Spring Boot部署在Azure环境中hasIpAddress校验带端口IP失败问题求助
Spring Boot部署在Azure环境中hasIpAddress校验带端口IP失败问题求助
我在Azure上部署了基于Spring Boot 3.3.1的应用,由于一些不可控因素,需要允许特定的IP地址访问一组特定页面。
目前我的安全配置部分代码如下:
.requestMatchers("/example1", "/example2") .access(new WebExpressionAuthorizationManager( "isAuthenticated() or (isAnonymous() and (hasIpAddress(123.456.0.1) or hasIpAddress(654.321.0.1))" ))
在本地(localhost)运行时,只要从指定IP访问,无需认证就能正常打开允许的页面。但部署到Azure实例后,每次尝试访问requestMatcher中指定的站点(比如example1)都会触发以下错误(IP地址已脱敏):
2025-02-24T15:41:43.308208721Z: [INFO] java.lang.IllegalArgumentException: Failed to parse address '123.456.0.1:12345' 2025-02-24T15:41:43.308212747Z: [INFO] at org.springframework.security.web.util.matcher.IpAddressMatcher.parseAddress(IpAddressMatcher.java:113) 2025-02-24T15:41:43.308215725Z: [INFO] at org.springframework.security.web.util.matcher.IpAddressMatcher.matches(IpAddressMatcher.java:73) 2025-02-24T15:41:43.308218491Z: [INFO] at org.springframework.security.web.util.matcher.IpAddressMatcher.matches(IpAddressMatcher.java:68) 2025-02-24T15:41:43.308221057Z: [INFO] at org.springframework.security.web.access.expression.WebSecurityExpressionRoot.hasIpAddress(WebSecurityExpressionRoot.java:65) 2025-02-24T15:41:43.308441662Z: [INFO] at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103) 2025-02-24T15:41:43.308446958Z: [INFO] at java.base/java.lang.reflect.Method.invoke(Method.java:580) 2025-02-24T15:41:43.308449788Z: [INFO] at org.springframework.expression.spel.support.ReflectiveMethodExecutor.execute(ReflectiveMethodExecutor.java:142) 2025-02-24T15:41:43.308452517Z: [INFO] at org.springframework.expression.spel.ast.MethodReference.getValueInternal(MethodReference.java:125) 2025-02-24T15:41:43.308455151Z: [INFO] at org.springframework.expression.spel.ast.MethodReference.getValueInternal(MethodReference.java:108) 2025-02-24T15:41:43.308457758Z: [INFO] at org.springframework.expression.spel.ast.SpelNodeImpl.getValue(SpelNodeImpl.java:222) 2025-02-24T15:41:43.308460311Z: [INFO] at org.springframework.expression.spel.ast.OpAnd.getBooleanValue(OpAnd.java:57) 2025-02-24T15:41:43.308462918Z: [INFO] at org.springframework.expression.spel.ast.OpAnd.getValueInternal(OpAnd.java:52) 2025-02-24T15:41:43.308465398Z: [INFO] at org.springframework.expression.spel.ast.SpelNodeImpl.getValue(SpelNodeImpl.java:222) 2025-02-24T15:41:43.308467918Z: [INFO] at org.springframework.expression.spel.ast.OpOr.getBooleanValue(OpOr.java:56) 2025-02-24T15:41:43.308470563Z: [INFO] at org.springframework.expression.spel.ast.OpOr.getValueInternal(OpOr.java:51) 2025-02-24T15:41:43.308473233Z: [INFO] at org.springframework.expression.spel.ast.OpOr.getValueInternal(OpOr.java:37) 2025-02-24T15:41:43.308475769Z: [INFO] at org.springframework.expression.spel.ast.SpelNodeImpl.getTypedValue(SpelNodeImpl.java:119) 2025-02-24T15:41:43.308478371Z: [INFO] at org.springframework.expression.spel.standard.SpelExpression.getValue(SpelExpression.java:309) 2025-02-24T15:41:43.308482590Z: [INFO] at org.springframework.security.access.expression.ExpressionUtils.evaluateAsBoolean(ExpressionUtils.java:30) 2025-02-24T15:41:43.308485469Z: [INFO] at org.springframework.security.web.access.expression.WebExpressionAuthorizationManager.check(WebExpressionAuthorizationManager.java:76) 2025-02-24T15:41:43.308488106Z: [INFO] at org.springframework.security.web.access.expression.WebExpressionAuthorizationManager.check(WebExpressionAuthorizationManager.java:39) [Lots of trace...] 2025-02-24T15:41:44.764129250Z: [INFO] at org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:389) 2025-02-24T15:41:44.764131941Z: [INFO] at org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:63) 2025-02-24T15:41:44.764134397Z: [INFO] at org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:904) 2025-02-24T15:41:44.764136904Z: [INFO] at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1741) 2025-02-24T15:41:44.764139363Z: [INFO] at org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:52) 2025-02-24T15:41:44.764141809Z: [INFO] at org.apache.tomcat.util.threads.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1190) 2025-02-24T15:41:44.764144270Z: [INFO] at org.apache.tomcat.util.threads.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:659) 2025-02-24T15:41:44.764146752Z: [INFO] at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:63) 2025-02-24T15:41:44.764149184Z: [INFO] at java.base/java.lang.Thread.run(Thread.java:1583) 2025-02-24T15:41:44.764154252Z: [INFO] Caused by: java.net.UnknownHostException: 123.456.0.1:12345: invalid IPv6 address literal 2025-02-24T15:41:44.764156916Z: [INFO] at java.base/java.net.InetAddress.invalidIPv6LiteralException(InetAddress.java:1693) 2025-02-24T15:41:44.764159465Z: [INFO] at java.base/java.net.InetAddress.getAllByName(InetAddress.java:1663) 2025-02-24T15:41:44.764161891Z: [INFO] at java.base/java.net.InetAddress.getByName(InetAddress.java:1568) 2025-02-24T15:41:44.764164362Z: [INFO] at org.springframework.security.web.util.matcher.IpAddressMatcher.parseAddress(IpAddressMatcher.java:110) 2025-02-24T15:41:44.764166884Z: [INFO] ... 119 common frames omitted
根据错误日志分析,问题出在安全校验流程中:hasIpAddress无法处理带端口的IP地址,但Azure环境下,请求的IP被附带了端口一起传入校验,导致解析失败。
请问我该如何避免端口被传入IP校验?或者有没有其他可行的解决方案?
备注:内容来源于stack exchange,提问作者Jacob B.
相关产品推荐
相关产品推荐

