Spring Boot多模块项目Bookstore启动后Access Denied无报错排查求助
Problem Overview
I have a Spring Boot project with onlinestore as the parent module, containing admin and bookstore submodules which ran normally before (only sharing URL paths via app.properties). After adding a domain module and moving all domain objects into it (imported into the bookstore module with no compilation errors), starting the bookstore module results in "access denied" for all endpoints with no visible error logs. Earlier, the system prompted for unique Order values, so I added the @Order annotation to my SecurityConfig, but I still can't pinpoint the root cause.
Provided Configurations
Parent Module (onlinestore) pom.xml
<?xml version="1.0" encoding="UTF-8"?> <project xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://maven.apache.org/POM/4.0.0" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <groupId>com.modular</groupId> <artifactId>onlinestore</artifactId> <version>0.0.1-SNAPSHOT</version> <modules> <module>admin</module> <module>bookstore</module> <module>domain</module> </modules> <packaging>pom</packaging> <name>onlinestore</name> <description>Demo project for Spring Boot</description> <parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>1.5.7.RELEASE</version> <relativePath/> <!-- lookup parent from repository --> </parent> <properties> <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding> <project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding> <java.version>1.8</java.version> </properties> <dependencies> <dependency> <groupId>net.sf.dozer</groupId> <artifactId>dozer-spring</artifactId> <version>5.5.1</version> </dependency> <dependency> <groupId>javax.mail</groupId> <artifactId>mail</artifactId> <version>1.4.7</version> </dependency> <dependency> <groupId>net.sf.dozer</groupId> <artifactId>dozer</artifactId> <version>5.5.1</version> </dependency> </dependencies> <repositories> <repository> <id>spring-snapshots</id> <name>Spring Snapshots</name> <url>https://repo.spring.io/libs-snapshot</url> <snapshots> <enabled>true</enabled> </snapshots> </repository> </repositories> <build> <plugins> <plugin> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-maven-plugin</artifactId> </plugin> </plugins> </build> </project>
Bookstore Module pom.xml
<?xml version="1.0" encoding="UTF-8"?> <project xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://maven.apache.org/POM/4.0.0" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"> <packaging>jar</packaging> <parent> <artifactId>onlinestore</artifactId> <groupId>com.modular</groupId> <version>0.0.1-SNAPSHOT</version> </parent> <modelVersion>4.0.0</modelVersion> <artifactId>bookstore</artifactId> <modules> <module>../domain</module> </modules> <properties> <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding> <project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding> <java.version>1.8</java.version> </properties> <dependencies> <dependency> <groupId>com.modular</groupId> <artifactId>domain</artifactId> <version>0.0.1-SNAPSHOT</version> </dependency> <dependency> <groupId>org.junit.jupiter</groupId> <artifactId>junit-jupiter-api</artifactId> <version>5.0.0-M3</version> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-thymeleaf</artifactId> </dependency> <dependency> <groupId>org.springframework.ldap</groupId> <artifactId>spring-ldap-core</artifactId> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-ldap</artifactId> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-jdbc</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-data-jpa</artifactId> </dependency> <dependency> <groupId>mysql</groupId> <artifactId>mysql-connector-java</artifactId> </dependency> <!-- this is added to check weather user logged in or not--> <dependency> <groupId>org.thymeleaf.extras</groupId> <artifactId>thymeleaf-extras-springsecurity4</artifactId> </dependency> <dependency> <groupId>org.easymock</groupId> <artifactId>easymock</artifactId> <version>3.4</version> <scope>test</scope> </dependency> <dependency> <groupId>com.h2database</groupId> <artifactId>h2</artifactId> <version>1.4.196</version> <scope>runtime</scope> </dependency> <dependency> <groupId>org.springframework</groupId> <artifactId>spring-context-support</artifactId> </dependency> <!--for checking --> <dependency> <groupId>net.sourceforge.htmlunit</groupId> <artifactId>htmlunit</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.seleniumhq.selenium</groupId> <artifactId>selenium-api</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.seleniumhq.selenium</groupId> <artifactId>htmlunit-driver</artifactId> <scope>test</scope> </dependency> <!--<dependency>--> <!--<groupId>org.mockito</groupId>--> <!--<artifactId>mockito-all</artifactId>--> <!--<version>${mockito.version}</version>--> <!--<scope>test</scope>--> <!--</dependency>--> </dependencies> <repositories> <repository> <id>spring-snapshots</id> <name>Spring Snapshots</name> <url>https://repo.spring.io/libs-snapshot</url> <snapshots> <enabled>true</enabled> </snapshots> </repository> </repositories> <build> <plugins> <plugin> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-maven-plugin</artifactId> </plugin> </plugins> </build> </project>
