添加Spring Security配置后应用出现404错误求助
解决Spring MVC集成Spring Security后404错误问题
问题描述
添加SecurityConfig和SecurityInitializer类后,Spring MVC应用出现404 Not Found错误,移除这两个类后应用可正常运行,调整依赖版本无法解决问题。
解决方案
1. 完善Spring Security授权配置
原SecurityConfig仅配置了内存认证规则,但未定义请求授权逻辑,Spring Security默认拦截所有请求且未正确转发到控制器。需添加HttpSecurity配置,明确各路径的访问权限并启用表单登录:
修改后的SecurityConfig:
package basic; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; import org.springframework.security.core.userdetails.User; @Configuration @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(AuthenticationManagerBuilder auth) throws Exception { User.UserBuilder userBuilder = User.withDefaultPasswordEncoder(); auth.inMemoryAuthentication() .withUser(userBuilder.username("Yehor").password("1111").roles("EMPLOYEE")) .withUser(userBuilder.username("Maria").password("2222").roles("HR")) .withUser(userBuilder.username("Yan").password("3333").roles("MANAGER", "HR")); } @Override protected void configure(HttpSecurity http) throws Exception { http.authorizeRequests() .antMatchers("/").hasRole("EMPLOYEE") .antMatchers("/hr-info").hasRole("HR") .antMatchers("/manager-info").hasAnyRole("MANAGER", "HR") .and() .formLogin().permitAll(); } }
2. 解决Servlet依赖冲突
pom.xml中同时引入Jakarta Servlet API(6.0.0)和javax Servlet API(4.0.1),二者存在包冲突(Spring Security 5.x基于javax.servlet,不兼容Jakarta EE 9+)。需移除Jakarta相关依赖:
修改后的pom.xml依赖部分:
<dependencies> <dependency> <groupId>junit</groupId> <artifactId>junit</artifactId> <version>3.8.1</version> <scope>test</scope> </dependency> <dependency> <groupId>javax.servlet</groupId> <artifactId>javax.servlet-api</artifactId> <version>4.0.1</version> <scope>provided</scope> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-web</artifactId> <version>5.4.1</version> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-config</artifactId> <version>5.4.1</version> </dependency> <!-- Spring Web MVC --> <dependency> <groupId>org.springframework</groupId> <artifactId>spring-webmvc</artifactId> <version>5.2.9.RELEASE</version> </dependency> </dependencies>
3. 移除控制器错误注解
MyController中根路径方法添加了@ResponseBody,会导致ModelAndView被序列化为JSON而非转发到JSP视图,引发404。需删除该注解:
修改后的MyController根路径方法:
@RequestMapping("/") public ModelAndView getInfoForAllEmps(){ ModelAndView modelAndView = new ModelAndView(); modelAndView.setViewName("view_for_all"); return modelAndView; }
验证步骤
- 清理并重新构建项目
- 启动应用,访问根路径会跳转到Spring Security默认登录页面
- 使用配置的账号(如Yehor/1111)登录,即可正常访问对应页面
内容的提问来源于stack exchange,提问作者Yehor But
相关产品推荐
相关产品推荐

