Spring项目引入AuthenticationManager Bean后构建失败求助
我使用Gradle 7.5构建Spring Boot 2.7.3项目(WebSecurityConfigurerAdapter已废弃),只要保留AuthenticationManager Bean,构建就失败;移除该Bean后构建正常。即使加上--debug和--stacktrace参数,也没找到明确的错误日志,唯一能看到的错误信息是测试任务失败:
> Task :test FAILED FAILURE: Build failed with an exception. * What went wrong: Execution failed for task ':test'. > There were failing tests. See the report at: file:///C:/Users/patrick/Desktop/WidePeepoHappy/build/reports/tests/test/index.html * Try: > Run with --stacktrace option to get the stack trace. > Run with --info or --debug option to get more log output. > Run with --scan to get full insights. * Get more help at https://help.gradle.org Deprecated Gradle features were used in this build, making it incompatible with Gradle 8.0. You can use '--warning-mode all' to show the individual deprecation warnings and determine if they come from your own scripts or plugins. See https://docs.gradle.org/7.5/userguide/command_line_interface.html#sec:command_line_warnings BUILD FAILED in 21s 10 actionable tasks: 3 executed, 7 up-to-date
我的Spring Security配置代码如下:
@Configuration @EnableWebSecurity @EnableGlobalMethodSecurity(prePostEnabled = true) public class SpringSecurityConfig { @Autowired private UserDetailServiceImpl userDetailService; @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } @Bean public AuthenticationManager authenticationManager(AuthenticationConfiguration authenticationConfiguration) throws Exception { return authenticationConfiguration.getAuthenticationManager(); } @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { return http.csrf().disable() .authorizeHttpRequests((requests) -> requests.antMatchers("/**").permitAll()) .logout(LogoutConfigurer::permitAll) .build(); } }
引发问题的就是这个AuthenticationManager Bean定义:
@Bean public AuthenticationManager authenticationManager(AuthenticationConfiguration authenticationConfiguration) throws Exception { return authenticationConfiguration.getAuthenticationManager(); }
解决方案
问题出在手动暴露AuthenticationManager Bean时,Spring Security需要确保UserDetailsService能被正确关联到认证流程,但当前配置仅注入了UserDetailServiceImpl,未完成关联配置。可以通过以下两种方式修复:
关联UserDetailsService到认证流程
在配置类中注入AuthenticationManagerBuilder,手动设置UserDetailsService和PasswordEncoder,确保AuthenticationManager能正确获取用户信息:@Configuration @EnableWebSecurity @EnableGlobalMethodSecurity(prePostEnabled = true) public class SpringSecurityConfig { @Autowired private UserDetailServiceImpl userDetailService; @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } @Autowired public void configureAuthentication(AuthenticationManagerBuilder auth) throws Exception { auth.userDetailsService(userDetailService) .passwordEncoder(passwordEncoder()); } @Bean public AuthenticationManager authenticationManager(AuthenticationConfiguration authenticationConfiguration) throws Exception { return authenticationConfiguration.getAuthenticationManager(); } @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { return http.csrf().disable() .authorizeHttpRequests((requests) -> requests.antMatchers("/**").permitAll()) .logout(LogoutConfigurer::permitAll) .build(); } }依赖自动配置简化代码
如果没有自定义认证流程的特殊需求,可以直接移除手动定义的AuthenticationManager Bean。Spring Boot的自动配置会识别已注册的UserDetailServiceImpl和PasswordEncoder Bean,自动完成AuthenticationManager的配置。
另外,构建失败提示是测试任务失败,建议打开错误日志中给出的测试报告页面,查看具体的测试失败详情,比如是否是测试类加载Spring上下文时出现依赖缺失,这能更精准定位问题。
内容的提问来源于stack exchange,提问作者Patrick

