Grails 3.3.x版本xss-sanitizer插件启动异常求助
Hey there, let's break down why your app is failing to start after upgrading to Grails 3.3.4 and how to fix it.
The Root Cause
Grails 3.3.x is built on Spring Boot 2.x, which introduced a breaking change to the package structure of FilterRegistrationBean:
- In Spring Boot 1.x (used by Grails 3.2.x), the class lived at
org.springframework.boot.context.embedded.FilterRegistrationBean - In Spring Boot 2.x, it moved to
org.springframework.boot.web.servlet.FilterRegistrationBean
The version of grails-xss-sanitizer you're using still references the old package path. When your upgraded app tries to load the plugin, it can't locate the class—hence the NoClassDefFoundError you're seeing.
Solutions to Try
1. Upgrade the Plugin to a Grails 3.3.x Compatible Version
First, check if the plugin has an updated release that supports Grails 3.3.x. If yes, update your build.gradle dependency to use the latest compatible version:
compile 'org.grails.plugins:xss-sanitizer:INSERT_COMPATIBLE_VERSION_HERE'
After updating, run ./gradlew clean build and restart your app to see if the issue resolves.
2. Manually Fix the Filter Registration (If No Plugin Update Exists)
If the plugin hasn't been updated for Grails 3.3.x, you can work around the issue by replacing the plugin's filter registration logic with your own:
- Step 1: Remove the old
grails-xss-sanitizerplugin dependency from yourbuild.gradle. - Step 2: Copy the core XSS filter class (
XssSanitizerFilter) from the plugin's source code into your project'ssrc/main/groovydirectory (preserving its original package structure, e.g.,grails/plugin/xss/sanitizer/XssSanitizerFilter.groovy). - Step 3: Create a Spring configuration class to register the filter using the new package path:
import org.springframework.boot.web.servlet.FilterRegistrationBean import grails.plugin.xss.sanitizer.XssSanitizerFilter import org.springframework.context.annotation.Bean import org.springframework.context.annotation.Configuration @Configuration class XssFilterConfiguration { @Bean FilterRegistrationBean<XssSanitizerFilter> xssSanitizerFilter() { FilterRegistrationBean<XssSanitizerFilter> registrationBean = new FilterRegistrationBean<>() registrationBean.filter = new XssSanitizerFilter() registrationBean.urlPatterns = ['/*'] // Apply filter to all requests registrationBean.order = 1 // Adjust filter order if needed return registrationBean } }
3. Temporary Downgrade (Not Recommended)
As a last resort, you could revert to Grails 3.2.11 for a quick fix, but this defeats the purpose of upgrading. It's far better to use one of the above solutions to get the plugin working with Grails 3.3.4.
Verification
After applying any of the fixes, run ./gradlew clean bootRun to start your app. Check the logs to confirm the NoClassDefFoundError is gone and the app launches successfully.
内容的提问来源于stack exchange,提问作者Charu Jain

