You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 2.3.2默认Security配置禁用失败,求助排查问题

Why Spring Security's Default Authentication Isn't Disabling for You

Hey there! Let's break down why your attempt to turn off Spring Security's default authentication isn't working, and fix it step by step.

Key Issues in Your Setup

1. @EnableWebSecurity is overriding your auto-configuration exclusion

When you add @EnableWebSecurity to your main application class, you're manually enabling Spring Security's core framework—even though you excluded SecurityAutoConfiguration. Without a custom security configuration, Spring Security falls back to its default rules: requiring authentication for all incoming requests. That's exactly why you're still seeing the default auth prompt.

2. Typo in your application.properties

You have a small typo in the password property:

spring.security.user.passward=xpassword

It should be password instead of passward. That said, this typo doesn't affect your current setup because you excluded SecurityAutoConfiguration (the component that reads these properties to create a default user).

Fixes Based on Your Needs

Option 1: Completely Disable Spring Security (No Authentication Required)

If you don't want any security checks at all, remove the @EnableWebSecurity annotation and keep the exclusion of SecurityAutoConfiguration:

@SpringBootApplication(exclude={SecurityAutoConfiguration.class})
public class SpringBasicSecurityApplication {
    public static void main(String[] args) {
        SpringApplication.run(SpringBasicSecurityApplication.class, args);
    }
}

This will turn off Spring Security entirely, so your /rest/auth/getMsg endpoint will be accessible without any authentication prompts.

Option 2: Customize Basic Authentication (Replace Default Auth)

If you want to implement your own Basic Auth instead of using the default, keep @EnableWebSecurity but add a custom security configuration. Here's how:

  1. (Optional) Remove the exclusion of SecurityAutoConfiguration (it won't conflict with your custom config)
  2. Create a custom security configuration class:
@Configuration
@EnableWebSecurity
public class CustomSecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            // Require authentication for all requests (adjust this rule as needed)
            .authorizeHttpRequests(auth -> auth.anyRequest().authenticated())
            // Enable Basic Authentication
            .httpBasic(Customizer.withDefaults());
        
        return http.build();
    }

    // Define your own user store (replace with a database-backed service in production)
    @Bean
    public UserDetailsService userDetailsService() {
        UserDetails user = User.withUsername("xusername")
            // Use {noop} for plain-text passwords (never use this in production! Use BCrypt instead)
            .password("{noop}xpassword")
            .roles("USER")
            .build();
        
        return new InMemoryUserDetailsManager(user);
    }
}
  1. Fix the typo in application.properties if you prefer using those properties instead of hardcoding (requires keeping SecurityAutoConfiguration):
spring.security.user.name=xusername
spring.security.user.password=xpassword
server.port=8081
logging.level.org.springframework.boot.autoconfigure.security=INFO

内容的提问来源于stack exchange,提问作者Skyfall

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 20:07:39