Spring全局方法安全与AspectJ自动代理冲突解决方案咨询
Hey there! Let's tackle this conflict between Spring Security's method security setup and AspectJ auto-proxying for your logging enhancements. I've looked at your config and the error stack, and here's how to fix it step by step:
你的场景与配置
You've already set up global method security with @EnableGlobalMethodSecurity(prePostEnabled=true) and are trying to add AspectJ auto-proxying via @EnableAspectJAutoProxy(proxyTargetClass=true) for logging, but hitting a bean creation conflict. Your current config classes are:
MethodSecurityConfig
@Configuration @EnableGlobalMethodSecurity(prePostEnabled=true) public class MethodSecurityConfig extends GlobalMethodSecurityConfiguration{ }
AspectConfig
@Configuration @EnableAspectJAutoProxy(proxyTargetClass=true) @ComponentScan public class AspectConfig { @Bean public ActionRecord record() { return new ActionRecord(); } }
启动报错信息
WARNING: Exception encountered during context initialization - cancelling refresh attempt: org.springframework.beans.factory.BeanCreationException: Error creating bean with name 'org.springframework.context.event.internalEventListenerProcessor': BeanPostProcessor before instantiation of bean failed; nested exception is org.springframework.beans.factory.BeanCreationException: Error creating bean with name 'metaDataSourceAdvisor': Cannot resolve reference to bean 'methodSecurityMetadataSource' while setting constructor argument; nested exception is org.springframework.beans.factory.UnsatisfiedDependencyException: Error creating bean with name 'methodSecurityConfig': Unsatisfied dependency expressed through method 'setObjectPostProcessor' parameter 0; nested exception is org.springframework.beans.factory.BeanCreationException: Error creating bean with name 'org.springframework.security.config.annotation.configuration.ObjectPostProcessorConfiguration': Initialization of bean failed; nested exception is java.lang.IllegalArgumentException: warning no match for this type name: beike.visitorsystem.authority.controller [Xlint:invalidAbsoluteTypeName] Jan 07, 2018 6:02:30 org.springframework.web.context.ContextLoader initWebApplicationContext Context initialization failed org.springframework.beans.factory.BeanCreationException: Error creating bean with name 'org.springframework.context.event.internalEventListenerProcessor': BeanPostProcessor before instantiation of bean failed; nested exception is org.springframework.beans.factory.BeanCreationException: Error creating bean with name 'metaDataSourceAdvisor': Cannot resolve reference to bean 'methodSecurityMetadataSource' while setting constructor argument; nested exception is org.springframework.beans.factory.UnsatisfiedDependencyException: Error creating bean with name 'methodSecurityConfig': Unsatisfied dependency expressed through method 'setObjectPostProcessor' parameter 0; nested exception is org.springframework.beans.factory.BeanCreationException: Error creating bean with name 'org.springframework.security.config.annotation.configuration.ObjectPostProcessorConfiguration': Initialization of bean failed; nested exception is java.lang.IllegalArgumentException: warning no match for this type name: beike.visitorsystem.authority.controller [Xlint:invalidAbsoluteTypeName]
解决方案
First, notice the critical warning in the error: warning no match for this type name: beike.visitorsystem.authority.controller. This means your AspectJ pointcut expression is referencing a class that doesn't exist (either a typo in the fully qualified name or the class was removed). Fix this pointcut issue first—it's a direct cause of the initialization failure!
Next, let's resolve the proxy conflict. The root problem is that splitting the proxy-enabling annotations across two config classes messes up the order of Spring's BeanPostProcessor initialization, leaving Spring Security's internal beans unable to resolve dependencies correctly. Here's how to fix it:
1. Combine Proxy Configurations in One Class
Move @EnableAspectJAutoProxy(proxyTargetClass=true) into your MethodSecurityConfig so Spring handles both security and AspectJ proxying in a unified way:
Updated MethodSecurityConfig:
@Configuration @EnableGlobalMethodSecurity(prePostEnabled = true) @EnableAspectJAutoProxy(proxyTargetClass = true) public class MethodSecurityConfig extends GlobalMethodSecurityConfiguration { }
Adjust AspectConfig to remove the duplicate proxy annotation:
@Configuration @ComponentScan public class AspectConfig { @Bean public ActionRecord record() { return new ActionRecord(); } }
2. Verify Proxy Coordination (Optional)
If you still run into minor issues after merging, double-check that your aspect class is being scanned correctly (either via @Component or declared as a bean in AspectConfig) and that your pointcut expressions target the right methods/classes. With proxyTargetClass=true, Spring will use CGLIB proxies, which support both Spring Security's method security annotations and AspectJ's method enhancements.
内容的提问来源于stack exchange,提问作者Siri Wee

