Thymeleaf Spring Security标签失效求助:无报错但权限控制不生效
Hey there, let's break down why those sec:authorize tags aren't behaving like they should. I've spotted a few key issues that are almost certainly causing the problem:
1. Critical Version Mismatch
Spring Boot 2.1.2.RELEASE comes bundled with Spring Security 5.1.x under the hood, but you're using thymeleaf-extras-springsecurity4—this library is built exclusively for Spring Security 4.x, so it can't properly integrate with the newer security framework in your project. This version mismatch is the root cause of your sec:authorize checks failing.
Fix: Swap to the Correct Extension Version
Replace your existing Thymeleaf Spring Security dependency with the 5.x variant that matches your Spring Boot version:
<dependency> <groupId>org.thymeleaf.extras</groupId> <artifactId>thymeleaf-extras-springsecurity5</artifactId> <!-- Version 3.0.4.RELEASE is fully compatible with Spring Boot 2.1.x --> <version>3.0.4.RELEASE</version> </dependency>
Quick side note: You should also align your spring-boot-configuration-processor version to match your spring-boot.version (2.1.2.RELEASE) to avoid subtle, hard-to-track conflicts.
2. Check Your HTML Namespace
Make sure all your Thymeleaf templates include the Spring Security namespace in the root HTML tag—without this, Thymeleaf won't recognize the sec: attributes at all:
<!DOCTYPE html> <html xmlns:th="http://www.thymeleaf.org" xmlns:sec="http://www.thymeleaf.org/extras/spring-security"> <!-- Rest of your template content --> </html>
3. Confirm Spring Security is Enabled
Double-check that you have a valid Spring Security configuration class. For Spring Boot 2.1.x, this should look something like:
import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; @Configuration @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { // Add your authentication/authorization rules here http.authorizeRequests() .anyRequest().authenticated() .and() .formLogin(); // Enables basic form-based login } }
If Spring Security isn't properly enabled, the sec:authorize checks won't have the context to determine if a user is authenticated or anonymous.
4. Verify Thymeleaf Dialect Registration
For most Spring Boot projects using the official starters, the SpringSecurityDialect is auto-registered. But if you've customized your ThymeleafTemplateEngine, you'll need to manually add the dialect:
@Bean public SpringSecurityDialect springSecurityDialect() { return new SpringSecurityDialect(); }
Once you've made these changes, run mvn clean install to refresh your dependencies, then restart your application. Your sec:authorize="isAuthenticated()" and sec:authorize="isAnonymous()" tags should now work as expected.
内容的提问来源于stack exchange,提问作者Gerolmed

