You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot中Vaadin与REST API并行多认证配置问题

问题分析与解决方案

你当前的问题核心是两个SecurityFilterChain没有明确划分请求匹配范围,被@Order(1)标记的过滤器链会默认匹配所有HTTP请求,导致后续@Order(2)的过滤器链完全没有执行机会——不管认证成功还是失败,请求都被第一个过滤器链处理完毕,不会流转到下一个。

修复方案:为每个过滤器链指定明确的请求匹配规则

你需要给restFilterChain添加请求匹配规则,限定它只处理/api/**路径的请求;同时给frontendFilterChain指定互补的匹配范围,这样Spring Security才能根据请求路径正确分发到对应的过滤器链。

修改后的完整配置代码:

@EnableWebSecurity
public class SecurityConfiguration extends VaadinWebSecurity {

    // ... 其他代码(比如authTokenFilter的定义、UserDetailsService等) ...

    @Bean
    @Order(1)
    public SecurityFilterChain restFilterChain(HttpSecurity http) throws Exception {
        return http
                // 仅匹配/api/**路径的请求
                .requestMatcher(new AntPathRequestMatcher("/api/**"))
                .cors().and()
                .csrf().disable()
                .authorizeRequests(auth -> auth
                        .antMatchers("/api/login").anonymous()
                        .anyRequest().authenticated()
                )
                .sessionManagement(session -> session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
                .addFilterBefore(authTokenFilter(), UsernamePasswordAuthenticationFilter.class)
                .build();
    }

    @Bean
    @Order(2)
    public SecurityFilterChain frontendFilterChain(HttpSecurity http) throws Exception {
        // 匹配除/api/**之外的所有请求
        http.requestMatcher(new NegatedRequestMatcher(new AntPathRequestMatcher("/api/**")));
        
        super.configure(http);
        setLoginView(http, LoginView.class, LOGOUT_URL);

        return http.build();
    }
}

关键说明

  • requestMatcher(new AntPathRequestMatcher("/api/**")):明确指定该过滤器链只处理以/api/开头的请求,非/api路径的请求会跳过它,流转到下一个优先级的过滤器链。
  • NegatedRequestMatcher:实现反向匹配,让前端过滤器链处理所有非/api路径的请求,与REST接口的过滤器链范围完全互补。
  • 若不指定requestMatcher,每个过滤器链都会默认匹配所有请求,Spring Security会优先使用@Order值最小的那个,后续过滤器链永远不会被触发——这就是你遇到问题的核心原因。

额外注意:

  • 确保JWT过滤器authTokenFilter仅在REST接口的过滤器链中生效,避免干扰Vaadin的表单认证流程。
  • Vaadin的super.configure(http)已自动处理Vaadin相关的安全规则(如静态资源忽略、内部路径权限等),无需重复配置。

内容的提问来源于stack exchange,提问作者Chris

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 02:50:50