How to solve Spring security misconfiguration: incorrect request matcher type?

Viewed 967

I have this Spring security configuration:

<?xml version="1.0" encoding="UTF-8" ?>
<beans xmlns="http://www.springframework.org/schema/beans"
       xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
       xmlns:oauth="http://www.springframework.org/schema/security/oauth2"
       xsi:schemaLocation="http://www.springframework.org/schema/security/oauth2 http://www.springframework.org/schema/security/spring-security-oauth2-2.0.xsd
  http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security-3.2.xsd
  http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-4.1.xsd ">

    <http pattern="/api/swagger-ui.html" security="none" xmlns="http://www.springframework.org/schema/security"/>
    <http pattern="/api/webjars/**" security="none" xmlns="http://www.springframework.org/schema/security"/>
    <http pattern="/api/swagger-resources/**" security="none" xmlns="http://www.springframework.org/schema/security"/>
    <http pattern="/api/v2/api-docs" security="none" xmlns="http://www.springframework.org/schema/security"/>

   <http pattern="/api/**" create-session="never" entry-point-ref="oauthAuthenticationEntryPoint"
         access-decision-manager-ref="accessDecisionManager" xmlns="http://www.springframework.org/schema/security">
     <anonymous enabled="false"/>
        <intercept-url pattern="/api/**" access="IS_AUTHENTICATED_FULLY"/>
        <custom-filter ref="resourceServerFilter" before="PRE_AUTH_FILTER"/>
        <access-denied-handler ref="oauthAccessDeniedHandler"/>
    </http>

    <bean id="accessDecisionManager" class="org.springframework.security.access.vote.UnanimousBased"
          xmlns="http://www.springframework.org/schema/beans">
        <constructor-arg>
            <list>
                <bean class="org.springframework.security.oauth2.provider.vote.ScopeVoter"/>
                <bean class="org.springframework.security.access.vote.AuthenticatedVoter"/>
            </list>
        </constructor-arg>
    </bean>

    <bean id="oauthAuthenticationEntryPoint"
          class="org.springframework.security.oauth2.provider.error.OAuth2AuthenticationEntryPoint">
        <property name="realmName" value="sample"/>
    </bean>

    <bean id="oauthAccessDeniedHandler"
          class="org.springframework.security.oauth2.provider.error.OAuth2AccessDeniedHandler"/>


    <oauth:resource-server id="resourceServerFilter" resource-id="sample" token-services-ref="remoteTokenServices"/>

    <bean id="remoteTokenServices" class="org.springframework.security.oauth2.provider.token.RemoteTokenServices">
        <property name="checkTokenEndpointUrl" value="${oauth.check.token.url}"/>
        <property name="clientId" value="${oauth.client:crdb}"/>
        <property name="clientSecret" value="${oauth.secret:secret}"/>
    </bean>

    <authentication-manager alias="authenticationManager" xmlns="http://www.springframework.org/schema/security">
    </authentication-manager>


    <oauth:expression-handler id="oauthExpressionHandler"/>
    <oauth:web-expression-handler id="oauthWebExpressionHandler"/>
</beans>

Fortify returns to me Spring security misconfiguration: incorrect request matcher type on line 9, 10, 11, 15. Can someone give me a point how to solve this issue? It seems there is a some path problem, but Im not so familiar with fortify, so I dont know how to solve this issue.

1 Answers

it seems like you have problem using <http/> tag used for configuration. Look closely whether you are using valid attributes related to that tag. You can simply identify the available properties/attributes for that by clicking on the tag.

It seems like xmlns="http://www.springframework.org/schema/security" this is making error because <http> does not have xmlns property.

You also don't need to define it in every http.

Try removing xmlns property from <http> tag and it should work.

For Reference: Spring Security XML Configuration

Available <http> attributes for configuration:

<http pattern=""
    name=""
    access-decision-manager-ref=""
    authentication-manager-ref=""
    auto-config=""
    create-session=""
    disable-url-rewriting=""
    entry-point-ref=""
    jaas-api-provision=""
    once-per-request=""
    realm=""
    request-matcher=""
    request-matcher-ref=""
    security=""
    security-context-repository-ref=""
    servlet-api-provision=""
    use-expressions=""/>
Related