springboot 3.2.5集成spring security 只放行get请求,其他请求403

环境配置

  • jdk 17
xml 复制代码
<parent>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-parent</artifactId>
        <version>3.2.5</version>
        <relativePath/> <!-- lookup parent from repository -->
    </parent>
 <dependency>
     <groupId>org.springframework.boot</groupId>
     <artifactId>spring-boot-starter-web</artifactId>
 </dependency>
     <dependency>
         <groupId>org.springframework.boot</groupId>
         <artifactId>spring-boot-starter-security</artifactId>
     </dependency>

解决办法

java 复制代码
    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http.csrf(AbstractHttpConfigurer::disable);// 关闭 crsf保护

		// 设置需要进行权限认证的请求
        http.authorizeRequests((authorizeRequests) ->
                        authorizeRequests
                                .requestMatchers("/**").hasRole("USER")
                ).formLogin(withDefaults());
        return http.build();
    }

验证

相关推荐
码事漫谈6 小时前
骂AI,会让它做得更好吗?
后端
萧瑟余晖7 小时前
Spring Boot 核心理念与快速上手
spring boot
陈随易7 小时前
bm2,Node.js 与 Bun 项目部署新选择
前端·后端·程序员
省钱兄--zs7 小时前
北京24小时自助健身房系统软件开发实战:从架构设计到部署指南
java·数据仓库·spring boot·小程序·需求分析
架构技术专栏8 小时前
AI Agent 框架怎么选:从一次制度查询拆出技术边界
后端·面试
明月_清风10 小时前
SaaS 的三层挣钱逻辑,正在被 AI 从第一层击穿
人工智能·后端
谁在黄金彼岸11 小时前
nginx服务化五套方案原理解剖与选型
后端
谁在黄金彼岸12 小时前
WinSW在Win7上失败真相-实测与修复
后端
花间相见12 小时前
【后端开发|Redis进阶01】—— Redis分布式锁全解:从SETNX到Redisson看门狗,再到RedLock
后端·面试
llqbzllll12 小时前
A2A 1.0 到底和 MCP 差在哪:从 Agent Card、Task 到 Java 最小互操作
后端