You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security未传递PasswordEncoder参数,登录为何自动使用它?

为啥Spring Security会自动用你的BCryptPasswordEncoder验证密码?

这是Spring Security的自动装配机制在起作用:

  • 你已经把BCryptPasswordEncoder注册成了Spring容器里的Bean,而且容器里只有这一个PasswordEncoder类型的Bean。
  • Spring Security的核心认证组件(比如DaoAuthenticationProvider)会自动从容器中查找PasswordEncoder类型的Bean,找到后就会用它来处理登录时的密码比对。
  • 你完全不需要手动把它传递给Security配置,只要容器里存在符合条件的PasswordEncoder Bean,Spring Security就会自动关联使用。

结合你的代码补充说明:
你的登录接口/api/auth/login虽然被webSecurityCustomizer设置为忽略,但实际处理登录的逻辑(比如你自定义的登录认证逻辑)里,只要用到了AuthenticationManager,它内部的认证提供者就会自动调用你注册的BCryptPasswordEncoder来完成密码验证。

内容的提问来源于stack exchange,提问作者gurkan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 03:35:30