How can I configure Spring Security 6 to ignore the static resources folder?
20:54 24 Apr 2023

I am storing my public web resources (CSS, JS) in the 'static' folder, with the following path: 'java/com/myapp/resources/static/**'. Here my configuration classes:

SecurityConfig.java

@Configuration
@EnableWebSecurity
public class SecurityConfig {
    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
                .authorizeHttpRequests(authorize -> authorize
                        .anyRequest().authenticated())
                .formLogin(form -> form
                        .loginPage("/login")
                        .permitAll());
        return http.build();
    }

    @Bean
    public WebSecurityCustomizer webSecurityCustomizer() throws Exception {
        return (web) -> web.ignoring().antMatchers("/resources/static/**");
    }

}

And ResourceConfig.java

@Configuration
public class ResourceConfig implements WebMvcConfigurer {

    @Override
    public void addResourceHandlers(ResourceHandlerRegistry registry) { 
        registry.addResourceHandler("/static/**")
            .addResourceLocations("classpath:/static/");
    }
    
}

It worked on Spring Security version 5.x.x, but in the current version of Spring Security (which is 6.0.3), the method 'antMatchers(String)' is undefined for the type 'WebSecurity.IgnoredRequestConfigurer', so I can't configure it in the same way anymore.

I read this document (https://docs.spring.io/spring-security/reference/5.8/migration/servlet/config.html#use-new-requestmatchers) which stated that I can replace the deprecated 'antMatchers' methods with 'requestMatchers', like so:

@Bean
public WebSecurityCustomizer webSecurityCustomizer() {
    return (web) -> web.ignoring().requestMatchers("/resources/static/**");
}

However, even after making this change, my CSS files are still missing. So, I would like to ask: how can I configure Spring Security 6 to ignore the static resources folder? Thank you.

spring-boot spring-security