Spring Boot 2.3.2默认Security配置禁用失败,求助排查问题
Hey there! Let's break down why your attempt to turn off Spring Security's default authentication isn't working, and fix it step by step.
Key Issues in Your Setup
1. @EnableWebSecurity is overriding your auto-configuration exclusion
When you add @EnableWebSecurity to your main application class, you're manually enabling Spring Security's core framework—even though you excluded SecurityAutoConfiguration. Without a custom security configuration, Spring Security falls back to its default rules: requiring authentication for all incoming requests. That's exactly why you're still seeing the default auth prompt.
2. Typo in your application.properties
You have a small typo in the password property:
spring.security.user.passward=xpassword
It should be password instead of passward. That said, this typo doesn't affect your current setup because you excluded SecurityAutoConfiguration (the component that reads these properties to create a default user).
Fixes Based on Your Needs
Option 1: Completely Disable Spring Security (No Authentication Required)
If you don't want any security checks at all, remove the @EnableWebSecurity annotation and keep the exclusion of SecurityAutoConfiguration:
@SpringBootApplication(exclude={SecurityAutoConfiguration.class}) public class SpringBasicSecurityApplication { public static void main(String[] args) { SpringApplication.run(SpringBasicSecurityApplication.class, args); } }
This will turn off Spring Security entirely, so your /rest/auth/getMsg endpoint will be accessible without any authentication prompts.
Option 2: Customize Basic Authentication (Replace Default Auth)
If you want to implement your own Basic Auth instead of using the default, keep @EnableWebSecurity but add a custom security configuration. Here's how:
- (Optional) Remove the exclusion of
SecurityAutoConfiguration(it won't conflict with your custom config) - Create a custom security configuration class:
@Configuration @EnableWebSecurity public class CustomSecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http // Require authentication for all requests (adjust this rule as needed) .authorizeHttpRequests(auth -> auth.anyRequest().authenticated()) // Enable Basic Authentication .httpBasic(Customizer.withDefaults()); return http.build(); } // Define your own user store (replace with a database-backed service in production) @Bean public UserDetailsService userDetailsService() { UserDetails user = User.withUsername("xusername") // Use {noop} for plain-text passwords (never use this in production! Use BCrypt instead) .password("{noop}xpassword") .roles("USER") .build(); return new InMemoryUserDetailsManager(user); } }
- Fix the typo in
application.propertiesif you prefer using those properties instead of hardcoding (requires keepingSecurityAutoConfiguration):
spring.security.user.name=xusername spring.security.user.password=xpassword server.port=8081 logging.level.org.springframework.boot.autoconfigure.security=INFO
内容的提问来源于stack exchange,提问作者Skyfall

