You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security5.7.0升级后SecurityContextPersistenceFilter未调用

问题根因

配置错误来自你注册的WebSecurityCustomizer Bean:你配置的web.ignoring().antMatchers("/**")规则会让所有请求完全绕过Spring Security的整个过滤器链,SecurityContextPersistenceFilter、认证授权相关的所有内置Filter都不会执行。
对比新旧配置可以直接定位差异:

  • 旧版代码里的setIgnoreEverything是自定义的protected static方法,既没有加@Override注解重写WebSecurityConfigurerAdapter中对应WebSecurity配置的方法,也没有被主动调用,这个全局忽略规则在旧版里完全没生效,安全过滤器链是正常运行的。
  • 迁移到新版配置后,你把这段全局忽略逻辑注册成了Spring托管的WebSecurityCustomizer Bean,规则会被Spring Security自动加载生效,所有请求直接跳过全部安全过滤器,自然看不到FilterChainProxy拦截请求、SecurityContextPersistenceFilter读取Session中认证信息的日志,requestPostProcessor预先存入HttpSession的认证信息也无法被加载到安全上下文。
修复方法

直接删除错误的全局忽略Bean定义即可,也就是移除以下代码:

/**
 * Set the default ignore everything on the security context.
 * @return WebSecurityCustomizer - used to customize WebSecurity
 */
@Bean
public WebSecurityCustomizer ignoringCustomizer() {
    return web -> web.ignoring().antMatchers("/**");
}

如果确实存在不需要走安全校验的路径(比如静态资源、公开健康检查接口),只需要把具体的路径匹配规则加到WebSecurityCustomizer的ignoring列表中即可,禁止使用/**通配符配置全局忽略。

调整完成后重新运行测试,即可在Debug日志中看到SecurityContextPersistenceFilter的执行记录,requestPostProcessor设置的认证信息也会被正常加载参与权限校验。

内容的提问来源于stack exchange,提问作者woggle

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.27 00:45:46