为什么我在Cloud Foundry上的Spring Boot 2上的执行器/刷新端点出现403 Forbidden错误{使用Cloud Config Server服务}

Shi*_*rma 5 spring-boot spring-boot-actuator spring-cloud-config

在我的项目中,我有以下bootstrap.properties文件:

spring.application.name=vault-demo
management.endpoints.web.exposure.include=*
Run Code Online (Sandbox Code Playgroud)

除此之外,我还定义了以下依赖项:

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-actuator</artifactId>
</dependency>
Run Code Online (Sandbox Code Playgroud)

配置服务器能够访问该属性,但是当我在GitHub和POST中更新该属性时,/refresh我得到了一个403: Forbidden.我是否需要在我的应用程序或bootstrap.properties中进行任何更改?

Shi*_*rma 8

我得到了解决方案,我需要添加安全配置,例如:

@Configuration
@EnableWebSecurity
public class SecurityConfiguration extends WebSecurityConfigurerAdapter{

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.csrf().disable();
    }
}
Run Code Online (Sandbox Code Playgroud)

另外,我必须添加以下依赖项:

<dependency> 
    <groupId>org.springframework.security</groupId> 
    <artifactId>spring-security-rsa</artifactId> 
    <version>1.0.5.RELEASE</version> 
</dependency>
Run Code Online (Sandbox Code Playgroud)

我在以下GitHub问题中找到了这个解决方案:https: //github.com/spring-cloud/spring-cloud-config/issues/950

  • 我不得不 csfr().disable(); 那是唯一的变化。 (2认同)