Spring Security中antMatchers(String)方法未定义问题求助
Spring Security
antMatchers方法无法识别的修复方案 问题描述
配置Spring Security的SecurityFilterChain时,代码里的antMatchers方法被IDE标红报错:
The method antMatchers(String) is undefined for the type AuthorizeHttpRequestsConfigurer.AuthorizationManagerRequestMatcherRegistry
对应的配置类代码如下:
package com.codewitheshan.blog.config; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.authentication.AuthenticationManager; import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; import org.springframework.security.config.annotation.authentication.configuration.AuthenticationConfiguration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.http.SessionCreationPolicy; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; import org.springframework.security.crypto.password.PasswordEncoder; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter; import com.codewitheshan.blog.security.CustomUserDetailService; import com.codewitheshan.blog.security.JwtAuthenticationEntryPoint; import com.codewitheshan.blog.security.JwtAuthenticationFilter; @Configuration @EnableWebSecurity public class SecurityConfig { @Autowired private CustomUserDetailService customUserDetailService; @Autowired private JwtAuthenticationEntryPoint jwtAuthenticationEntryPoint; @Autowired private JwtAuthenticationFilter jwtAuthenticationFilter; @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .csrf() .disable() .authorizeHttpRequests() .antMatchers("/api/v1/auth/login").permitAll() .anyRequest() .authenticated() .and() .exceptionHandling() .authenticationEntryPoint(this.jwtAuthenticationEntryPoint) .and() .sessionManagement() .sessionCreationPolicy(SessionCreationPolicy.STATELESS); http.addFilterBefore(this.jwtAuthenticationFilter, UsernamePasswordAuthenticationFilter.class); return http.build(); } protected void configure(AuthenticationManagerBuilder auth) throws Exception{ auth.userDetailsService(this.customUserDetailService).passwordEncoder(passwordEncoder()); } @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } @Bean public AuthenticationManager authenticationManagerBean(AuthenticationConfiguration configuration) throws Exception { return configuration.getAuthenticationManager(); } }
修复方法
这报错是因为Spring Security 6.x 版本彻底移除了antMatchers方法,官方统一用requestMatchers替代了旧版本的antMatchers、mvcMatchers等路径匹配方法。
1. 直接替换方法名
把代码里的:
.antMatchers("/api/v1/auth/login").permitAll()
改成:
.requestMatchers("/api/v1/auth/login").permitAll()
2. 进阶:显式指定Ant风格匹配器
如果你的路径用到了*、**这类Ant风格通配符,也可以显式创建AntPathRequestMatcher来确保匹配规则生效:
.requestMatchers(new AntPathRequestMatcher("/api/v1/auth/**")).permitAll()
不过一般直接传字符串路径就行,Spring Security会自动适配匹配规则。
3. 可选:优化配置代码(推荐)
Spring Security 6.x推荐使用Lambda式的配置风格,代码更简洁易读,修改后的filterChain方法如下:
@Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .csrf(csrf -> csrf.disable()) .authorizeHttpRequests(auth -> auth .requestMatchers("/api/v1/auth/login").permitAll() .anyRequest().authenticated() ) .exceptionHandling(ex -> ex .authenticationEntryPoint(this.jwtAuthenticationEntryPoint) ) .sessionManagement(session -> session .sessionCreationPolicy(SessionCreationPolicy.STATELESS) ); http.addFilterBefore(this.jwtAuthenticationFilter, UsernamePasswordAuthenticationFilter.class); return http.build(); }
额外注意
- 确认你的Spring Security版本:如果是6.x及以上,所有路径匹配都要用
requestMatchers,别再用旧方法了。 - 原代码里的
configure(AuthenticationManagerBuilder auth)方法可以删掉,因为Spring Security会自动把CustomUserDetailService和PasswordEncoder关联到认证管理器里,不需要手动配置。
内容的提问来源于stack exchange,提问作者Eshan Akash
相关产品推荐
相关产品推荐

