You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Spring Security保护@PostMapping端点并解决GET请求401问题

Spring Security权限配置问题排查与解决

问题背景

需要实现以下权限控制:

  • TestController中/test的POST接口仅允许已认证用户访问
  • /test的GET接口对所有人开放
  • 已为/shapes、/shapes/history的GET接口配置permitAll,但未认证访问仍返回401 Unauthorized

相关代码

TestController

@RestController
@RequestMapping("/test")
@RequiredArgsConstructor
public class TestController {

    @PostMapping
    public ResponseEntity post() {
        ...
    }

    @GetMapping
    public ResponseEntity get() {
        ...
    }
}

初始Security配置

@Configuration
@EnableWebSecurity
@RequiredArgsConstructor
public class MyWebSecurityConfig extends WebSecurityConfigurerAdapter {
    private final MyUserDetailsService myUserDetailsService;

    @Override
    public void configure(HttpSecurity http) throws Exception {
        http.httpBasic().and()
            .cors().and().csrf().disable()
            .authorizeRequests()
            .antMatchers("/users", "/users/**").permitAll()
            .anyRequest().authenticated();
    }
}

更新后的Security配置

@Override
public void configure(HttpSecurity http) throws Exception {
    http.httpBasic().and()
            .cors().and().csrf().disable()
            .authorizeRequests()
            .antMatchers("/users", "/users/**").permitAll()
            .antMatchers(HttpMethod.GET, "/shapes").permitAll()
            .antMatchers(HttpMethod.GET, "/shapes/history").permitAll()
            .anyRequest().authenticated();
}

问题分析

Spring Security的规则匹配是从上到下依次执行,一旦匹配到对应规则就停止后续判断。当前配置存在两个核心问题:

  1. 未对/test的GET请求添加permitAll规则,导致该请求被最后一条anyRequest().authenticated()规则拦截
  2. 需确认HttpMethod的导入是否为org.springframework.http.HttpMethod,若导入错误会导致方法匹配失效

解决方案

修正后的完整Security配置

@Configuration
@EnableWebSecurity
@RequiredArgsConstructor
public class MyWebSecurityConfig extends WebSecurityConfigurerAdapter {
    private final MyUserDetailsService myUserDetailsService;

    @Override
    public void configure(HttpSecurity http) throws Exception {
        http.httpBasic()
            .and()
            .cors()
            .and()
            .csrf().disable()
            .authorizeRequests()
            // 允许/users相关路径所有请求
            .antMatchers("/users", "/users/**").permitAll()
            // 允许/test的GET请求
            .antMatchers(HttpMethod.GET, "/test").permitAll()
            // 合并/shapes相关GET请求的permitAll规则
            .antMatchers(HttpMethod.GET, "/shapes", "/shapes/history").permitAll()
            // 剩余所有请求必须认证
            .anyRequest().authenticated();
    }

    // 配置AuthenticationManager,确保自定义UserDetailsService生效
    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        auth.userDetailsService(myUserDetailsService);
    }
}

额外排查点

  1. 路径匹配准确性:如果应用配置了上下文路径(如server.servlet.context-path=/app),需在规则中加上上下文路径,例如/app/test
  2. 配置类冲突:确保项目中只有一个标注@EnableWebSecurity的配置类,避免多配置冲突
  3. 缓存影响:测试时使用无痕模式或清除浏览器缓存,避免之前的认证会话缓存干扰结果
  4. CORS配置:若前端跨域请求,需确保CORS配置正确,避免权限判断被跨域前置检查拦截

内容的提问来源于stack exchange,提问作者Lulex97

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 07:50:25