Spring Security整合UserDetailsService认证失效问题求助
Hey, let's break down why your Spring Security authentication isn't working even though the app starts up fine. I see a few key issues in your configuration that are likely causing the problem:
1. Missing Spring Security Filter Registration
The biggest problem here is that your AppInitializer doesn't register the Spring Security filter chain with the ServletContext. Without this filter, Spring Security can't intercept incoming requests to handle authentication at all.
In a Java-based setup, you can fix this by adding the DelegatingFilterProxy directly in your onStartup method (before registering your dispatchers):
// Register Spring Security Filter to intercept all requests FilterRegistration.Dynamic securityFilter = container.addFilter("springSecurityFilterChain", DelegatingFilterProxy.class); securityFilter.addMappingForUrlPatterns(null, false, "/*");
This ensures every request passes through Spring Security's processing pipeline.
2. Incorrect Bean Definition for Authentication Provider
Looking at your BusinessSecurityConfig, you've annotated the authenticationProvider() method with @Autowired—that's not right. This method is supposed to create a Spring-managed bean, so you need to replace @Autowired with @Bean:
@Bean public DaoAuthenticationProvider authenticationProvider() { DaoAuthenticationProvider authProvider = new DaoAuthenticationProvider(); authProvider.setUserDetailsService(userDetailsService); authProvider.setPasswordEncoder(getPasswordEncoder()); return authProvider; }
Without @Bean, Spring won't recognize this as a valid authentication provider, so your custom UserDetailsService won't be used during authentication.
3. Context Scanning & Component Detection
Make sure your UserDetailsServiceImpl is being picked up by Spring's component scanning:
- Check that your root configuration (like
MvcConfiguration) has@ComponentScanenabled, and that it includes the package whereUserDetailsServiceImpllives. - Verify that
BusinessSecurityConfigis actually being loaded into the application context—since you're registering it explicitly viacontext.register(BusinessSecurityConfig.class), this should work, but double-check for any accidental exclusions.
4. Empty Authorities Collection in UserPrincipal
Your UserPrincipal's getAuthorities() returns an empty list. While this might not block successful authentication (if username/password are correct), it can cause authorization failures (e.g., being denied access even after logging in). Even if you don't use roles yet, implement this properly to avoid unexpected behavior:
@Override public Collection<? extends GrantedAuthority> getAuthorities() { // Replace with logic to convert your User's roles to GrantedAuthority objects return user.getRoles().stream() .map(role -> new SimpleGrantedAuthority(role.getName())) .collect(Collectors.toList()); }
5. Typo in Dispatcher Servlet Mapping
I noticed a typo in your AppInitializer when setting up the ppaDispatcher:
initDispatcher(businessDispatcher, 3, "/ppa");
This should reference the ppaDispatcher instead:
initDispatcher(ppaDispatcher, 3, "/ppa");
While this doesn't directly affect authentication, it's a critical error that will break routing for /ppa requests.
After fixing these issues, restart your app and test authentication again. If it still fails, enable debug logging for Spring Security by adding logging.level.org.springframework.security=DEBUG to your properties—this will give you detailed logs about exactly what's happening during the authentication process.
内容的提问来源于stack exchange,提问作者Evgeniy

