Spring Security标签在Thymeleaf中无法识别的问题排查求助
Hey there, let's dig into why both your authenticated and anonymous blocks are showing up—this is a common issue when the Spring Security Thymeleaf integration isn't set up correctly. Here are the most likely fixes:
1. Fix Dependency Version Mismatch
Looking at your pom.xml, you're using thymeleaf-extras-springsecurity4, but this is incompatible with newer Spring Boot versions (2.x+ uses Spring Security 5, 3.x+ uses Spring Security 6).
- For Spring Boot 2.x: Replace the security extras dependency with:
<dependency> <groupId>org.thymeleaf.extras</groupId> <artifactId>thymeleaf-extras-springsecurity5</artifactId> <!-- No need to specify version—Spring Boot's parent manages compatible versions --> </dependency> - For Spring Boot 3.x: Use the Spring Security 6 variant:
<dependency> <groupId>org.thymeleaf.extras</groupId> <artifactId>thymeleaf-extras-springsecurity6</artifactId> </dependency>
Remove the old springsecurity4 dependency entirely—version mismatches are the #1 cause of unprocessed sec tags.
2. Add the Spring Security Namespace to Your HTML
Thymeleaf won't recognize sec: attributes unless you declare the namespace in your HTML root tag. Make sure every template using security tags includes this:
<html xmlns:th="http://www.thymeleaf.org" xmlns:sec="http://www.thymeleaf.org/extras/spring-security">
Also, note that the JSP-style <sec:authorize> tags don't work with Thymeleaf—stick to the Thymeleaf attribute syntax (sec:authorize="isAuthenticated()") for all security checks.
3. Ensure the Security Dialect is Registered
While Spring Boot usually auto-registers the SpringSecurityDialect, sometimes custom Thymeleaf configurations can override this. Add a configuration class to explicitly register it if needed:
For Spring Security 5:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.thymeleaf.extras.springsecurity5.dialect.SpringSecurityDialect; @Configuration public class ThymeleafSecurityConfig { @Bean public SpringSecurityDialect springSecurityDialect() { return new SpringSecurityDialect(); } }
For Spring Security 6, just swap the import to org.thymeleaf.extras.springsecurity6.dialect.SpringSecurityDialect.
4. Verify Your Spring Security Configuration
Double-check that your security setup is actually active. Make sure you have a configuration class annotated with @EnableWebSecurity that defines authentication and authorization rules. For example:
import org.springframework.context.annotation.Bean; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.core.userdetails.User; import org.springframework.security.core.userdetails.UserDetails; import org.springframework.security.core.userdetails.UserDetailsService; import org.springframework.security.provisioning.InMemoryUserDetailsManager; import org.springframework.security.web.SecurityFilterChain; @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(req -> req .anyRequest().authenticated() ) .formLogin() // Enable form-based login .and() .logout(); return http.build(); } @Bean public UserDetailsService userDetailsService() { UserDetails testUser = User.withDefaultPasswordEncoder() .username("testuser") .password("testpass") .roles("USER") .build(); return new InMemoryUserDetailsManager(testUser); } }
Without a valid security configuration, Spring Security won't process the authorization checks in your templates.
Final Notes
After making these changes, rebuild your project, clear any template caches, and test again. The sec:authorize attributes should now correctly show/hide content based on the user's authentication status.
内容的提问来源于stack exchange,提问作者DannyZ

