You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security基于角色授权:删除/创建接口403 Forbidden问题

问题:删除库存项及创建新资源时遭遇403 Forbidden错误

我在删除库存项以及在数据库中创建新资源时遇到403 Forbidden错误,以下是我的配置代码和控制器实现:

WebSecurityConfiguration 类

package com.inventoryservice.config;

import org.springframework.context.annotation.Bean;
import org.springframework.http.HttpMethod;
import org.springframework.security.authorization.AuthorityAuthorizationManager;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
import org.springframework.security.crypto.password.NoOpPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;

@EnableWebSecurity
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        auth.inMemoryAuthentication()
                .withUser("test")
                .password("test_pass")
                .roles("ADMIN")
                .and()
                .withUser("store")
                .password("store_pass")
                .roles("USER");
    }

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
                .authorizeHttpRequests()
                    .antMatchers(HttpMethod.DELETE, "/items-management").hasRole("ADMIN")
                    .antMatchers(HttpMethod.POST, "/items-management").hasAnyRole("ADMIN","USER")
                    .antMatchers(HttpMethod.GET, "/items-management").permitAll()
                .anyRequest().authenticated();
    }

    @Bean
    public PasswordEncoder passwordEncoder() {
        return NoOpPasswordEncoder.getInstance();
    }
}

Inventory 控制器

该控制器配置了所有从服务获取数据库记录的端点,代码如下:

package com.inventoryservice.controller;

import com.inventoryservice.dto.request.InventoryRequestDto;
import com.inventoryservice.dto.response.InventoryItemDto;
import com.inventoryservice.dto.response.InventoryResponseDto;
import com.inventoryservice.entity.Inventory;
import com.inventoryservice.service.ItemService;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.http.HttpStatus;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.*;

@RestController
@RequestMapping("/items-management")
public class InventoryController {

    private ItemService itemService;

    @Autowired
    public InventoryController(ItemService itemService) {
        this.itemService = itemService;
    }

    @GetMapping
    public ResponseEntity<InventoryResponseDto> getItems() {
        return new ResponseEntity(
                InventoryResponseDto.builder()
                        .lines(itemService.getItems())
                        .build()
                , HttpStatus.OK
        );
    }

    @PostMapping
    public ResponseEntity<InventoryResponseDto> create(@RequestBody InventoryRequestDto inventory) {
        return new ResponseEntity(
                InventoryResponseDto
                        .builder()
                        .lines(itemService.create(inventory.getLines()))
                        .build()
                , HttpStatus.CREATED
        );
    }

    @DeleteMapping
    public ResponseEntity delete(@RequestBody InventoryItemDto inventoryItemDto) {
        itemService.deleteItems(
                inventoryItemDto.getItemIds()
        );
        return ResponseEntity.ok(inventoryItemDto);
    }
}

内容的提问来源于stack exchange,提问作者Raza Haider

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 08:05:23