You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security整合Vaadin登录失败问题求助

登录失败排查与解决方案

核心问题排查与修复步骤

1. 密码匹配逻辑修正

你配置了BCryptPasswordEncoder作为密码编码器,需严格遵循以下规则:

  • 数据库中存储的密码必须是纯BCrypt哈希值(无{bcrypt}前缀),比如通过new BCryptPasswordEncoder().encode("你的明文密码")生成的字符串。如果带前缀,Spring Security会把前缀当成密码的一部分匹配,必然失败。
  • 可在TribunalesUserDetailsService中添加调试代码验证密码匹配结果:
    @Autowired
    private PasswordEncoder passwordEncoder;
    
    @Override
    public UserDetails loadUserByUsername(String username) throws UsernameNotFoundException {
        // ... 原有代码
        if(it.hasNext()){
            Persona persona = it.next();
            // 调试密码匹配
            boolean isMatch = passwordEncoder.matches("测试明文密码", persona.getContrasena());
            System.out.println("密码匹配结果:" + isMatch);
            // ... 原有代码
        }
    }
    

2. 角色权限格式调整

Spring Security默认要求角色权限以ROLE_前缀开头,否则无法识别为有效角色:

  • 直接修改角色存储的codigo值,比如将ADMIN改为ROLE_ADMIN;
  • 或者在代码中统一添加前缀,避免修改数据库:
    for (Rol rol : roles) {
        authorityList.add(new SimpleGrantedAuthority("ROLE_" + rol.getCodigo()));
    }
    

3. 用户与角色查询逻辑校验

  • 确认personaRepository.search(username)是精确匹配用户名,如果是模糊查询可能返回错误用户,建议改为精确查询方法(比如findByUsuario(username))。
  • 验证rolRepository.search(persona.getUsuario())能正确查询到该用户的所有角色,可添加日志打印角色列表,排查是否为空或返回错误角色。

4. Bean配置优化

  • TribunalesUserDetailsService已通过@Service注解成为Spring Bean,无需在SecurityConfig中重复定义UserDetailsService Bean,删除以下代码避免冲突:
    @Bean
    public UserDetailsService users() {
        return userDetailsService;
    }
    
  • 建议直接注入PersonaRepository和RolRepository,替代通过CrmService间接获取,减少中间环节的潜在问题:
    @Service
    public class TribunalesUserDetailsService implements UserDetailsService {
    
        @Autowired
        private PersonaRepository personaRepository;
        @Autowired
        private RolRepository rolRepository;
    
        @Override
        public UserDetails loadUserByUsername(String username) throws UsernameNotFoundException {
            Set<GrantedAuthority> authorityList = new HashSet<>();
            // 改用精确查询
            Persona persona = personaRepository.findByUsuario(username);
            if(persona != null){
                List<Rol> roles = rolRepository.findByUsuario(persona.getUsuario());
                for (Rol rol : roles) {
                    authorityList.add(new SimpleGrantedAuthority("ROLE_" + rol.getCodigo()));
                }
                return new org.springframework.security.core.userdetails.User(persona.getUsuario(), persona.getContrasena(), authorityList);
            }else{
                throw new UsernameNotFoundException("Usuario no encontrado");
            }
        }
    }
    

验证流程

  1. 用BCryptPasswordEncoder重新生成密码,存入数据库(无前缀)。
  2. 启动应用前添加调试日志,确认查询到的用户、密码、角色信息正确。
  3. 确认passwordEncoder.matches返回true后,再尝试登录。

内容的提问来源于stack exchange,提问作者Tmato Cheat Engine

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 00:13:10