Spring Security未拦截请求:新手配置失效求助
Hey 👋,作为Spring Security新手遇到这种配置不生效的情况太正常了,我帮你一步步排查可能的问题:
1. 先补全必要的依赖
你贴的依赖只包含了spring-security-core,但要让Web请求拦截生效,还需要另外两个核心依赖。分两种场景给你配置:
普通Spring Web项目
需要手动引入三个核心依赖:
<dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-core</artifactId> <version>5.0.3.RELEASE</version> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-web</artifactId> <version>5.0.3.RELEASE</version> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-config</artifactId> <version>5.0.3.RELEASE</version> </dependency>
Spring Boot项目(更省心)
直接用starter依赖,它会自动帮你引入所有必要组件,版本和你的Spring Boot版本匹配即可(5.0.3.RELEASE对应Spring Boot 2.0.x系列):
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency>
2. 确保配置类正确编写
你需要创建一个带@EnableWebSecurity注解的配置类,继承WebSecurityConfigurerAdapter(5.0.x版本还支持这个类),示例如下:
import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; @Configuration @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http .authorizeRequests() .anyRequest().authenticated() // 拦截所有请求,要求认证 .and() .formLogin() // 启用默认的表单登录页面 .permitAll(); // 登录页面允许匿名访问 } }
这个配置会让所有请求都被拦截,跳转到Spring Security自带的登录页面。
3. 检查配置类是否被Spring扫描到
如果你的配置类不在Spring的组件扫描范围内,Spring根本不会加载它。确保配置类所在的包是启动类(或@ComponentScan指定包)的子包或同级包。比如启动类在com.example.demo,配置类放在com.example.demo.security就没问题。
4. 普通Spring项目需额外配置过滤器(Spring Boot跳过此步)
如果不是Spring Boot项目,你需要在web.xml中注册Spring Security的核心过滤器,或者用Java配置方式初始化:
XML方式(web.xml)
<filter> <filter-name>springSecurityFilterChain</filter-name> <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class> </filter> <filter-mapping> <filter-name>springSecurityFilterChain</filter-name> <url-pattern>/*</url-pattern> </filter-mapping>
Java配置方式
import org.springframework.web.servlet.support.AbstractAnnotationConfigDispatcherServletInitializer; import org.springframework.web.filter.DelegatingFilterProxy; import javax.servlet.Filter; public class AppInitializer extends AbstractAnnotationConfigDispatcherServletInitializer { @Override protected Class<?>[] getRootConfigClasses() { return new Class[]{SecurityConfig.class}; } @Override protected Class<?>[] getServletConfigClasses() { return new Class[]{WebConfig.class}; // 你的Spring MVC配置类 } @Override protected String[] getServletMappings() { return new String[]{"/"}; } @Override protected Filter[] getServletFilters() { DelegatingFilterProxy securityFilter = new DelegatingFilterProxy("springSecurityFilterChain"); return new Filter[]{securityFilter}; } }
5. 排查是否有配置冲突
如果项目里有其他自定义过滤器或拦截器,可能会影响Spring Security过滤器的执行顺序。springSecurityFilterChain需要是第一个执行的过滤器,才能确保所有请求都被拦截。
你可以先按上面的步骤逐一排查,最常见的问题就是依赖不全或者配置类没被正确加载。如果还是不行,可以把完整的配置类和项目结构贴出来,我再帮你深挖~
内容的提问来源于stack exchange,提问作者Daimon

