由于csrf失败,Swagger没有显示控制器端点

  • 2025-10-11 13:51:32

在我的应用程序中,我添加了swagger,但它没有显示控制器apis。当我签入开发人员控制台时,它显示localhost:9000/和localhost:9000/csrf apis失败了。

​

​

下面是我的安全配置:

代码语言:javascript运行复制 @Override

protected void configure(AuthenticationManagerBuilder auth) {

auth.authenticationProvider(activeDirectoryLdapAuthenticationProvider());

}

@Bean

public AuthenticationProvider activeDirectoryLdapAuthenticationProvider() {

ActiveDirectoryLdapAuthenticationProvider authenticationProvider =

new ActiveDirectoryLdapAuthenticationProvider(ldapDomain, ldapUrl,ldapBase);

authenticationProvider.setConvertSubErrorCodesToExceptions(true);

authenticationProvider.setUseAuthenticationRequestCredentials(true);

authenticationProvider.setSearchFilter("(sAMAccountName={1})");

return authenticationProvider;

}

@Bean

@Override

public AuthenticationManager authenticationManagerBean() throws Exception {

return super.authenticationManagerBean();

}

@Override

protected void configure(HttpSecurity httpSecurity) throws Exception {

httpSecurity

.csrf()

.disable()

.exceptionHandling().authenticationEntryPoint(jwtUnAuthorizedResponseAuthenticationEntryPoint).and()

.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS).and()

.authorizeRequests()

.antMatchers("/v2/api-docs",

"/configuration/ui",

"/swagger-resources/**",

"/configuration/security",

"/swagger-ui.html",

"/webjars/**").permitAll()

.anyRequest().authenticated();

httpSecurity

.addFilterBefore(jwtAuthenticationTokenFilter, UsernamePasswordAuthenticationFilter.class);

httpSecurity

.headers()

.frameOptions().sameOrigin() //H2 Console Needs this setting

.cacheControl(); //disable caching

}

@Override

public void configure(WebSecurity webSecurity) throws Exception {

webSecurity

.ignoring()

.antMatchers(

HttpMethod.POST,

authenticationPath

)

.antMatchers(HttpMethod.OPTIONS, "/**")

.and()

.ignoring()

.antMatchers(

HttpMethod.GET,

"/" //Other Stuff You want to Ignore

)

.and()

.ignoring()

.antMatchers("/h2-console/**/**");//Should not be in Production!

}SwaggerConfig:

代码语言:javascript运行复制public static final String DEFAULT_INCLUDE_PATTERN = "/deployer/*.*";

@Bean

public Docket productApi() {

return new Docket(DocumentationType.SWAGGER_2).select()

.apis(RequestHandlerSelectors.basePackage("com.org.deployer.controller"))

.paths(PathSelectors.regex(DEFAULT_INCLUDE_PATTERN)).build().apiInfo(metaData())

.securityContexts(Lists.newArrayList(securityContext()))

.securitySchemes(Lists.newArrayList(apiKey()))

.useDefaultResponseMessages(false);

}

private ApiKey apiKey() {

return new ApiKey("JWT", AUTHORIZATION_HEADER, "header");

}

private SecurityContext securityContext() {

return SecurityContext.builder()

.securityReferences(defaultAuth())

.forPaths(PathSelectors.regex(DEFAULT_INCLUDE_PATTERN))

.build();

}

List defaultAuth() {

AuthorizationScope authorizationScope

= new AuthorizationScope("global", "accessEverything");

AuthorizationScope[] authorizationScopes = new AuthorizationScope[1];

authorizationScopes[0] = authorizationScope;

return Lists.newArrayList(

new SecurityReference("JWT", authorizationScopes));

}响应/v2/api-docs:

代码语言:javascript运行复制{

"swagger": "2.0",

"info": {

"description": "deployment Tool ",

"version": "1.0",

"title": " api",

"termsOfService": "Terms of service",

"contact": {

"name": "Support Team"

},

"license": {

}

},

"host": "localhost:9000",

"basePath": "/",

"securityDefinitions": {

"JWT": {

"type": "apiKey",

"name": "Authorization",

"in": "header"

}

}

}主计长:

代码语言:javascript运行复制package com.org.deployer.controller;

@RestController

@CrossOrigin(origins = "http://localhost:4200")

@Api(value = "package operations", description = "Operations pertaining to Package Schedule")

public class PackageScheduleController {

private static final Logger logger = LoggerFactory.getLogger(PackageScheduleController.class);

@Autowired

PackageScheduleService packageScheduleService;

@PostMapping("/schedule")

@ApiOperation(value = "This method is used to get the clients.")

public PackageScheduleResponse schedule(@RequestBody PackageScheduleRequest packageScheduleRequest){

try{

logger.info("Schedule Request received for {}",packageScheduleRequest.getName());

System.out.println(packageScheduleRequest.getScheduleTime().toLocalTime());

return packageScheduleService.schedule(packageScheduleRequest);

}

catch(Exception e){

logger.error("Exception occured",e);

throw new RuntimeException("Some Error Occured");

}

}

@GetMapping("/view-schedule")

public List schedule(){

try{

logger.info("Request received for fetching upcoming schedule jobs");

return packageScheduleService.fetchAllScheudules();

}

catch(Exception e){

logger.error("Exception occured",e);

throw new RuntimeException("Some Error Occured");

}

}

}通过看到,我可以理解这是相关的csrf配置,但不确定如何解决它。