Spring报错:缺少AuthenticationManager类型Bean,SSO本地Demo搭建求助
解决Spring SSO项目中缺失AuthenticationManager Bean的问题
嘿,我刚在本地跟着教程搭建SSO演示项目,本来想先把相关机制摸透再用到其他项目里,结果直接卡壳了——系统一直报错说必须添加AuthenticationManager类型的Bean,程序根本跑不起来。
先给大家看看我的项目情况:
(注:文件目录结构暂未完整提供,以下是AuthApplication.java的部分代码)
package com.spud.auth; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.boot.SpringApplication; import org.springframework.boot.autoconfigure.SpringBootApplication; @SpringBootApplication public class AuthApplication { public static void main(String[] args) { SpringApplication.run(AuthApplication.class, args); } // 其他注入或代码片段... }
问题原因
Spring Security默认不会自动把AuthenticationManager作为可注入的Bean暴露出来,而SSO相关的核心组件(比如OAuth2授权服务器、认证流程过滤器)都需要依赖这个Bean来处理用户身份验证请求,所以才会抛出这个缺失Bean的错误。
具体解决方案
方案1:通过继承WebSecurityConfigurerAdapter暴露Bean
这是比较传统的方式,适合还在使用旧版Spring Security配置的项目:
import org.springframework.context.annotation.Bean; import org.springframework.security.authentication.AuthenticationManager; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { // 暴露AuthenticationManager Bean供其他组件注入使用 @Bean @Override public AuthenticationManager authenticationManagerBean() throws Exception { return super.authenticationManagerBean(); } // 可以在这里添加用户认证规则、权限配置等 @Override protected void configure(HttpSecurity http) throws Exception { http .authorizeRequests() .antMatchers("/auth/**").permitAll() // 开放认证相关接口 .anyRequest().authenticated(); } }
方案2:使用AuthenticationConfiguration获取(Spring Boot 2.1+推荐)
如果你的项目用的是较新版本的Spring Security,推荐用这种不需要继承适配器的方式:
import org.springframework.context.annotation.Bean; import org.springframework.security.authentication.AuthenticationManager; import org.springframework.security.config.annotation.authentication.configuration.AuthenticationConfiguration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; @EnableWebSecurity public class SecurityConfig { // 从AuthenticationConfiguration中获取并暴露AuthenticationManager @Bean public AuthenticationManager authenticationManager(AuthenticationConfiguration authConfig) throws Exception { return authConfig.getAuthenticationManager(); } // 配置HttpSecurity的访问规则 protected void configure(HttpSecurity http) throws Exception { http .csrf().disable() // 根据实际场景决定是否关闭CSRF .authorizeRequests() .anyRequest().authenticated() .and() .formLogin(); // 启用表单登录 } }
方案3:检查依赖是否齐全
别忘了确认你的项目已经引入了Spring Security的 starter 依赖:
- Maven(pom.xml):
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency>
- Gradle(build.gradle):
implementation 'org.springframework.boot:spring-boot-starter-security'
添加完上述配置后,重新启动项目,应该就能解决这个缺失Bean的问题啦!
内容的提问来源于stack exchange,提问作者Thomas Rokicki
相关产品推荐
相关产品推荐

