You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot多模块项目Bookstore启动后Access Denied无报错排查求助

Troubleshooting "Access Denied" Issue After Adding Domain Module

Problem Overview

I have a Spring Boot project with onlinestore as the parent module, containing admin and bookstore submodules which ran normally before (only sharing URL paths via app.properties). After adding a domain module and moving all domain objects into it (imported into the bookstore module with no compilation errors), starting the bookstore module results in "access denied" for all endpoints with no visible error logs. Earlier, the system prompted for unique Order values, so I added the @Order annotation to my SecurityConfig, but I still can't pinpoint the root cause.

Provided Configurations

Parent Module (onlinestore) pom.xml

<?xml version="1.0" encoding="UTF-8"?>
<project xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://maven.apache.org/POM/4.0.0" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<groupId>com.modular</groupId>
<artifactId>onlinestore</artifactId>
<version>0.0.1-SNAPSHOT</version>
<modules>
<module>admin</module>
<module>bookstore</module>
<module>domain</module>
</modules>
<packaging>pom</packaging>
<name>onlinestore</name>
<description>Demo project for Spring Boot</description>
<parent>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-parent</artifactId>
<version>1.5.7.RELEASE</version>
<relativePath/>
<!-- lookup parent from repository -->
</parent>
<properties>
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
<project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>
<java.version>1.8</java.version>
</properties>
<dependencies>
<dependency>
<groupId>net.sf.dozer</groupId>
<artifactId>dozer-spring</artifactId>
<version>5.5.1</version>
</dependency>
<dependency>
<groupId>javax.mail</groupId>
<artifactId>mail</artifactId>
<version>1.4.7</version>
</dependency>
<dependency>
<groupId>net.sf.dozer</groupId>
<artifactId>dozer</artifactId>
<version>5.5.1</version>
</dependency>
</dependencies>
<repositories>
<repository>
<id>spring-snapshots</id>
<name>Spring Snapshots</name>
<url>https://repo.spring.io/libs-snapshot</url>
<snapshots>
<enabled>true</enabled>
</snapshots>
</repository>
</repositories>
<build>
<plugins>
<plugin>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-maven-plugin</artifactId>
</plugin>
</plugins>
</build>
</project>

Bookstore Module pom.xml

<?xml version="1.0" encoding="UTF-8"?>
<project xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://maven.apache.org/POM/4.0.0" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
<packaging>jar</packaging>
<parent>
<artifactId>onlinestore</artifactId>
<groupId>com.modular</groupId>
<version>0.0.1-SNAPSHOT</version>
</parent>
<modelVersion>4.0.0</modelVersion>
<artifactId>bookstore</artifactId>
<modules>
<module>../domain</module>
</modules>
<properties>
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
<project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>
<java.version>1.8</java.version>
</properties>
<dependencies>
<dependency>
<groupId>com.modular</groupId>
<artifactId>domain</artifactId>
<version>0.0.1-SNAPSHOT</version>
</dependency>
<dependency>
<groupId>org.junit.jupiter</groupId>
<artifactId>junit-jupiter-api</artifactId>
<version>5.0.0-M3</version>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-thymeleaf</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.ldap</groupId>
<artifactId>spring-ldap-core</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.security</groupId>
<artifactId>spring-security-ldap</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.security</groupId>
<artifactId>spring-security-test</artifactId>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-security</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-test</artifactId>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-web</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-jdbc</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-data-jpa</artifactId>
</dependency>
<dependency>
<groupId>mysql</groupId>
<artifactId>mysql-connector-java</artifactId>
</dependency>
<!-- this is added to check weather user logged in or not-->
<dependency>
<groupId>org.thymeleaf.extras</groupId>
<artifactId>thymeleaf-extras-springsecurity4</artifactId>
</dependency>
<dependency>
<groupId>org.easymock</groupId>
<artifactId>easymock</artifactId>
<version>3.4</version>
<scope>test</scope>
</dependency>
<dependency>
<groupId>com.h2database</groupId>
<artifactId>h2</artifactId>
<version>1.4.196</version>
<scope>runtime</scope>
</dependency>
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-context-support</artifactId>
</dependency>
<!--for checking -->
<dependency>
<groupId>net.sourceforge.htmlunit</groupId>
<artifactId>htmlunit</artifactId>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.seleniumhq.selenium</groupId>
<artifactId>selenium-api</artifactId>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.seleniumhq.selenium</groupId>
<artifactId>htmlunit-driver</artifactId>
<scope>test</scope>
</dependency>
<!--<dependency>-->
<!--<groupId>org.mockito</groupId>-->
<!--<artifactId>mockito-all</artifactId>-->
<!--<version>${mockito.version}</version>-->
<!--<scope>test</scope>-->
<!--</dependency>-->
</dependencies>
<repositories>
<repository>
<id>spring-snapshots</id>
<name>Spring Snapshots</name>
<url>https://repo.spring.io/libs-snapshot</url>
<snapshots>
<enabled>true</enabled>
</snapshots>
</repository>
</repositories>
<build>
<plugins>
<plugin>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-maven-plugin</artifactId>
</plugin>
</plugins>
</build>
</project>

