引自 @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { @Bean public DemoFilter demoFilter(){ return new DemoFilter(); } @Override protected void configure(HttpSecurity http) throws Exception { http.addFilterBefore(demoFilter(),AnonymousAuthenticationFilter.class). authorizeRequests(). antMatchers("/login","