升级Spring Boot3.0与Spring Security6.0时Bean依赖异常求助
升级Spring Boot 3.0.0和Spring Security 6.0时Bean依赖注入错误
错误信息
org.springframework.beans.factory.UnsatisfiedDependencyException: Error creating bean with name 'jwtFilter': Unsatisfied dependency expressed through field 'jwtUtility': Error creating bean with name 'jwtUtility': Injection of autowired dependencies failed
提供的WebSecurityConfiguration代码
package com.ims.usermanagement.config; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.authentication.AuthenticationManager; import org.springframework.security.config.annotation.authentication.configuration.AuthenticationConfiguration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.http.SessionCreationPolicy; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; import org.springframework.security.crypto.password.PasswordEncoder; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter; import com.ims.usermanagement.jwt.JwtFilter; @Configuration @EnableWebSecurity public class WebSecurityConfiguration { @Autowired private JwtFilter jwtFilter; @Autowired private AuthEntryPointJwt unauthorizedHandler; @Bean public AuthenticationManager authenticationManager(AuthenticationConfiguration authenticationConfiguration) throws Exception { return authenticationConfiguration.getAuthenticationManager(); } @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(11); } @Bean public SecurityFilterChain configure(HttpSecurity http) throws Exception { http.cors().and().csrf().disable() .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS).and() .exceptionHandling().authenticationEntryPoint(unauthorizedHandler).and() .authorizeHttpRequests() .requestMatchers("/authenticate/") .permitAll() .requestMatchers("/utilisateur/photos/{id}") .permitAll() .requestMatchers("/discussion/attachment/{id}") .permitAll() .requestMatchers("/retrait/file/{id}/{name}") .permitAll() .requestMatchers("/client/photos/{id}") .permitAll() .requestMatchers("/partenaire/photos/{id}") .permitAll() .requestMatchers("/resetPassword") .permitAll() .requestMatchers("/resetPassword/reset") .permitAll() .requestMatchers("/autopayment/\\?token=.*$") .permitAll() .anyRequest() .authenticated(); http.addFilterBefore(jwtFilter, UsernamePasswordAuthenticationFilter.class); return http.build(); } }
排查及解决步骤
- 检查JwtUtility的Spring注册状态:确认
JwtUtility类上是否添加了@Component、@Service等Spring组件注解,只有被标记的类才会被Spring容器扫描并创建Bean。 - 排查JwtUtility内部依赖:查看
JwtUtility中的@Autowired字段,确保这些依赖同样被Spring注册为Bean,比如JWT密钥配置、解析工具类等,缺失的话需要补充对应的@Bean定义或组件注解。 - 确认组件扫描范围:检查项目主启动类的
@SpringBootApplication注解是否覆盖了JwtUtility所在的包路径,若未覆盖,需添加@ComponentScan指定扫描的包范围。 - 调整JwtFilter的注入方式:避免直接
@Autowired注入JwtFilter,改为在配置类中通过@Bean方式创建实例并传入依赖:
同时删除原有的@Bean public JwtFilter jwtFilter(JwtUtility jwtUtility) { return new JwtFilter(jwtUtility); }@Autowired private JwtFilter jwtFilter;,这种方式能确保依赖注入的顺序和正确性,避免初始化时机问题。 - 修正Spring Security 6.0路径匹配:代码中
"/autopayment/\\?token=.*$"的路径匹配可能不符合Spring Security 6.0的规则,建议改为MvcRequestMatcher处理带参数的路径,或者简化为"/autopayment/**"(根据实际业务需求调整),例如:.requestMatchers(MvcRequestMatcher.antMatcher("/autopayment/**")).permitAll()
内容的提问来源于stack exchange,提问作者Veron
相关产品推荐
相关产品推荐