Domain Module pom.xml

<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
<parent>
<artifactId>onlinestore</artifactId>
<groupId>com.modular</groupId>
<version>0.0.1-SNAPSHOT</version>
</parent>
<packaging>jar</packaging>
<modelVersion>4.0.0</modelVersion>
<artifactId>domain</artifactId>
<dependencies>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-thymeleaf</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.ldap</groupId>
<artifactId>spring-ldap-core</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.security</groupId>
<artifactId>spring-security-ldap</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.security</groupId>
<artifactId>spring-security-test</artifactId>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-security</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-test</artifactId>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-web</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-jdbc</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-data-jpa</artifactId>
</dependency>
<dependency>
<groupId>mysql</groupId>
<artifactId>mysql-connector-java</artifactId>
</dependency>
</dependencies>
</project>

Bookstore Main Class

@Configuration
@SpringBootApplication
@EntityScan(basePackages = {"com.modular.domain","com.domain.domain"})
@ComponentScan(basePackages = {"com.bookstore.services","com.domain.domain", "com.bookstore.utility","com.domain.domain.security","com.bookstore.repository"})
@EnableJpaRepositories(basePackages = {"com.bookstore.repository"})
@EnableTransactionManagement
public class BookstoreApplications implements CommandLineRunner {

Key Troubleshooting Steps

1. Fix Maven Module Dependency Structure

Looking at your bookstore pom.xml, you've incorrectly added the domain module as a submodule:

<modules>
  <module>../domain</module>
</modules>

The <modules> section is for declaring child modules of the current module, but domain is a sibling under the parent onlinestore. Remove this block—you only need the <dependency> entry for the domain module. This could be causing classpath conflicts or incorrect build ordering.

2. Clean Up Domain Module Dependencies

Your domain module includes heavy dependencies like spring-boot-starter-security, spring-boot-starter-web, and spring-boot-starter-thymeleaf—these don't belong in a domain layer! A domain module should only contain entity classes, shared repositories, and basic utilities. These extra dependencies are likely triggering unintended Spring Security auto-configuration in the bookstore module, overriding your custom rules.

Remove all unnecessary dependencies from the domain module; keep only what's needed for JPA/entities:

  • spring-boot-starter-data-jpa
  • mysql-connector-java
  • (Optional) Test dependencies like spring-boot-starter-test

3. Validate Security Configuration Priority & Conflicts

Even with @Order on your SecurityConfig, there might be another security configuration being picked up (from the domain module, if it has one) with a higher priority (lower order value).

  • Enable debug logging for Spring Security to see which configs are being applied:
    Add this to your bookstore's application.properties:

    logging.level.org.springframework.security=DEBUG
    

    Check the logs for lines like Adding security filter chain to see which configuration is active.

  • Ensure your @Order value is set correctly: Spring uses lower numbers for higher priority. If you have multiple security configs, make sure your bookstore's config has a lower order than any others.

4. Correct Component/Entity Scan Packages

Your main class has some suspicious package declarations:

@EntityScan(basePackages = {"com.modular.domain","com.domain.domain"})
@ComponentScan(basePackages = {"com.bookstore.services","com.domain.domain", "com.bookstore.utility","com.domain.domain.security","com.bookstore.repository"})
  • com.domain.domain looks like a typo—your domain module's groupId is com.modular, so entities should be in com.modular.domain.
  • If the domain module has security components (like a SecurityConfig or UserDetailsService), @ComponentScan is pulling them into the bookstore context, which could introduce conflicting rules. Remove com.domain.domain.security from the scan if it's not intended.

5. Verify Security Rules & User Details

After moving domain objects, confirm that:

  • Your UserDetailsService is correctly fetching user roles from the moved User entity.
  • Your SecurityConfig's configure(HttpSecurity http) method still permits public endpoints (e.g., antMatchers("/", "/home").permitAll()) and restricts others correctly.
  • There are no changes to role names or authorities that would break existing access rules.

6. Check for Hidden Runtime Errors

Enable general Spring debug logging to catch bean initialization issues that aren't showing up as compilation errors:

logging.level.org.springframework=DEBUG

Look for errors related to:

  • Failed to initialize DataSource or JPA repositories
  • Missing dependencies for security beans (like AuthenticationManager)
  • Conflicting bean definitions from the domain module

内容的提问来源于stack exchange,提问作者valik

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:46:29