You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Spring Security实现应用首页匿名访问,仅认证指定接口

解决Spring Security自动重定向登录页的问题

这是Spring Security默认全局拦截规则导致的问题——它默认会保护所有端点,未登录用户访问任何路径都会被跳转到登录页。要实现访客直接访问首页、仅部分API需要认证的需求,只需要自定义Security的权限配置规则就行,下面分两种版本给你具体方案:

方案一:Spring Security 5.7+(推荐,WebSecurityConfigurerAdapter已弃用)

创建配置类,用@Configuration和@EnableWebSecurity注解,通过@Bean定义SecurityFilterChain来配置权限规则:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            // 按需关闭CSRF(如果前端不需要该防护可关闭,否则保留默认)
            .csrf(csrf -> csrf.disable())
            // 配置权限匹配规则
            .authorizeHttpRequests(auth -> auth
                // 允许所有用户访问首页及相关路径(如果首页依赖静态资源,可追加/static/**、/css/**等路径)
                .requestMatchers("/MyApp", "/MyApp/**").permitAll()
                // 指定需要登录才能访问的API端点,比如/api/secure/**这类路径
                .requestMatchers("/api/secure/**").authenticated()
                // 其他路径默认允许访问(可根据需求改为denyAll)
                .anyRequest().permitAll()
            )
            // 配置登录相关逻辑(如需自定义登录页,可修改loginPage路径)
            .formLogin(form -> form
                .loginPage("/login")
                .permitAll()
        );
        
        return http.build();
    }
}

方案二:使用WebSecurityConfigurerAdapter(旧版本兼容)

如果你的项目还在使用Spring Security 5.7之前的版本,可采用这种继承适配器的方式:

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .csrf().disable()
            .authorizeRequests()
                // 允许匿名访问首页
                .antMatchers("/MyApp", "/MyApp/**").permitAll()
                // 需要认证的API路径
                .antMatchers("/api/secure/**").authenticated()
                .anyRequest().permitAll()
            .and()
            .formLogin()
                .permitAll();
    }
}

关键注意点

  • permitAll():表示该路径允许所有用户访问,包括未登录的访客;authenticated():表示访问该路径必须先完成登录认证。
  • 路径匹配有顺序优先级:更具体的路径规则要放在前面,比如如果/MyApp/secure这类子路径需要认证,要把它的规则写在/MyApp/**前面,否则会被permitAll()的规则覆盖。
  • 如果首页依赖静态资源(CSS、JS、图片等),记得把对应静态资源路径也加入permitAll()的规则中。

配置完成后,访问http://localhost:8080/MyApp就会直接加载首页,只有你指定的API端点才会要求用户登录认证。

内容的提问来源于stack exchange,提问作者Praful Jha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 04:09:57