You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SpringBoot 3.0.1中登录接口报Full authentication is required错误排查

解决SpringBoot 3.0.1 + Java17登录接口返回「Full authentication is required to access this resource」问题

以下是针对该问题的排查和解决步骤:

1. 检查Spring Security配置是否放行登录接口

SpringBoot 3.x已废弃WebSecurityConfigurerAdapter,需使用SecurityFilterChain配置权限规则,务必确保登录接口被放行:

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http.csrf(csrf -> csrf.disable())
            .authorizeHttpRequests(auth -> auth
                // 替换为你的实际登录接口路径
                .requestMatchers("/api/auth/login").permitAll()
                .anyRequest().authenticated()
            );
        return http.build();
    }

    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }
}

若登录接口仍被拦截,检查是否存在其他Security配置类冲突,或路径匹配规则是否正确(比如是否包含应用上下文路径)。

2. 确保登录接口逻辑不依赖已认证上下文

你的需求是通过登录接口生成JWT并存入Cookie,因此登录接口需先手动验证用户名密码,再生成Token,而非依赖Security的自动认证流程:

@RestController
@RequestMapping("/api/auth")
public class AuthController {

    private final UserDetailsService userDetailsService;
    private final PasswordEncoder passwordEncoder;
    private final JwtTokenUtil jwtTokenUtil;

    // 构造注入依赖
    public AuthController(UserDetailsService userDetailsService, PasswordEncoder passwordEncoder, JwtTokenUtil jwtTokenUtil) {
        this.userDetailsService = userDetailsService;
        this.passwordEncoder = passwordEncoder;
        this.jwtTokenUtil = jwtTokenUtil;
    }

    @PostMapping("/login")
    public ResponseEntity<String> login(@RequestBody LoginRequest request, HttpServletResponse response) {
        // 1. 加载用户信息
        UserDetails userDetails = userDetailsService.loadUserByUsername(request.getUsername());
        // 2. 验证密码
        if (!passwordEncoder.matches(request.getPassword(), userDetails.getPassword())) {
            return ResponseEntity.badRequest().body("用户名或密码错误");
        }
        // 3. 生成JWT Token
        String token = jwtTokenUtil.generateToken(userDetails);
        // 4. 将Token写入Cookie
        Cookie jwtCookie = new Cookie("JWT-TOKEN", token);
        jwtCookie.setHttpOnly(true); // 防止XSS窃取
        jwtCookie.setPath("/");
        jwtCookie.setMaxAge(7 * 24 * 60 * 60); // 7天有效期
        response.addCookie(jwtCookie);
        
        return ResponseEntity.ok("登录成功");
    }
}

LoginRequest为简单DTO类,包含username和password字段即可。

3. 检查Postman请求配置

  • 确保登录接口使用POST请求,请求体为JSON格式,正确传入username和password参数
  • 测试前清除Postman中该域名下的旧Cookie,避免无效Cookie导致拦截
  • 若开启了CSRF防护(上述配置已禁用),需确保请求头携带CSRF Token,但登录接口放行后一般无需配置

4. 验证依赖版本兼容性

SpringBoot 3.0.1对应Spring Security 6.0.x,JWT依赖需选用适配Java17和Spring6的版本,推荐使用jjwt 0.11.5+:

<!-- pom.xml 依赖 -->
<dependency>
    <groupId>io.jsonwebtoken</groupId>
    <artifactId>jjwt-api</artifactId>
    <version>0.11.5</version>
</dependency>
<dependency>
    <groupId>io.jsonwebtoken</groupId>
    <artifactId>jjwt-impl</artifactId>
    <version>0.11.5</version>
    <scope>runtime</scope>
</dependency>
<dependency>
    <groupId>io.jsonwebtoken</groupId>
    <artifactId>jjwt-jackson</artifactId>
    <version>0.11.5</version>
    <scope>runtime</scope>
</dependency>

Gradle对应配置:

implementation 'io.jsonwebtoken:jjwt-api:0.11.5'
runtimeOnly 'io.jsonwebtoken:jjwt-impl:0.11.5'
runtimeOnly 'io.jsonwebtoken:jjwt-jackson:0.11.5'

5. 排查配置文件中的默认Security配置

若application.yml或application.properties中配置了默认Security用户,会启用默认登录逻辑,可能干扰自定义接口,建议删除:

# 若存在以下配置,建议移除
spring:
  security:
    user:
      name: admin
      password: admin

内容的提问来源于stack exchange,提问作者sriram chenniapan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 04:05:37