Spring SecurityFilterChain致空白页面,请求排查配置错误
Spring Security OAuth2客户端配置异常排查
项目结构
- pom.xml
- src/main/java/oa/tests/securitytest/SecurityTest.java
- src/main/java/oa/tests/securitytest/SecurityConfig.java
- src/main/resources/application.properties
- src/main/resources/static/index.html
- src/main/resources/static/test.html
异常现象
- 未定义SecurityFilterChain Bean时:所有页面均需认证,认证后可正常访问;
- 配置SecurityFilterChain Bean后:index.html无需认证即可访问,但test.html显示空白页面且无登录跳转。
排查说明
已尝试更换application.properties中的OAuth2服务器配置(GitHub/Google),问题仍存在,确定错误出在SecurityFilterChain Bean配置中。
pom.xml
<?xml version="1.0" encoding="UTF-8"?> <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>3.1.5</version> <relativePath/> <!-- lookup parent from repository --> </parent> <groupId>oa.tests</groupId> <artifactId>securitytest</artifactId> <version>1.0</version> <name>securitytest</name> <description>Test for Spring security</description> <properties> <java.version>21</java.version> <spring.boot.mainclass>oa.tests.securitytest.SecurityTest</spring.boot.mainclass> </properties> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-client</artifactId> </dependency> </dependencies> <build> <plugins> <plugin> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-maven-plugin</artifactId> <configuration> <image> <builder>paketobuildpacks/builder-jammy-base:latest</builder> </image> </configuration> </plugin> </plugins> </build> </project>
SecurityTest.java
package oa.tests.securitytest; import org.springframework.boot.SpringApplication; import org.springframework.boot.autoconfigure.SpringBootApplication; @SpringBootApplication public class SecurityTest { public static void main(String[] args) { SpringApplication.run(SecurityTest.class, args); } }
SecurityConfig.java(原配置)
package oa.tests.securitytest; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.http.HttpStatus; import static org.springframework.security.config.Customizer.withDefaults; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.authentication.HttpStatusEntryPoint; @Configuration @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(a -> a .requestMatchers("/index.html", "/error").permitAll() .anyRequest().authenticated() ) .logout(l -> l .logoutSuccessUrl("/").permitAll() ) .exceptionHandling(e -> e .authenticationEntryPoint(new HttpStatusEntryPoint(HttpStatus.UNAUTHORIZED)) ) .oauth2Login(withDefaults()); return http.build(); } }
application.properties
spring.security.oauth2.client.registration.github.clientId=4e5e66b02640eeb2XXX spring.security.oauth2.client.registration.github.clientSecret=acefbb827cf0c635d1331e122ba912XXXXXXXXXX
问题分析
原配置中exceptionHandling里的HttpStatusEntryPoint(HttpStatus.UNAUTHORIZED)是核心问题:
- 这个EntryPoint会在用户未认证时直接返回401 Unauthorized状态码,而非触发OAuth2的登录跳转流程;
- 当访问需要认证的
test.html时,浏览器收到401响应但没有页面内容,因此显示空白; - 用户误以为无需认证,实际上请求已被拦截,只是没有跳转到登录页面。
解决方案
移除自定义的authenticationEntryPoint,让Spring Security OAuth2的默认逻辑处理未认证请求(自动跳转到第三方登录页面)。修改后的SecurityConfig如下:
package oa.tests.securitytest; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import static org.springframework.security.config.Customizer.withDefaults; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.web.SecurityFilterChain; @Configuration @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(a -> a .requestMatchers("/index.html", "/error").permitAll() .anyRequest().authenticated() ) .logout(l -> l .logoutSuccessUrl("/").permitAll() ) .oauth2Login(withDefaults()); return http.build(); } }
修改后,访问test.html时会自动跳转到GitHub/Google登录页面,认证通过后即可正常访问页面。
内容的提问来源于stack exchange,提问作者Nestor Arias
相关产品推荐
相关产品推荐

