You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Web部署Wildfly请求返回403问题求助

Spring Boot WAR部署至Wildfly返回403的排查与修复

1. 修正WAR打包配置

Spring Boot默认依赖内置Tomcat,打包WAR需调整配置适配Wildfly:

  • 在pom.xml中设置打包方式为war,排除内置Tomcat并添加provided范围的Servlet API依赖:
    <packaging>war</packaging>
    
    <dependencies>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-web</artifactId>
            <exclusions>
                <exclusion>
                    <groupId>org.springframework.boot</groupId>
                    <artifactId>spring-boot-starter-tomcat</artifactId>
                </exclusion>
            </exclusions>
        </dependency>
        <dependency>
            <groupId>javax.servlet</groupId>
            <artifactId>javax.servlet-api</artifactId>
            <version>4.0.1</version>
            <scope>provided</scope>
        </dependency>
    </dependencies>
    
  • 启动类必须继承SpringBootServletInitializer并重写configure方法:
    @SpringBootApplication
    public class DemoApp extends SpringBootServletInitializer {
        @Override
        protected SpringApplicationBuilder configure(SpringApplicationBuilder app) {
            return app.sources(DemoApp.class);
        }
    
        public static void main(String[] args) {
            SpringApplication.run(DemoApp.class, args);
        }
    }
    

2. 调整Wildfly默认安全域

全新安装的Wildfly默认安全域other会强制拦截所有Web请求做认证,可临时修改关闭验证排查:

  • 编辑standalone.xml,找到<subsystem xmlns="urn:jboss:domain:security:2.0">节点下的<security-domain name="other" cache-type="default">,替换认证模块为Disabled:
    <security-domain name="other" cache-type="default">
        <authentication>
            <login-module code="Disabled" flag="required"/>
        </authentication>
    </security-domain>
    
    重启Wildfly后重新部署测试,若请求恢复正常则说明是默认安全拦截导致的问题。

3. 确认访问路径正确性

部署到Wildfly后,访问URL需包含WAR包的上下文路径(默认是WAR文件名去掉.war后缀):

  • 若Controller映射为@GetMapping("/hello"),WAR包名为demo.war,则正确访问路径为http://localhost:8080/demo/hello,不要遗漏上下文路径。

4. 检查访问日志

查看standalone/log/access.log,里面会记录请求的完整路径、状态码等详细信息,可确认请求是否正确到达应用,是否存在未被server.log捕获的拦截行为。

内容的提问来源于stack exchange,提问作者Ben Jones

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 19:12:37