求助:Spring Cloud Finchley.RC1的Eureka如何恢复Egware.SR3认证机制
恢复Eureka Server的HTTP Basic认证机制(适配Finchley.RC1)
这个问题根源在于Spring Cloud Finchley版本对应的Spring Security默认配置做了调整——默认启用了表单登录和CSRF防护,而Eureka客户端是通过HTTP Basic认证和Server交互的,自然就被拦截了。要恢复到Egware.SR3的原有认证机制,只需要在Eureka Server里自定义Spring Security配置即可,具体步骤如下:
1. 确认依赖引入
先确保你的Eureka Server项目已经添加了spring-boot-starter-security依赖(如果之前没加的话),这是开启认证功能的基础。
2. 自定义Spring Security配置类
新建一个配置类,继承WebSecurityConfigurerAdapter,通过重写configure(HttpSecurity http)方法调整认证规则:
import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { // 关闭Eureka相关端点的CSRF防护,因为客户端不会携带CSRF Token http.csrf().ignoringAntMatchers("/eureka/**") // 要求访问Eureka端点的请求必须经过认证 .and() .authorizeRequests() .antMatchers("/eureka/**").authenticated() // 启用HTTP Basic认证模式 .and() .httpBasic(); } }
配置细节说明:
csrf().ignoringAntMatchers("/eureka/**"):忽略Eureka端点的CSRF检查,否则客户端的请求会被直接拒绝。authorizeRequests().antMatchers("/eureka/**").authenticated():限制只有认证后的请求才能访问Eureka相关接口。httpBasic():切换到HTTP Basic认证模式,这样客户端就能通过http://user:password@localhost:8761/eureka的方式传递凭证。
3. 配置认证用户信息
在application.yml(或application.properties)里保持原有用户密码配置即可:
spring: security: user: name: user password: password
4. 客户端配置无需修改
你的Eureka客户端依然可以沿用原来的配置方式:
eureka: client: serviceUrl: defaultZone: http://user:password@localhost:8761/eureka
完成以上配置后,Eureka Server就会恢复到Egware.SR3版本的HTTP Basic认证机制,客户端就能正常通过URL中的凭证完成认证了。
内容的提问来源于stack exchange,提问作者Zoltan Altfatter
相关产品推荐
相关产品推荐

