You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot配置多个认证提供者出现StackOverflowError问题求助

Spring Boot配置多个认证提供者出现StackOverflowError问题求助

大家好,我现在遇到一个Spring Security的问题,想请教下各位:

我在项目里维护了internal_users和external_users两张数据库表,分别对应内部和外部用户,所以打算配置两个不同的认证提供者来处理不同的认证流程。但是当我同时配置两个提供者的时候,代码抛出了StackOverflowError,注释掉其中任意一个提供者,代码就能正常运行。

出现错误的完整配置代码:

@Configuration
@EnableGlobalMethodSecurity(
// securedEnabled = true,
// jsr250Enabled = true,
prePostEnabled = true)
public class WebSecurityConfig {

@Autowired
private internalUserDetailsServiceImpl internalUserDetailsService;

@Autowired
private externalUserDetailsServiceImpl externalUserDetailsServiceImpl;

@Autowired
private AuthEntryPointJwt unauthorizedHandler;

@Autowired
private PasswordEncoder passwordEncoder;

private static final String[] AUTH_WHITELIST = {
"/api/auth/**",
"/swagger-resources/**",
"/swagger-ui/**",
"/v3/api-docs",
"/v2/api-docs",
"/webjars/**"
};

@Bean
public AuthTokenFilter authenticationJwtTokenFilter() {
return new AuthTokenFilter();
}

@Bean
public AuthenticationManager authenticationManager(AuthenticationConfiguration authConfig) throws Exception {
return authConfig.getAuthenticationManager();
}

@Bean
public DaoAuthenticationProvider externalUserauthenticationProvider() {
DaoAuthenticationProvider externalUserAuthProvider = new DaoAuthenticationProvider();
externalUserAuthProvider.setUserDetailsService(externalUserDetailsServiceImpl);
externalUserAuthProvider.setPasswordEncoder(passwordEncoder);
return externalUserAuthProvider;
}

@Bean
public DaoAuthenticationProvider internalUserAuthenticationProvider() {
DaoAuthenticationProvider internalUserAuthProvider = new DaoAuthenticationProvider();
internalUserAuthProvider.setUserDetailsService(internalUserDetailsServiceImpl);
internalUserAuthProvider.setPasswordEncoder(passwordEncoder);
return internalUserAuthProvider;
}

@Bean
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
http.cors().and().csrf().disable()
.exceptionHandling().authenticationEntryPoint(unauthorizedHandler).and()
.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS).and()
.authorizeRequests().antMatchers(AUTH_WHITELIST).permitAll()
.antMatchers("/api/test/**").permitAll()
.anyRequest().authenticated();

http.authenticationProvider(internalUserAuthProvider())
.authenticationProvider(externalUserAuthProvider());

http.addFilterBefore(authenticationJwtTokenFilter(), UsernamePasswordAuthenticationFilter.class);

return http.build();
}

}

错误信息:

Handler dispatch failed; nested exception is java.lang.StackOverflowError

我进一步调试发现,在调用认证的Controller代码处,authenticationManager.authenticate()方法出现了问题:

Authentication authentication = authenticationManager.authenticate(
new UsernamePasswordAuthenticationToken(authDTO.getUserName(), authDTO.getPassword()));
SecurityContextHolder.getContext().setAuthentication(authentication);

注释掉一个认证提供者后可以正常运行的代码:

@Configuration
@EnableGlobalMethodSecurity(
// securedEnabled = true,
// jsr250Enabled = true,
prePostEnabled = true)
public class WebSecurityConfig {

@Autowired
private internalUserDetailsServiceImpl internalUserDetailsService;

@Autowired
private externalUserDetailsServiceImpl externalUserDetailsServiceImpl;

@Autowired
private AuthEntryPointJwt unauthorizedHandler;

@Autowired
private PasswordEncoder passwordEncoder;

private static final String[] AUTH_WHITELIST = {
"/api/auth/**",
"/swagger-resources/**",
"/swagger-ui/**",
"/v3/api-docs",
"/v2/api-docs",
"/webjars/**"
};

@Bean
public AuthTokenFilter authenticationJwtTokenFilter() {
return new AuthTokenFilter();
}

@Bean
public AuthenticationManager authenticationManager(AuthenticationConfiguration authConfig) throws Exception {
return authConfig.getAuthenticationManager();
}

/*@Bean
public DaoAuthenticationProvider externalUserauthenticationProvider() {
DaoAuthenticationProvider externalUserAuthProvider = new DaoAuthenticationProvider();
externalUserAuthProvider.setUserDetailsService(externalUserDetailsServiceImpl);
externalUserAuthProvider.setPasswordEncoder(passwordEncoder);
return externalUserAuthProvider;
} */

@Bean
public DaoAuthenticationProvider internalUserAuthenticationProvider() {
DaoAuthenticationProvider internalUserAuthProvider = new DaoAuthenticationProvider();
internalUserAuthProvider.setUserDetailsService(internalUserDetailsServiceImpl);
internalUserAuthProvider.setPasswordEncoder(passwordEncoder);
return internalUserAuthProvider;
}

@Bean
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
http.cors().and().csrf().disable()
.exceptionHandling().authenticationEntryPoint(unauthorizedHandler).and()
.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS).and()
.authorizeRequests().antMatchers(AUTH_WHITELIST).permitAll()
.antMatchers("/api/test/**").permitAll()
.anyRequest().authenticated();

http.authenticationProvider(internalUserAuthProvider());
//.authenticationProvider(externalUserAuthProvider());

http.addFilterBefore(authenticationJwtTokenFilter(), UsernamePasswordAuthenticationFilter.class);

return http.build();
}

}

有没有大佬能指点下,我到底哪里配置错了导致这个栈溢出问题?

备注:内容来源于stack exchange,提问作者Krishna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 11:54:50