You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

添加Spring Security配置后应用出现404错误求助

解决Spring MVC集成Spring Security后404错误问题

问题描述

添加SecurityConfig和SecurityInitializer类后,Spring MVC应用出现404 Not Found错误,移除这两个类后应用可正常运行,调整依赖版本无法解决问题。

解决方案

1. 完善Spring Security授权配置

原SecurityConfig仅配置了内存认证规则,但未定义请求授权逻辑,Spring Security默认拦截所有请求且未正确转发到控制器。需添加HttpSecurity配置,明确各路径的访问权限并启用表单登录:

修改后的SecurityConfig:

package basic;

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
import org.springframework.security.core.userdetails.User;

@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        User.UserBuilder userBuilder = User.withDefaultPasswordEncoder();
        auth.inMemoryAuthentication()
            .withUser(userBuilder.username("Yehor").password("1111").roles("EMPLOYEE"))
            .withUser(userBuilder.username("Maria").password("2222").roles("HR"))
            .withUser(userBuilder.username("Yan").password("3333").roles("MANAGER", "HR"));
    }

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.authorizeRequests()
            .antMatchers("/").hasRole("EMPLOYEE")
            .antMatchers("/hr-info").hasRole("HR")
            .antMatchers("/manager-info").hasAnyRole("MANAGER", "HR")
            .and()
            .formLogin().permitAll();
    }
}

2. 解决Servlet依赖冲突

pom.xml中同时引入Jakarta Servlet API(6.0.0)和javax Servlet API(4.0.1),二者存在包冲突(Spring Security 5.x基于javax.servlet,不兼容Jakarta EE 9+)。需移除Jakarta相关依赖:

修改后的pom.xml依赖部分:

<dependencies>
    <dependency>
      <groupId>junit</groupId>
      <artifactId>junit</artifactId>
      <version>3.8.1</version>
      <scope>test</scope>
    </dependency>

    <dependency>
      <groupId>javax.servlet</groupId>
      <artifactId>javax.servlet-api</artifactId>
      <version>4.0.1</version>
      <scope>provided</scope>
    </dependency>

    <dependency>
      <groupId>org.springframework.security</groupId>
      <artifactId>spring-security-web</artifactId>
      <version>5.4.1</version>
    </dependency>
    <dependency>
      <groupId>org.springframework.security</groupId>
      <artifactId>spring-security-config</artifactId>
      <version>5.4.1</version>
    </dependency>

    <!-- Spring Web MVC -->
    <dependency>
      <groupId>org.springframework</groupId>
      <artifactId>spring-webmvc</artifactId>
      <version>5.2.9.RELEASE</version>
    </dependency>
</dependencies>

3. 移除控制器错误注解

MyController中根路径方法添加了@ResponseBody,会导致ModelAndView被序列化为JSON而非转发到JSP视图,引发404。需删除该注解:

修改后的MyController根路径方法:

@RequestMapping("/")
public ModelAndView getInfoForAllEmps(){
    ModelAndView modelAndView = new ModelAndView();
    modelAndView.setViewName("view_for_all");
    return modelAndView;
}

验证步骤

  1. 清理并重新构建项目
  2. 启动应用,访问根路径会跳转到Spring Security默认登录页面
  3. 使用配置的账号(如Yehor/1111)登录,即可正常访问对应页面

内容的提问来源于stack exchange,提问作者Yehor But

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 00:22:48