You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 2.0.1中security.basic.enabled弃用,求替代方案

解决*security.basic.enabled: false*失效的方案

嘿,针对你在Spring Boot 2.0.1.RELEASE版本里遇到的*security.basic.enabled*配置失效、被警告弃用的问题,这里有官方推荐的替代方案,完全适配你的版本:

1. 自定义安全配置类

新建一个Spring配置类,继承WebSecurityConfigurerAdapter,通过重写方法来关闭默认的基础安全认证,代码如下:

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        // 关闭CSRF保护(如果你的接口不需要的话),同时允许所有请求无需认证即可访问
        http.csrf().disable()
            .authorizeRequests()
            .anyRequest().permitAll();
    }
}

2. 清理无效配置

把你application.yml里这段已经失效的配置删掉就行:

security:
  basic:
    enabled: false

额外小提示

如果之后你需要对特定路径做权限控制,也可以在这个配置类里灵活调整规则,比如只放行公开接口,其他接口需要认证:

http.csrf().disable()
    .authorizeRequests()
    .antMatchers("/public/**", "/actuator/**").permitAll() // 放行指定路径
    .anyRequest().authenticated(); // 其余路径需要认证

这个方案完全遵循Spring Boot 2.x版本的安全规范,不仅替代了原来的配置作用,还能让你更灵活地定制项目的安全策略。

内容的提问来源于stack exchange,提问作者Jeff Cook

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:56:29