**").permitAll()
                .anyRequest().authenticated()
                .and()
            .oauth2ResourceServer()
                .jwt()
                .jwtAuthenticationConverter(jwtConverter);
        return http.build();
    }
}
解决方法
  1. 修正变量拼写错误
    当前SecurityConfig类中存在变量名拼写错误:private JwtConverter wtConverter; 应改为private JwtConverter jwtConverter;,否则会导致依赖注入异常,直接影响配置生效。

  2. 放行Swagger UI全量必要接口
    SpringDoc Swagger UI不仅需要访问/swagger-ui/**路径,还需要获取openapi文档数据的/v3/api-docs/**接口,部分场景下还需放行/swagger-ui.html。修改Security配置的授权规则:

    @Bean
    public SecurityFilterChain configure(HttpSecurity http) throws Exception {
        http
            .authorizeRequests()
                .antMatchers("/swagger-ui/**", "/v3/api-docs/**", "/swagger-ui.html").permitAll()
                .anyRequest().authenticated()
                .and()
            .oauth2ResourceServer()
                .jwt()
                .jwtAuthenticationConverter(jwtConverter);
        return http.build();
    }
    
  3. 关闭CSRF防护(可选)
    若浏览器访问仍存在异常,可能是CSRF拦截导致Swagger UI请求失败。可临时关闭CSRF防护(生产环境需根据业务场景评估风险):

    @Bean
    public SecurityFilterChain configure(HttpSecurity http) throws Exception {
        http
            .csrf().disable()
            .authorizeRequests()
                .antMatchers("/swagger-ui/**", "/v3/api-docs/**", "/swagger-ui.html").permitAll()
                .anyRequest().authenticated()
                .and()
            .oauth2ResourceServer()
                .jwt()
                .jwtAuthenticationConverter(jwtConverter);
        return http.build();
    }
    
验证

修改配置后重启服务,再次访问http://localhost:8080/swagger-ui/index.html即可正常加载页面。若需调用需认证的接口,可通过页面右上角的Authorize按钮输入Token完成授权。

内容的提问来源于stack exchange,提问作者kernel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 22:55:38