You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security 6中配置permitAll()后,/api/auth/signin端点仍被自定义JwtAuthenticationFilter拦截的问题求助

Spring Security 6中配置permitAll()后,/api/auth/signin端点仍被自定义JwtAuthenticationFilter拦截的问题求助

我现在在用Spring Security 6配合自定义的JwtAuthenticationFilter来处理API的JWT认证,但明明给/api/auth/signin端点配置了.permitAll(),这个自定义过滤器还是会对该端点生效——这明显不合理,登录接口本来就不该要求JWT凭证啊。

我的安全配置代码:

@Configuration
public class SecurityConfig {

    private final JwtAuthenticationFilter jwtAuthenticationFilter;

    public SecurityConfig(JwtAuthenticationFilter jwtAuthenticationFilter) {
        this.jwtAuthenticationFilter = jwtAuthenticationFilter;
    }

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        // Configure CORS support
        http.cors().configurationSource(corsConfigurationSource())
            .and()
            .authorizeRequests()
            .requestMatchers("/api/auth/signin").permitAll()  // Allow signin endpoint
            .requestMatchers(HttpMethod.OPTIONS, "/api/auth/signin").permitAll()  // Allow OPTIONS for /api/auth/signin
            .anyRequest().authenticated()  // Secure other requests
            .and()
            .addFilterBefore(jwtAuthenticationFilter, UsernamePasswordAuthenticationFilter.class); // Register the custom JWT filter

        return http.build();
    }

    @Bean
    public CorsConfigurationSource corsConfigurationSource() {
        // CORS configuration
        CorsConfiguration corsConfig = new CorsConfiguration();
        corsConfig.setAllowedOrigins(Arrays.asList("http://localhost:3000"));  // Set your frontend domain here
        corsConfig.setAllowedMethods(Arrays.asList("GET", "POST", "PUT", "DELETE", "OPTIONS"));  // Allow these methods
        corsConfig.setAllowedHeaders(Arrays.asList("Content-Type", "Authorization"));  // Allow these headers
        corsConfig.setAllowCredentials(true);  // Allow credentials like cookies, if needed

        // Register the CORS configuration
        UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
        source.registerCorsConfiguration("/**", corsConfig);
        return source;
    }
}

自定义JwtAuthenticationFilter实现:

@Component
public class JwtAuthenticationFilter extends OncePerRequestFilter {

    private final JwtTokenProvider jwtTokenProvider;

    public JwtAuthenticationFilter(JwtTokenProvider jwtTokenProvider) {
        this.jwtTokenProvider = jwtTokenProvider;
    }

    @Override
    protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain chain)
            throws ServletException, IOException {

        // Extract and validate JWT
        String jwt = getJwtFromRequest(request);
        
        if (StringUtils.hasText(jwt) && jwtTokenProvider.validateToken(jwt)) {
            String username = jwtTokenProvider.getUsernameFromToken(jwt);

            // Set authentication in security context
            SecurityContextHolder.getContext().setAuthentication(jwtTokenProvider.getAuthentication(username));
        }

        // Continue with the filter chain
        chain.doFilter(request, response);
    }

    private String getJwtFromRequest(HttpServletRequest request) {
        String bearerToken = request.getHeader("Authorization");
        if (StringUtils.hasText(bearerToken) && bearerToken.startsWith("Bearer ")) {
            return bearerToken.substring(7);  // Extract the token without the "Bearer " prefix
        }
        return null;
    }
}

有没有大佬能帮我排查下问题出在哪呀?

备注:内容来源于stack exchange,提问作者Bharath

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.15 10:34:28