集成Spring Security后H2 Database控制台无法访问的问题
问题
Spring项目集成H2 Database与Spring Security后,访问http://localhost:8080/h2-console返回401 - Unauthorized错误。已在SecurityConfig的AUTH_WHITE_LIST中添加/h2-console/**路径,Swagger相关路径可正常访问,但H2控制台仍无法访问;仅当白名单改为/**时,H2控制台才可正常打开。
相关配置
pom.xml的H2依赖
<dependency> <groupId>com.h2database</groupId> <artifactId>h2</artifactId> <scope>runtime</scope> </dependency>
application.properties配置
spring.datasource.url=jdbc:h2:file:/data/noNameDB spring.h2.console.enabled=true spring.datasource.driverClassName=org.h2.Driver spring.datasource.username=admin spring.datasource.password=admin spring.jpa.database-platform=org.hibernate.dialect.H2Dialect spring.h2.console.path=/h2-console spring.jpa.show-sql=true spring.jpa.hibernate.ddl-auto=update spring.jackson.serialization.fail-on-empty-beans=false
SecurityConfig代码
import com.example.noName.security.JwtAuthenticationEntryPoint; import com.example.noName.security.JwtAuthenticationFilter; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.authentication.AuthenticationManager; import org.springframework.security.config.annotation.authentication.configuration.AuthenticationConfiguration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.http.SessionCreationPolicy; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; import org.springframework.security.crypto.password.PasswordEncoder; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter; @Configuration @EnableWebSecurity public class SecurityConfig { private static final String[] AUTH_WHITE_LIST = { "/v3/api-docs/**", "/swagger-ui/**", "/v2/api-docs/**", "/swagger-resources/**", "/h2-console/**", "/console/**", "/account/**" }; @Autowired private JwtAuthenticationEntryPoint jwtAuthenticationEntryPoint; @Bean public JwtAuthenticationFilter jwtAuthenticationFilter() { return new JwtAuthenticationFilter(); } @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } @Bean public AuthenticationManager authenticationManager( AuthenticationConfiguration authConfig) throws Exception { return authConfig.getAuthenticationManager(); } @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .cors() .and() .csrf() .disable() .exceptionHandling() .authenticationEntryPoint(jwtAuthenticationEntryPoint) .and() .sessionManagement() .sessionCreationPolicy(SessionCreationPolicy.STATELESS) .and() .authorizeHttpRequests() .requestMatchers(AUTH_WHITE_LIST) .permitAll() .and() .headers() .frameOptions() .disable() .and() .authorizeHttpRequests() .anyRequest() .authenticated() .and() .httpBasic() .and() .addFilterBefore(jwtAuthenticationFilter(), UsernamePasswordAuthenticationFilter.class) .httpBasic(); return http.build(); } }
解决方案
1. 修复重复的授权配置
你的filterChain配置中存在两次authorizeHttpRequests()和两次httpBasic()调用,这会导致白名单的permitAll()规则被后续的anyRequest().authenticated()覆盖。需要将所有授权规则合并到同一个authorizeHttpRequests()块中,确保白名单规则优先级更高。
2. 修改后的SecurityFilterChain配置
替换原有的filterChain方法为以下代码:
@Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .cors() .and() .csrf() .disable() .exceptionHandling() .authenticationEntryPoint(jwtAuthenticationEntryPoint) .and() .sessionManagement() .sessionCreationPolicy(SessionCreationPolicy.STATELESS) .and() .authorizeHttpRequests(auth -> auth .requestMatchers(AUTH_WHITE_LIST) .permitAll() .anyRequest() .authenticated() ) .headers(headers -> headers .frameOptions() .disable() ) .httpBasic() .and() .addFilterBefore(jwtAuthenticationFilter(), UsernamePasswordAuthenticationFilter.class); return http.build(); }
3. 额外检查点
- 确认
spring.h2.console.path=/h2-console配置与白名单中的/h2-console/**路径完全匹配 - 验证JwtAuthenticationFilter没有自定义拦截逻辑覆盖白名单规则
内容的提问来源于stack exchange,提问作者Marc
相关产品推荐
相关产品推荐

