You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring报错:缺少AuthenticationManager类型Bean,SSO本地Demo搭建求助

解决Spring SSO项目中缺失AuthenticationManager Bean的问题

嘿,我刚在本地跟着教程搭建SSO演示项目,本来想先把相关机制摸透再用到其他项目里,结果直接卡壳了——系统一直报错说必须添加AuthenticationManager类型的Bean,程序根本跑不起来。

先给大家看看我的项目情况:
(注:文件目录结构暂未完整提供,以下是AuthApplication.java的部分代码)

package com.spud.auth;

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;

@SpringBootApplication
public class AuthApplication {
    public static void main(String[] args) {
        SpringApplication.run(AuthApplication.class, args);
    }

    // 其他注入或代码片段...
}

问题原因

Spring Security默认不会自动把AuthenticationManager作为可注入的Bean暴露出来,而SSO相关的核心组件(比如OAuth2授权服务器、认证流程过滤器)都需要依赖这个Bean来处理用户身份验证请求,所以才会抛出这个缺失Bean的错误。

具体解决方案

方案1:通过继承WebSecurityConfigurerAdapter暴露Bean

这是比较传统的方式,适合还在使用旧版Spring Security配置的项目:

import org.springframework.context.annotation.Bean;
import org.springframework.security.authentication.AuthenticationManager;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    // 暴露AuthenticationManager Bean供其他组件注入使用
    @Bean
    @Override
    public AuthenticationManager authenticationManagerBean() throws Exception {
        return super.authenticationManagerBean();
    }

    // 可以在这里添加用户认证规则、权限配置等
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .authorizeRequests()
            .antMatchers("/auth/**").permitAll() // 开放认证相关接口
            .anyRequest().authenticated();
    }
}

方案2:使用AuthenticationConfiguration获取(Spring Boot 2.1+推荐)

如果你的项目用的是较新版本的Spring Security,推荐用这种不需要继承适配器的方式:

import org.springframework.context.annotation.Bean;
import org.springframework.security.authentication.AuthenticationManager;
import org.springframework.security.config.annotation.authentication.configuration.AuthenticationConfiguration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;

@EnableWebSecurity
public class SecurityConfig {

    // 从AuthenticationConfiguration中获取并暴露AuthenticationManager
    @Bean
    public AuthenticationManager authenticationManager(AuthenticationConfiguration authConfig) throws Exception {
        return authConfig.getAuthenticationManager();
    }

    // 配置HttpSecurity的访问规则
    protected void configure(HttpSecurity http) throws Exception {
        http
            .csrf().disable() // 根据实际场景决定是否关闭CSRF
            .authorizeRequests()
            .anyRequest().authenticated()
            .and()
            .formLogin(); // 启用表单登录
    }
}

方案3:检查依赖是否齐全

别忘了确认你的项目已经引入了Spring Security的 starter 依赖:

  • Maven(pom.xml):
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>
  • Gradle(build.gradle):
implementation 'org.springframework.boot:spring-boot-starter-security'

添加完上述配置后,重新启动项目,应该就能解决这个缺失Bean的问题啦!

内容的提问来源于stack exchange,提问作者Thomas Rokicki

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 04:05:29