SpringBoot 3.0.1中登录接口报Full authentication is required错误排查
解决SpringBoot 3.0.1 + Java17登录接口返回「Full authentication is required to access this resource」问题
以下是针对该问题的排查和解决步骤:
1. 检查Spring Security配置是否放行登录接口
SpringBoot 3.x已废弃WebSecurityConfigurerAdapter,需使用SecurityFilterChain配置权限规则,务必确保登录接口被放行:
@Configuration @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http.csrf(csrf -> csrf.disable()) .authorizeHttpRequests(auth -> auth // 替换为你的实际登录接口路径 .requestMatchers("/api/auth/login").permitAll() .anyRequest().authenticated() ); return http.build(); } @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } }
若登录接口仍被拦截,检查是否存在其他Security配置类冲突,或路径匹配规则是否正确(比如是否包含应用上下文路径)。
2. 确保登录接口逻辑不依赖已认证上下文
你的需求是通过登录接口生成JWT并存入Cookie,因此登录接口需先手动验证用户名密码,再生成Token,而非依赖Security的自动认证流程:
@RestController @RequestMapping("/api/auth") public class AuthController { private final UserDetailsService userDetailsService; private final PasswordEncoder passwordEncoder; private final JwtTokenUtil jwtTokenUtil; // 构造注入依赖 public AuthController(UserDetailsService userDetailsService, PasswordEncoder passwordEncoder, JwtTokenUtil jwtTokenUtil) { this.userDetailsService = userDetailsService; this.passwordEncoder = passwordEncoder; this.jwtTokenUtil = jwtTokenUtil; } @PostMapping("/login") public ResponseEntity<String> login(@RequestBody LoginRequest request, HttpServletResponse response) { // 1. 加载用户信息 UserDetails userDetails = userDetailsService.loadUserByUsername(request.getUsername()); // 2. 验证密码 if (!passwordEncoder.matches(request.getPassword(), userDetails.getPassword())) { return ResponseEntity.badRequest().body("用户名或密码错误"); } // 3. 生成JWT Token String token = jwtTokenUtil.generateToken(userDetails); // 4. 将Token写入Cookie Cookie jwtCookie = new Cookie("JWT-TOKEN", token); jwtCookie.setHttpOnly(true); // 防止XSS窃取 jwtCookie.setPath("/"); jwtCookie.setMaxAge(7 * 24 * 60 * 60); // 7天有效期 response.addCookie(jwtCookie); return ResponseEntity.ok("登录成功"); } }
LoginRequest为简单DTO类,包含username和password字段即可。
3. 检查Postman请求配置
- 确保登录接口使用POST请求,请求体为JSON格式,正确传入
username和password参数 - 测试前清除Postman中该域名下的旧Cookie,避免无效Cookie导致拦截
- 若开启了CSRF防护(上述配置已禁用),需确保请求头携带CSRF Token,但登录接口放行后一般无需配置
4. 验证依赖版本兼容性
SpringBoot 3.0.1对应Spring Security 6.0.x,JWT依赖需选用适配Java17和Spring6的版本,推荐使用jjwt 0.11.5+:
<!-- pom.xml 依赖 --> <dependency> <groupId>io.jsonwebtoken</groupId> <artifactId>jjwt-api</artifactId> <version>0.11.5</version> </dependency> <dependency> <groupId>io.jsonwebtoken</groupId> <artifactId>jjwt-impl</artifactId> <version>0.11.5</version> <scope>runtime</scope> </dependency> <dependency> <groupId>io.jsonwebtoken</groupId> <artifactId>jjwt-jackson</artifactId> <version>0.11.5</version> <scope>runtime</scope> </dependency>
Gradle对应配置:
implementation 'io.jsonwebtoken:jjwt-api:0.11.5' runtimeOnly 'io.jsonwebtoken:jjwt-impl:0.11.5' runtimeOnly 'io.jsonwebtoken:jjwt-jackson:0.11.5'
5. 排查配置文件中的默认Security配置
若application.yml或application.properties中配置了默认Security用户,会启用默认登录逻辑,可能干扰自定义接口,建议删除:
# 若存在以下配置,建议移除 spring: security: user: name: admin password: admin
内容的提问来源于stack exchange,提问作者sriram chenniapan
相关产品推荐
相关产品推荐

