You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署在Google Cloud Run的Angular/Spring应用Chrome访问出现403错误

问题排查与解决方案

1. 修正Spring Security的Ant匹配规则

你当前配置的/**.js是Ant语法的错误写法,它实际匹配的是所有目录下名为.js的空文件名文件,而非任意路径下的.js后缀文件。正确的匹配规则应该覆盖根目录和子目录下的所有JS文件:

http.authorizeRequests()
    .antMatchers("/", "/index.html", "/*.js", "/**/*.js", "/*.css", "/**/*.css").permitAll()

或者更精准匹配Angular打包后的核心JS文件:

http.authorizeRequests()
    .antMatchers("/", "/index.html", "/runtime*.js", "/polyfills*.js", "/main*.js", "/*.css", "/**/*.css").permitAll()

2. 关闭静态资源的CSRF校验

Spring Security默认开启CSRF防护,虽然通常不拦截GET请求,但Chrome的请求头可能触发了异常校验。可以对静态资源路径忽略CSRF:

http.csrf()
    .ignoringAntMatchers("/", "/index.html", "/*.js", "/**/*.js", "/*.css", "/**/*.css")
    .and()
    .authorizeRequests()
    .antMatchers("/", "/index.html", "/*.js", "/**/*.js", "/*.css", "/**/*.css").permitAll()
    // 补充其他权限配置

3. 检查Chrome缓存与无痕模式测试

Chrome可能缓存了旧的认证相关资源,导致请求异常。尝试用无痕模式访问应用,如果正常,则清除Chrome的缓存后再测试。

4. 验证响应头的CSP设置

Chrome对Content-Security-Policy(CSP)的执行比Firefox更严格。在Chrome开发者工具的Network面板中,查看这三个JS文件的响应头,确认是否存在Content-Security-Policy头,且脚本源(script-src)允许加载当前域名的资源。如果CSP限制过严,可在Spring Security中添加宽松的CSP配置(或临时关闭用于测试):

http.headers()
    .contentSecurityPolicy("default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'")

5. 确认Cloud Run的静态资源路径映射

确保Spring Boot正确映射了Angular打包后的静态资源:

  • Angular打包后的文件应放在src/main/resources/static目录下
  • 验证Spring Boot的application.properties中是否配置了正确的静态资源路径(默认无需额外配置)

内容的提问来源于stack exchange,提问作者lukas99

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 11:55:20