You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security LDAP认证时springSecurityFilterChain Bean创建失败求助

Hey Anita, let's work through this Spring Security LDAP authentication issue step by step—here's how to fix the missing springSecurityFilterChain bean and related errors:

1. First, Fix the NoClassDefFoundError (Root Cause Clue)

Your error cuts off, but NoClassDefFoundError almost always means a missing dependency. Double-check your build file to ensure you have all required Spring Security and web dependencies:

For Maven (add to pom.xml):

<!-- Spring Security Web core (required for filter chain) -->
<dependency>
    <groupId>org.springframework.security</groupId>
    <artifactId>spring-security-web</artifactId>
    <version>your-spring-security-version</version>
</dependency>
<!-- Spring Security LDAP support -->
<dependency>
    <groupId>org.springframework.security</groupId>
    <artifactId>spring-security-ldap</artifactId>
    <version>your-spring-security-version</version>
</dependency>
<!-- Spring Web (required for servlet filter integration) -->
<dependency>
    <groupId>org.springframework</groupId>
    <artifactId>spring-web</artifactId>
    <version>your-spring-version</version>
</dependency>

For Gradle (add to build.gradle):

implementation 'org.springframework.security:spring-security-web:your-spring-security-version'
implementation 'org.springframework.security:spring-security-ldap:your-spring-security-version'
implementation 'org.springframework:spring-web:your-spring-version'

2. Fix the SecurityWebApplicationInitializer Placement & Usage

Your initializer class needs to be in a package that Spring can scan. Here's what to do:

  • Place it in the same package as your LdapSecurityConfig (or a subpackage) so Spring picks it up automatically.
  • If you're using Spring Boot, you don't need this class at all—Spring Boot auto-registers the security filter chain for you. Delete it entirely if this is a Boot project.
  • If you're using a traditional Spring MVC project, keep the class but ensure it references your config correctly:
// Put this in com.yourcompany.security (same package as LdapSecurityConfig)
public class SecurityWebApplicationInitializer extends AbstractSecurityWebApplicationInitializer {
    public SecurityWebApplicationInitializer() {
        super(LdapSecurityConfig.class); // Use YOUR config class, not WebSecurityConfiguration
    }
}

3. Simplify Your LdapSecurityConfig (Remove Redundant Annotations)

You're using conflicting/unnecessary annotations that can confuse Spring's auto-configuration:

@Configuration
@EnableWebSecurity // This single annotation replaces @EnableGlobalAuthentication and @Import(WebSecurityConfiguration.class)
// Remove @Import({ WebSecurityConfiguration.class }) and @EnableGlobalAuthentication—they're redundant
// Keep @Import({ SecurityConfig.class }) only if SecurityConfig is a required separate config
public class LdapSecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        SavedRequestAwareAuthenticationSuccessHandler successHandler = new SavedRequestAwareAuthenticationSuccessHandler();
        successHandler.setAlwaysUseDefaultTargetUrl(true);
        successHandler.setTargetUrlParameter("/");
        http
                .requiresChannel().anyRequest().requiresInsecure().and()
                .authorizeRequests()
                .anyRequest().permitAll()
                .and()
                .formLogin()
                .loginPage("/login_form")
                .loginProcessingUrl("/login")
                .successHandler(successHandler)
                .failureUrl("/login_form?error")
                .and()
                .logout().logoutSuccessUrl("/login_form")
                .and()
                .csrf().disable();
        http.sessionManagement().maximumSessions(2).expiredUrl("/login_form");
    }

    @Override
    public void configure(AuthenticationManagerBuilder auth) throws Exception {
        LdapAuthenticationProviderConfigurer ldapConfig = auth.ldapAuthentication();
        ldapConfig.contextSource().url("ldap://ldap.vmware.com");
        ldapConfig.contextSource().managerDn("x");
        ldapConfig.contextSource().managerPassword("y");
        ldapConfig.userSearchFilter("(sAMAccountName={0})");
        ldapConfig.userSearchBase("dc=z, dc=com");
        ldapConfig.groupSearchBase(null);
        TokenAuthProvider provider = new TokenAuthProvider();
        auth.authenticationProvider(provider);
    }
}

4. Ensure Your Config Class Is Scanned

  • For Spring Boot: Make sure your main application class is in a parent package of LdapSecurityConfig (e.g., if your config is in com.yourcompany.security, your app class should be in com.yourcompany). Or add @ComponentScan(basePackages = "com.yourcompany.security") to your main class.
  • For traditional Spring: Add <context:component-scan base-package="com.yourcompany.security"/> to your XML config, or include the package in your Java-based @ComponentScan.

After making these changes, rebuild your project and test again—the springSecurityFilterChain bean should be created correctly, and the LDAP authentication flow should work as expected.

内容的提问来源于stack exchange,提问作者Anita

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 17:27:50