Spring Security LDAP认证时springSecurityFilterChain Bean创建失败求助
Hey Anita, let's work through this Spring Security LDAP authentication issue step by step—here's how to fix the missing springSecurityFilterChain bean and related errors:
1. First, Fix the NoClassDefFoundError (Root Cause Clue)
Your error cuts off, but NoClassDefFoundError almost always means a missing dependency. Double-check your build file to ensure you have all required Spring Security and web dependencies:
For Maven (add to pom.xml):
<!-- Spring Security Web core (required for filter chain) --> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-web</artifactId> <version>your-spring-security-version</version> </dependency> <!-- Spring Security LDAP support --> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-ldap</artifactId> <version>your-spring-security-version</version> </dependency> <!-- Spring Web (required for servlet filter integration) --> <dependency> <groupId>org.springframework</groupId> <artifactId>spring-web</artifactId> <version>your-spring-version</version> </dependency>
For Gradle (add to build.gradle):
implementation 'org.springframework.security:spring-security-web:your-spring-security-version' implementation 'org.springframework.security:spring-security-ldap:your-spring-security-version' implementation 'org.springframework:spring-web:your-spring-version'
2. Fix the SecurityWebApplicationInitializer Placement & Usage
Your initializer class needs to be in a package that Spring can scan. Here's what to do:
- Place it in the same package as your
LdapSecurityConfig(or a subpackage) so Spring picks it up automatically. - If you're using Spring Boot, you don't need this class at all—Spring Boot auto-registers the security filter chain for you. Delete it entirely if this is a Boot project.
- If you're using a traditional Spring MVC project, keep the class but ensure it references your config correctly:
// Put this in com.yourcompany.security (same package as LdapSecurityConfig) public class SecurityWebApplicationInitializer extends AbstractSecurityWebApplicationInitializer { public SecurityWebApplicationInitializer() { super(LdapSecurityConfig.class); // Use YOUR config class, not WebSecurityConfiguration } }
3. Simplify Your LdapSecurityConfig (Remove Redundant Annotations)
You're using conflicting/unnecessary annotations that can confuse Spring's auto-configuration:
@Configuration @EnableWebSecurity // This single annotation replaces @EnableGlobalAuthentication and @Import(WebSecurityConfiguration.class) // Remove @Import({ WebSecurityConfiguration.class }) and @EnableGlobalAuthentication—they're redundant // Keep @Import({ SecurityConfig.class }) only if SecurityConfig is a required separate config public class LdapSecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { SavedRequestAwareAuthenticationSuccessHandler successHandler = new SavedRequestAwareAuthenticationSuccessHandler(); successHandler.setAlwaysUseDefaultTargetUrl(true); successHandler.setTargetUrlParameter("/"); http .requiresChannel().anyRequest().requiresInsecure().and() .authorizeRequests() .anyRequest().permitAll() .and() .formLogin() .loginPage("/login_form") .loginProcessingUrl("/login") .successHandler(successHandler) .failureUrl("/login_form?error") .and() .logout().logoutSuccessUrl("/login_form") .and() .csrf().disable(); http.sessionManagement().maximumSessions(2).expiredUrl("/login_form"); } @Override public void configure(AuthenticationManagerBuilder auth) throws Exception { LdapAuthenticationProviderConfigurer ldapConfig = auth.ldapAuthentication(); ldapConfig.contextSource().url("ldap://ldap.vmware.com"); ldapConfig.contextSource().managerDn("x"); ldapConfig.contextSource().managerPassword("y"); ldapConfig.userSearchFilter("(sAMAccountName={0})"); ldapConfig.userSearchBase("dc=z, dc=com"); ldapConfig.groupSearchBase(null); TokenAuthProvider provider = new TokenAuthProvider(); auth.authenticationProvider(provider); } }
4. Ensure Your Config Class Is Scanned
- For Spring Boot: Make sure your main application class is in a parent package of
LdapSecurityConfig(e.g., if your config is incom.yourcompany.security, your app class should be incom.yourcompany). Or add@ComponentScan(basePackages = "com.yourcompany.security")to your main class. - For traditional Spring: Add
<context:component-scan base-package="com.yourcompany.security"/>to your XML config, or include the package in your Java-based@ComponentScan.
After making these changes, rebuild your project and test again—the springSecurityFilterChain bean should be created correctly, and the LDAP authentication flow should work as expected.
内容的提问来源于stack exchange,提问作者Anita

