Spring Boot 2.0.1中security.basic.enabled弃用,求替代方案
解决*
security.basic.enabled: false*失效的方案 嘿,针对你在Spring Boot 2.0.1.RELEASE版本里遇到的*security.basic.enabled*配置失效、被警告弃用的问题,这里有官方推荐的替代方案,完全适配你的版本:
1. 自定义安全配置类
新建一个Spring配置类,继承WebSecurityConfigurerAdapter,通过重写方法来关闭默认的基础安全认证,代码如下:
import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; @Configuration public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { // 关闭CSRF保护(如果你的接口不需要的话),同时允许所有请求无需认证即可访问 http.csrf().disable() .authorizeRequests() .anyRequest().permitAll(); } }
2. 清理无效配置
把你application.yml里这段已经失效的配置删掉就行:
security: basic: enabled: false
额外小提示
如果之后你需要对特定路径做权限控制,也可以在这个配置类里灵活调整规则,比如只放行公开接口,其他接口需要认证:
http.csrf().disable() .authorizeRequests() .antMatchers("/public/**", "/actuator/**").permitAll() // 放行指定路径 .anyRequest().authenticated(); // 其余路径需要认证
这个方案完全遵循Spring Boot 2.x版本的安全规范,不仅替代了原来的配置作用,还能让你更灵活地定制项目的安全策略。
内容的提问来源于stack exchange,提问作者Jeff Cook
相关产品推荐
相关产品推荐

