Spring Security 6中配置permitAll()后,/api/auth/signin端点仍被自定义JwtAuthenticationFilter拦截的问题求助
Spring Security 6中配置permitAll()后,/api/auth/signin端点仍被自定义JwtAuthenticationFilter拦截的问题求助
我现在在用Spring Security 6配合自定义的JwtAuthenticationFilter来处理API的JWT认证,但明明给/api/auth/signin端点配置了.permitAll(),这个自定义过滤器还是会对该端点生效——这明显不合理,登录接口本来就不该要求JWT凭证啊。
我的安全配置代码:
@Configuration public class SecurityConfig { private final JwtAuthenticationFilter jwtAuthenticationFilter; public SecurityConfig(JwtAuthenticationFilter jwtAuthenticationFilter) { this.jwtAuthenticationFilter = jwtAuthenticationFilter; } @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { // Configure CORS support http.cors().configurationSource(corsConfigurationSource()) .and() .authorizeRequests() .requestMatchers("/api/auth/signin").permitAll() // Allow signin endpoint .requestMatchers(HttpMethod.OPTIONS, "/api/auth/signin").permitAll() // Allow OPTIONS for /api/auth/signin .anyRequest().authenticated() // Secure other requests .and() .addFilterBefore(jwtAuthenticationFilter, UsernamePasswordAuthenticationFilter.class); // Register the custom JWT filter return http.build(); } @Bean public CorsConfigurationSource corsConfigurationSource() { // CORS configuration CorsConfiguration corsConfig = new CorsConfiguration(); corsConfig.setAllowedOrigins(Arrays.asList("http://localhost:3000")); // Set your frontend domain here corsConfig.setAllowedMethods(Arrays.asList("GET", "POST", "PUT", "DELETE", "OPTIONS")); // Allow these methods corsConfig.setAllowedHeaders(Arrays.asList("Content-Type", "Authorization")); // Allow these headers corsConfig.setAllowCredentials(true); // Allow credentials like cookies, if needed // Register the CORS configuration UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource(); source.registerCorsConfiguration("/**", corsConfig); return source; } }
自定义JwtAuthenticationFilter实现:
@Component public class JwtAuthenticationFilter extends OncePerRequestFilter { private final JwtTokenProvider jwtTokenProvider; public JwtAuthenticationFilter(JwtTokenProvider jwtTokenProvider) { this.jwtTokenProvider = jwtTokenProvider; } @Override protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain chain) throws ServletException, IOException { // Extract and validate JWT String jwt = getJwtFromRequest(request); if (StringUtils.hasText(jwt) && jwtTokenProvider.validateToken(jwt)) { String username = jwtTokenProvider.getUsernameFromToken(jwt); // Set authentication in security context SecurityContextHolder.getContext().setAuthentication(jwtTokenProvider.getAuthentication(username)); } // Continue with the filter chain chain.doFilter(request, response); } private String getJwtFromRequest(HttpServletRequest request) { String bearerToken = request.getHeader("Authorization"); if (StringUtils.hasText(bearerToken) && bearerToken.startsWith("Bearer ")) { return bearerToken.substring(7); // Extract the token without the "Bearer " prefix } return null; } }
有没有大佬能帮我排查下问题出在哪呀?
备注:内容来源于stack exchange,提问作者Bharath
相关产品推荐
相关产品推荐

