You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Vaadin 14登录页莫名发起/error请求致认证后跳转异常求助

问题分析与解决方案

问题核心

未认证用户访问/application时,Spring Security正确重定向到/login,但Vaadin加载登录页过程中自动发起了/error请求,该请求被Spring Security拦截(要求authenticated),导致自定义请求缓存将/error覆盖了原目标/application,最终用户登录后跳转到状态码999的错误页。

从日志可明确关键节点:

  1. 初始请求/application被缓存,重定向到/login
  2. /login成功加载后,出现未预期的GET /error请求
  3. /error请求因未认证被拦截,缓存被更新为/error,再次重定向到/login

解决方案

1. 放行/error端点的匿名访问

Spring Security默认可能对/error应用了authenticated规则,而Vaadin在生产模式下可能因资源加载触发/error请求。在Security配置中添加规则允许匿名访问:

@Configuration
public class SecurityConfig extends VaadinWebSecurity {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        super.configure(http);
        http.authorizeHttpRequests(auth -> auth
                .requestMatchers("/error").permitAll()
                // 其他授权规则
        );
        http.requestCache().requestCache(new CustomRequestCache());
    }
}

2. 修复自定义请求缓存,排除/error请求

当前CustomRequestCache会缓存所有未认证请求,包括意外的/error,修改缓存逻辑跳过该请求:

public class CustomRequestCache extends HttpSessionRequestCache {
    @Override
    public void saveRequest(HttpServletRequest request, HttpServletResponse response) {
        if (!"/error".equals(request.getRequestURI())) {
            super.saveRequest(request, response);
        }
    }
}

3. 确保Vaadin内部资源不被拦截

日志显示Vaadin运行在生产模式,需添加Vaadin默认资源放行规则,避免内部请求触发错误:

http.authorizeHttpRequests(auth -> auth
        .requestMatchers(VaadinWebSecurity.getDefaultHttpSecurityPermitAllMatcher()).permitAll()
        .requestMatchers("/error").permitAll()
        .anyRequest().authenticated()
);

验证逻辑

修改后,Vaadin触发的/error请求会被允许匿名访问,不会触发重定向和缓存更新,原/application的缓存请求将被保留,用户登录后将正确跳转到目标页面。

内容的提问来源于stack exchange,提问作者Stimpson Cat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 17:34:56