You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security未拦截请求:新手配置失效求助

解决Spring Security配置不生效、未拦截请求的问题

Hey 👋,作为Spring Security新手遇到这种配置不生效的情况太正常了,我帮你一步步排查可能的问题:

1. 先补全必要的依赖

你贴的依赖只包含了spring-security-core,但要让Web请求拦截生效,还需要另外两个核心依赖。分两种场景给你配置:

普通Spring Web项目

需要手动引入三个核心依赖:

<dependency>
    <groupId>org.springframework.security</groupId>
    <artifactId>spring-security-core</artifactId>
    <version>5.0.3.RELEASE</version>
</dependency>
<dependency>
    <groupId>org.springframework.security</groupId>
    <artifactId>spring-security-web</artifactId>
    <version>5.0.3.RELEASE</version>
</dependency>
<dependency>
    <groupId>org.springframework.security</groupId>
    <artifactId>spring-security-config</artifactId>
    <version>5.0.3.RELEASE</version>
</dependency>

Spring Boot项目(更省心)

直接用starter依赖,它会自动帮你引入所有必要组件,版本和你的Spring Boot版本匹配即可(5.0.3.RELEASE对应Spring Boot 2.0.x系列):

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>

2. 确保配置类正确编写

你需要创建一个带@EnableWebSecurity注解的配置类,继承WebSecurityConfigurerAdapter(5.0.x版本还支持这个类),示例如下:

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .authorizeRequests()
                .anyRequest().authenticated() // 拦截所有请求,要求认证
                .and()
            .formLogin() // 启用默认的表单登录页面
                .permitAll(); // 登录页面允许匿名访问
    }
}

这个配置会让所有请求都被拦截,跳转到Spring Security自带的登录页面。

3. 检查配置类是否被Spring扫描到

如果你的配置类不在Spring的组件扫描范围内,Spring根本不会加载它。确保配置类所在的包是启动类(或@ComponentScan指定包)的子包或同级包。比如启动类在com.example.demo,配置类放在com.example.demo.security就没问题。

4. 普通Spring项目需额外配置过滤器(Spring Boot跳过此步)

如果不是Spring Boot项目,你需要在web.xml中注册Spring Security的核心过滤器,或者用Java配置方式初始化:

XML方式(web.xml)

<filter>
    <filter-name>springSecurityFilterChain</filter-name>
    <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
</filter>
<filter-mapping>
    <filter-name>springSecurityFilterChain</filter-name>
    <url-pattern>/*</url-pattern>
</filter-mapping>

Java配置方式

import org.springframework.web.servlet.support.AbstractAnnotationConfigDispatcherServletInitializer;
import org.springframework.web.filter.DelegatingFilterProxy;
import javax.servlet.Filter;

public class AppInitializer extends AbstractAnnotationConfigDispatcherServletInitializer {

    @Override
    protected Class<?>[] getRootConfigClasses() {
        return new Class[]{SecurityConfig.class};
    }

    @Override
    protected Class<?>[] getServletConfigClasses() {
        return new Class[]{WebConfig.class}; // 你的Spring MVC配置类
    }

    @Override
    protected String[] getServletMappings() {
        return new String[]{"/"};
    }

    @Override
    protected Filter[] getServletFilters() {
        DelegatingFilterProxy securityFilter = new DelegatingFilterProxy("springSecurityFilterChain");
        return new Filter[]{securityFilter};
    }
}

5. 排查是否有配置冲突

如果项目里有其他自定义过滤器或拦截器,可能会影响Spring Security过滤器的执行顺序。springSecurityFilterChain需要是第一个执行的过滤器,才能确保所有请求都被拦截。

你可以先按上面的步骤逐一排查,最常见的问题就是依赖不全或者配置类没被正确加载。如果还是不行,可以把完整的配置类和项目结构贴出来,我再帮你深挖~

内容的提问来源于stack exchange,提问作者Daimon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 04:11:23