Vaadin 14登录页莫名发起/error请求致认证后跳转异常求助
问题分析与解决方案
问题核心
未认证用户访问/application时,Spring Security正确重定向到/login,但Vaadin加载登录页过程中自动发起了/error请求,该请求被Spring Security拦截(要求authenticated),导致自定义请求缓存将/error覆盖了原目标/application,最终用户登录后跳转到状态码999的错误页。
从日志可明确关键节点:
- 初始请求
/application被缓存,重定向到/login /login成功加载后,出现未预期的GET /error请求/error请求因未认证被拦截,缓存被更新为/error,再次重定向到/login
解决方案
1. 放行/error端点的匿名访问
Spring Security默认可能对/error应用了authenticated规则,而Vaadin在生产模式下可能因资源加载触发/error请求。在Security配置中添加规则允许匿名访问:
@Configuration public class SecurityConfig extends VaadinWebSecurity { @Override protected void configure(HttpSecurity http) throws Exception { super.configure(http); http.authorizeHttpRequests(auth -> auth .requestMatchers("/error").permitAll() // 其他授权规则 ); http.requestCache().requestCache(new CustomRequestCache()); } }
2. 修复自定义请求缓存,排除/error请求
当前CustomRequestCache会缓存所有未认证请求,包括意外的/error,修改缓存逻辑跳过该请求:
public class CustomRequestCache extends HttpSessionRequestCache { @Override public void saveRequest(HttpServletRequest request, HttpServletResponse response) { if (!"/error".equals(request.getRequestURI())) { super.saveRequest(request, response); } } }
3. 确保Vaadin内部资源不被拦截
日志显示Vaadin运行在生产模式,需添加Vaadin默认资源放行规则,避免内部请求触发错误:
http.authorizeHttpRequests(auth -> auth .requestMatchers(VaadinWebSecurity.getDefaultHttpSecurityPermitAllMatcher()).permitAll() .requestMatchers("/error").permitAll() .anyRequest().authenticated() );
验证逻辑
修改后,Vaadin触发的/error请求会被允许匿名访问,不会触发重定向和缓存更新,原/application的缓存请求将被保留,用户登录后将正确跳转到目标页面。
内容的提问来源于stack exchange,提问作者Stimpson Cat
相关产品推荐
相关产品推荐

