You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Thymeleaf Spring Security标签失效求助:无报错但权限控制不生效

Fixing Thymeleaf Spring Security Extension Not Working in Spring Boot 2.1.2

Hey there, let's break down why those sec:authorize tags aren't behaving like they should. I've spotted a few key issues that are almost certainly causing the problem:

1. Critical Version Mismatch

Spring Boot 2.1.2.RELEASE comes bundled with Spring Security 5.1.x under the hood, but you're using thymeleaf-extras-springsecurity4—this library is built exclusively for Spring Security 4.x, so it can't properly integrate with the newer security framework in your project. This version mismatch is the root cause of your sec:authorize checks failing.

Fix: Swap to the Correct Extension Version

Replace your existing Thymeleaf Spring Security dependency with the 5.x variant that matches your Spring Boot version:

<dependency>
    <groupId>org.thymeleaf.extras</groupId>
    <artifactId>thymeleaf-extras-springsecurity5</artifactId>
    <!-- Version 3.0.4.RELEASE is fully compatible with Spring Boot 2.1.x -->
    <version>3.0.4.RELEASE</version>
</dependency>

Quick side note: You should also align your spring-boot-configuration-processor version to match your spring-boot.version (2.1.2.RELEASE) to avoid subtle, hard-to-track conflicts.

2. Check Your HTML Namespace

Make sure all your Thymeleaf templates include the Spring Security namespace in the root HTML tag—without this, Thymeleaf won't recognize the sec: attributes at all:

<!DOCTYPE html>
<html xmlns:th="http://www.thymeleaf.org"
      xmlns:sec="http://www.thymeleaf.org/extras/spring-security">
<!-- Rest of your template content -->
</html>

3. Confirm Spring Security is Enabled

Double-check that you have a valid Spring Security configuration class. For Spring Boot 2.1.x, this should look something like:

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        // Add your authentication/authorization rules here
        http.authorizeRequests()
            .anyRequest().authenticated()
            .and()
            .formLogin(); // Enables basic form-based login
    }
}

If Spring Security isn't properly enabled, the sec:authorize checks won't have the context to determine if a user is authenticated or anonymous.

4. Verify Thymeleaf Dialect Registration

For most Spring Boot projects using the official starters, the SpringSecurityDialect is auto-registered. But if you've customized your ThymeleafTemplateEngine, you'll need to manually add the dialect:

@Bean
public SpringSecurityDialect springSecurityDialect() {
    return new SpringSecurityDialect();
}

Once you've made these changes, run mvn clean install to refresh your dependencies, then restart your application. Your sec:authorize="isAuthenticated()" and sec:authorize="isAnonymous()" tags should now work as expected.

内容的提问来源于stack exchange,提问作者Gerolmed

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 06:37:48