Domain Module pom.xml
<?xml version="1.0" encoding="UTF-8"?> <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"> <parent> <artifactId>onlinestore</artifactId> <groupId>com.modular</groupId> <version>0.0.1-SNAPSHOT</version> </parent> <packaging>jar</packaging> <modelVersion>4.0.0</modelVersion> <artifactId>domain</artifactId> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-thymeleaf</artifactId> </dependency> <dependency> <groupId>org.springframework.ldap</groupId> <artifactId>spring-ldap-core</artifactId> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-ldap</artifactId> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-jdbc</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-data-jpa</artifactId> </dependency> <dependency> <groupId>mysql</groupId> <artifactId>mysql-connector-java</artifactId> </dependency> </dependencies> </project>
Bookstore Main Class
@Configuration @SpringBootApplication @EntityScan(basePackages = {"com.modular.domain","com.domain.domain"}) @ComponentScan(basePackages = {"com.bookstore.services","com.domain.domain", "com.bookstore.utility","com.domain.domain.security","com.bookstore.repository"}) @EnableJpaRepositories(basePackages = {"com.bookstore.repository"}) @EnableTransactionManagement public class BookstoreApplications implements CommandLineRunner {
Key Troubleshooting Steps
1. Fix Maven Module Dependency Structure
Looking at your bookstore pom.xml, you've incorrectly added the domain module as a submodule:
<modules> <module>../domain</module> </modules>
The <modules> section is for declaring child modules of the current module, but domain is a sibling under the parent onlinestore. Remove this block—you only need the <dependency> entry for the domain module. This could be causing classpath conflicts or incorrect build ordering.
2. Clean Up Domain Module Dependencies
Your domain module includes heavy dependencies like spring-boot-starter-security, spring-boot-starter-web, and spring-boot-starter-thymeleaf—these don't belong in a domain layer! A domain module should only contain entity classes, shared repositories, and basic utilities. These extra dependencies are likely triggering unintended Spring Security auto-configuration in the bookstore module, overriding your custom rules.
Remove all unnecessary dependencies from the domain module; keep only what's needed for JPA/entities:
spring-boot-starter-data-jpamysql-connector-java- (Optional) Test dependencies like
spring-boot-starter-test
3. Validate Security Configuration Priority & Conflicts
Even with @Order on your SecurityConfig, there might be another security configuration being picked up (from the domain module, if it has one) with a higher priority (lower order value).
Enable debug logging for Spring Security to see which configs are being applied:
Add this to your bookstore'sapplication.properties:logging.level.org.springframework.security=DEBUGCheck the logs for lines like
Adding security filter chainto see which configuration is active.Ensure your
@Ordervalue is set correctly: Spring uses lower numbers for higher priority. If you have multiple security configs, make sure your bookstore's config has a lower order than any others.
4. Correct Component/Entity Scan Packages
Your main class has some suspicious package declarations:
@EntityScan(basePackages = {"com.modular.domain","com.domain.domain"}) @ComponentScan(basePackages = {"com.bookstore.services","com.domain.domain", "com.bookstore.utility","com.domain.domain.security","com.bookstore.repository"})
com.domain.domainlooks like a typo—your domain module's groupId iscom.modular, so entities should be incom.modular.domain.- If the domain module has security components (like a
SecurityConfigorUserDetailsService),@ComponentScanis pulling them into the bookstore context, which could introduce conflicting rules. Removecom.domain.domain.securityfrom the scan if it's not intended.
5. Verify Security Rules & User Details
After moving domain objects, confirm that:
- Your
UserDetailsServiceis correctly fetching user roles from the movedUserentity. - Your
SecurityConfig'sconfigure(HttpSecurity http)method still permits public endpoints (e.g.,antMatchers("/", "/home").permitAll()) and restricts others correctly. - There are no changes to role names or authorities that would break existing access rules.
6. Check for Hidden Runtime Errors
Enable general Spring debug logging to catch bean initialization issues that aren't showing up as compilation errors:
logging.level.org.springframework=DEBUG
Look for errors related to:
- Failed to initialize
DataSourceor JPA repositories - Missing dependencies for security beans (like
AuthenticationManager) - Conflicting bean definitions from the domain module
内容的提问来源于stack exchange,提问作者valik

