Spring Boot中WebSecurityConfigurerAdapter不存在及相关方法报错求助
Spring Security 弃用WebSecurityConfigurerAdapter后的JWT认证配置修复方案
你的问题核心是Spring Security 5.7.0及以上版本已弃用WebSecurityConfigurerAdapter类,同时旧版的authorizeRequests()方法也被标记为过时,导致你原来基于继承WebSecurityConfigurerAdapter的配置方式失效。以下是适配新版本的完整修复代码及改动说明:
修复后的完整配置代码
import org.springframework.beans.factory.annotation.Autowired; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.authentication.AuthenticationManager; import org.springframework.security.authentication.AuthenticationProvider; import org.springframework.security.authentication.dao.DaoAuthenticationProvider; import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.http.SessionCreationPolicy; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; import org.springframework.security.crypto.password.PasswordEncoder; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter; import com.unze.sis.security.jwt.AuthEntryPointJwt; import com.unze.sis.security.jwt.AuthTokenFilter; import com.unze.sis.security.services.UserDetailsServiceImpl; @Configuration @EnableWebSecurity @EnableGlobalMethodSecurity( prePostEnabled = true) public class WebSecurityConfig { @Autowired UserDetailsServiceImpl userDetailsService; @Autowired private AuthEntryPointJwt unauthorizedHandler; @Bean public AuthTokenFilter authenticationJwtTokenFilter() { return new AuthTokenFilter(); } @Bean public AuthenticationProvider authenticationProvider() { DaoAuthenticationProvider authProvider = new DaoAuthenticationProvider(); authProvider.setUserDetailsService(userDetailsService); authProvider.setPasswordEncoder(passwordEncoder()); return authProvider; } @Bean public AuthenticationManager authenticationManager(HttpSecurity http) throws Exception { return http.getSharedObject(AuthenticationManagerBuilder.class) .authenticationProvider(authenticationProvider()) .build(); } @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http.cors().and().csrf().disable() .exceptionHandling().authenticationEntryPoint(unauthorizedHandler).and() .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS).and() .authorizeHttpRequests(auth -> auth .requestMatchers("/api/auth/**", "/api/test/**").permitAll() .anyRequest().authenticated()); http.addFilterBefore(authenticationJwtTokenFilter(), UsernamePasswordAuthenticationFilter.class); http.authenticationProvider(authenticationProvider()); return http.build(); } }
关键改动说明
- 移除WebSecurityConfigurerAdapter继承:新版本Spring Security推荐使用
SecurityFilterChainBean替代继承式配置 - 替换AuthenticationManager配置:通过
AuthenticationManagerBuilder和DaoAuthenticationProvider来配置用户认证逻辑,替代原来重写configure(AuthenticationManagerBuilder)和authenticationManagerBean()的方式 - 替换URL授权配置:用
authorizeHttpRequests()替代过时的authorizeRequests(),用requestMatchers()替代antMatchers()(新版本中antMatchers()仍可兼容,但requestMatchers()是官方推荐的新方法) - 保留原有核心逻辑:CORS配置、CSRF禁用、无状态会话、JWT过滤器添加等原有JWT认证的核心逻辑完全保留
内容的提问来源于stack exchange,提问作者Nedim
相关产品推荐
相关产品推荐

