You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot/Spring Security如何实现仅根路径带lang参数的请求免认证

实现方案

Spring Security 自带的 AntPathMatcher 仅匹配请求路径,不支持匹配请求参数,因此你需要通过自定义 RequestMatcher 实现精准匹配规则。

步骤1:定义自定义匹配规则

在你的 Security 配置类中添加匹配器,仅匹配根路径 + 携带lang参数的请求:

import org.springframework.security.web.util.matcher.AndRequestMatcher;
import org.springframework.security.web.util.matcher.AntPathRequestMatcher;
import org.springframework.security.web.util.matcher.RequestParameterRequestMatcher;

// 构造组合匹配规则
private RequestMatcher langRootRequestMatcher() {
    return new AndRequestMatcher(
        // 匹配根路径
        AntPathRequestMatcher.antMatcher("/"),
        // 匹配请求中携带lang参数
        new RequestParameterRequestMatcher("lang")
    );
}

步骤2:修改Security配置

在授权规则中添加自定义匹配器的放行规则,替换你之前加的/*放行配置:

http.authorizeRequests()
    // Restrict Endpoints
    .antMatchers("/login/**").hasAnyRole("admin", "member")
    // Allow Forms
    .antMatchers("/member/**").permitAll()
    // Allow Resources
    .antMatchers("/js/**", "/css/**").permitAll()
    // 仅放行带lang参数的根路径请求
    .requestMatchers(langRootRequestMatcher()).permitAll()
    // Deny All
    .anyRequest().authenticated();

扩展说明

如果需要进一步限制lang参数的可选值(比如仅允许zh/en/de等已支持的语言),可以自定义 RequestMatcher 实现更复杂的校验逻辑:

private RequestMatcher limitedLangRootMatcher() {
    return request -> {
        // 先判断是否是根路径
        if (!"/".equals(request.getServletPath())) {
            return false;
        }
        String lang = request.getParameter("lang");
        // 仅当lang参数为已支持的语言时匹配成功
        return lang != null && List.of("zh", "en", "de").contains(lang);
    };
}

内容的提问来源于stack exchange,提问作者Kevin O.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 22:00:01