You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Spring Boot Security登录时出现HTTP ERROR 403问题求助

Spring Boot Security首次登录403问题排查与修复

问题现象

基于Spring Boot Security实现登录功能时,首次登录无论使用application.properties中定义的默认账号密码,还是数据库中的账号密码均会失败,点击登录后跳转至http://localhost:8080/error?continue,页面提示HTTP ERROR 403无权限;返回重新登录第二次则可成功。

提供的SecurityConfig代码

package com.firstweb.web.security;

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
public class SecurityConfig {
    private final CustomUserDetailsService userDetailsService;

    public SecurityConfig(CustomUserDetailsService userDetailsService) {
        this.userDetailsService = userDetailsService;
    }

    @Bean
    public static PasswordEncoder passwordEncoder () {
        return new BCryptPasswordEncoder();
    }
    
    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception{
        http
            .csrf(csrf -> csrf.disable())
            .authorizeHttpRequests((authz) -> authz
                .requestMatchers("/login", "/register", "/clubs", "/static/**", "/css/**", "/js/**")
                .permitAll()
            )
            .formLogin((form) -> form
                .loginPage("/login")
                .defaultSuccessUrl("/clubs?success")
                .loginProcessingUrl("/login")
                .failureUrl("/login?error=true")
                .permitAll()
            )
            .logout((logout) -> logout
                .logoutUrl("/logout")
                .permitAll())
            ;
        return http.build();
    }

    public void configure(AuthenticationManagerBuilder builder) throws Exception {
        builder.userDetailsService(userDetailsService).passwordEncoder((passwordEncoder()));
    }

}

问题原因

  1. AuthenticationManager配置未生效:Spring Security 5.7+版本弃用了WebSecurityConfigurerAdapter,原有的configure(AuthenticationManagerBuilder)方法不会被Spring自动调用,导致首次认证时CustomUserDetailsService未正确关联到认证管理器,触发认证逻辑异常。
  2. /error路径未被放行:首次登录失败后跳转的/error路径未加入匿名访问白名单,触发403权限拦截。
  3. 默认跳转逻辑受continue参数影响:首次登录时的continue参数可能指向未授权路径,导致跳转失败。

修复方案

1. 正确配置AuthenticationManager

替换原有的configure(AuthenticationManagerBuilder)方法,通过@Bean注册认证管理器,确保CustomUserDetailsService生效:

@Bean
public AuthenticationManager authenticationManager(HttpSecurity http) throws Exception {
    AuthenticationManagerBuilder authBuilder = http.getSharedObject(AuthenticationManagerBuilder.class);
    authBuilder.userDetailsService(userDetailsService).passwordEncoder(passwordEncoder());
    return authBuilder.build();
}

2. 放行/error路径

在authorizeHttpRequests中添加/error到允许匿名访问的列表,并明确其他路径需认证:

.authorizeHttpRequests((authz) -> authz
    .requestMatchers("/login", "/register", "/clubs", "/error", "/static/**", "/css/**", "/js/**")
    .permitAll()
    .anyRequest().authenticated()
)

3. 强制指定成功跳转页

修改defaultSuccessUrl,设置第二个参数为true,强制跳转到指定页面,忽略continue参数影响:

.formLogin((form) -> form
    .loginPage("/login")
    .defaultSuccessUrl("/clubs?success", true)
    .loginProcessingUrl("/login")
    .failureUrl("/login?error=true")
    .permitAll()
)

内容的提问来源于stack exchange,提问作者agen7p

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 22:32:09