如何同时启用Thymeleaf输入字段(th:field)并设置值(th:value)?将${#authentication.name}存入数据库*{pres}位置是否可行?
Hey there! Let's walk through your two Thymeleaf questions and share a working solution I used for a similar scenario (for other devs who might hit this same roadblock):
th:field and th:value together in Thymeleaf Here's the key: Thymeleaf's th:field is built to bind directly to a property in your form-backing object (the one you link with th:object). It automatically sets the input's value based on that object's property, so using th:value alongside it can cause conflicts because th:field takes priority.
The cleanest approach is to populate the initial value in your backend controller before passing the object to the view. For example:
// In your Spring controller @GetMapping("/your-form") public String showForm(Model model) { YourFormDto formDto = new YourFormDto(); formDto.setTargetField("Your desired initial value"); // Set the value here model.addAttribute("formDto", formDto); return "your-form-template"; }
Then in your Thymeleaf template:
<form th:object="${formDto}" method="post"> <input type="text" th:field="*{targetField}" /> </form>
If you must set the value directly in the template (instead of the backend), you can use th:attr to override the value—though this is less ideal for maintainability:
<input type="text" th:field="*{targetField}" th:attr="value='Template-side initial value'" />
${#authentication.name} into a field and saving to pres in the database Absolutely, this is totally doable! Here are two solid approaches:
Option 1: Backend-driven (Recommended)
Fetch the authenticated user's name in your controller, assign it to the pres property of your entity/form object, then bind it via th:field in the template. This keeps auth logic in the backend (safer, since frontend values can be tampered with):
// Controller code import org.springframework.security.core.context.SecurityContextHolder; @GetMapping("/pres-form") public String showPresForm(Model model) { YourEntity entity = new YourEntity(); // Grab the authenticated username String currentUser = SecurityContextHolder.getContext().getAuthentication().getName(); entity.setPres(currentUser); // Assign to the `pres` field model.addAttribute("entity", entity); return "pres-form-template"; } @PostMapping("/pres-form") public String submitPresForm(@ModelAttribute YourEntity entity) { // Save the entity—your database's `pres` column will get the username yourEntityRepository.save(entity); return "success-page"; }
Template code:
<form th:object="${entity}" th:action="@{/pres-form}" method="post"> <!-- Auto-populates with the username from the backend --> <input type="text" th:field="*{pres}" readonly /> <!-- Add readonly if users shouldn't edit this --> <button type="submit">Save</button> </form>
Option 2: Template-driven
If you want to set the value directly in the Thymeleaf template, combine th:field with th:attr to inject the authenticated username:
<form th:object="${entity}" th:action="@{/pres-form}" method="post"> <input type="text" th:field="*{pres}" th:attr="value=${#authentication.name}" /> <button type="submit">Save</button> </form>
Just keep in mind: if your backend entity's pres property already has a value, th:field will use that instead of the template-set value.
My Working Solution for This Exact Scenario
Since I dealt with this same requirement recently, here's the structure that worked perfectly for me—balancing visibility for users and security for submission:
<form th:object="${document}" th:action="@{/save-document}" method="post"> <!-- Visible read-only field so users see the username --> <input type="text" th:value="${#authentication.name}" readonly class="form-control mb-3" /> <!-- Hidden field bound to `pres` to pass the value on submission --> <input type="hidden" th:field="*{pres}" th:value="${#authentication.name}" /> <!-- Other form fields --> <textarea th:field="*{content}" class="form-control mb-3"></textarea> <button type="submit" class="btn btn-primary">Save Document</button> </form>
Pro tip: Even with the hidden field, I added a validation step in the backend to confirm the submitted pres value matches the authenticated user's name—always good to guard against frontend tampering!
内容的提问来源于stack exchange,提问作者isfa afreen

