You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security中WebExpressionVoter的表达式选择逻辑及全评估方法

Understanding Spring Security's Expression Evaluation Logic & Fixing Your Issue

Hey there! Let's break down why your denyAll() expression isn't being evaluated, and how to get Spring Security to process all the rules you intend.

Why Only authenticated() Is Being Evaluated

Spring Security's HttpSecurity configuration is order-sensitive—it checks request matching rules in the exact order you define them. Here's what's happening with your current setup:

// ... 
.anyRequest().authenticated() 
.antMatcher("/*").denyAll() 
// ...

The anyRequest() matcher is a catch-all that matches every possible HTTP request. Since it's placed before your antMatcher("/*"), Spring Security stops at the first matching rule (the authenticated() one) and never gets to evaluate the denyAll() rule.

WebExpressionVoter only processes the expression associated with the first successfully matched security rule—so your denyAll() is never even considered because the request was already matched by anyRequest().

How to Get All Expressions Evaluated

To fix this, you need to adjust your rule order and structure to ensure the right rules are matched at the right time:

1. Prioritize Specific Matchers Over Broad Ones

Always place more specific matchers (like antMatcher("/*")) before broad ones (like anyRequest()). This way, the specific rule gets checked first, and the broad rule acts as a fallback. For your use case, the correct order would be:

@Override
protected void configure(HttpSecurity http) throws Exception {
    http
        // First, match the root path and deny all access
        .antMatcher("/*")
            .access("denyAll()")
        // Then, match all other requests and require authentication
        .antMatcher("/**")
            .authenticated();
}

2. Combine Multiple Expressions in a Single Rule

If you want multiple conditions to apply to the same request, use SpEL logical operators to combine them in a single access() call. For example, if you wanted to require authentication and block a specific IP:

.anyRequest()
    .access("authenticated() && !hasIpAddress('192.168.1.1')");

WebExpressionVoter will evaluate this combined expression as a single unit, checking all conditions at once.

3. Use Mutex Matchers

Make sure your matchers don't overlap unnecessarily. If two matchers cover the same requests, only the first one will be used. Structure your rules so each matcher targets a distinct set of requests.

Key Takeaways

  • Order matters: Specific rules first, broad rules last.
  • anyRequest() is a fallback: Always put it at the end of your configuration.
  • Combine expressions with SpEL: Use &&, ||, and ! to bundle multiple conditions into one rule when they apply to the same requests.

内容的提问来源于stack exchange,提问作者Lauren

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 07:02:55