You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot(Spring 3.1.3)Spring Security过滤器配置及视图问题求助

Spring Boot Security配置问题排查

问题背景

已在Spring Boot项目的build.gradle中引入Security依赖:

implementation 'org.springframework.boot:spring-boot-starter-security'

当前SpringSecurityConfig配置类:

@Configuration
@EnableWebSecurity
@EnableWebMvc
public class SpringSecurityConfig {
    //Authentication
    @Bean
    public UserDetailsService userDetailsService(PasswordEncoder passwordEncoder){
        UserDetails admin = User.withUsername("admin").password(passwordEncoder.encode("admin")).roles("ADMIN").build();
        UserDetails user = User.withUsername("user").password(passwordEncoder.encode("user")).roles("USER").build();
        return new InMemoryUserDetailsManager(admin, user);
    }


    @Bean
    public PasswordEncoder passwordEncoder(){
        return new BCryptPasswordEncoder();
    }

}

遇到的问题

  1. 配置过滤器时收到提示:

"This method cannot decide whether these patterns are Spring MVC patterns or not. If this endpoint is a Spring MVC endpoint, please use requestMatchers(MvcRequestMatcher); otherwise, please use requestMatchers(AntPathRequestMatcher)."

  1. 尝试使用MvcRequestMatcher配置SecurityFilterChain后,访问/、/home或/signup时抛出错误:
jakarta.servlet.ServletException: Could not resolve view with name 'home' in servlet with name 'dispatcherServlet'

最新尝试的SecurityFilterChain代码:

@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http, HandlerMappingIntrospector introspector) throws Exception {
    MvcRequestMatcher.Builder mvcMatcherBuilder = new MvcRequestMatcher.Builder(introspector);
    http.authorizeHttpRequests((requests) -> requests
            .requestMatchers(mvcMatcherBuilder.pattern("/"), mvcMatcherBuilder.pattern("/home"), mvcMatcherBuilder.pattern("/signup")).permitAll()
            .anyRequest().authenticated()
    );
    return http.build();
}

项目环境

  • 未使用Thymeleaf,仅用JSP
  • 完整build.gradle依赖:
dependencies {
    implementation 'org.springframework.boot:spring-boot-starter-actuator'
    implementation 'org.springframework.boot:spring-boot-starter-web'
    implementation 'org.springframework.boot:spring-boot-starter-security'
    implementation 'org.apache.tomcat.embed:tomcat-embed-jasper'
    implementation 'org.webjars:jquery:3.6.0'
    implementation 'org.webjars:bootstrap:5.3.1'
    implementation 'org.webjars:bootstrap-datepicker:1.0.1'
    implementation 'org.webjars:font-awesome:5.15.4'
    implementation 'org.springframework.boot:spring-boot-starter-data-mongodb'
    testImplementation 'org.springframework.boot:spring-boot-starter-test'
}

异常现象

  • 移除Spring Security依赖及配置类后,应用可正常访问
  • 未添加自定义SecurityFilterChain时,访问localhost:8080会跳转至默认登录页,登录后可正常访问根页面

解决方案

1. 配置JSP视图解析器

由于使用JSP作为视图,需在application.properties中添加视图解析配置,确保Spring能定位到JSP文件:

# JSP视图路径配置
spring.mvc.view.prefix=/WEB-INF/views/
spring.mvc.view.suffix=.jsp

同时确保JSP文件放置在src/main/webapp/WEB-INF/views/目录下,比如home.jsp、signup.jsp都需存放在此路径。

2. 优化SecurityFilterChain配置

简化MvcRequestMatcher使用,同时放行静态资源(如webjars),保留默认登录/登出逻辑:

@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http, HandlerMappingIntrospector introspector) throws Exception {
    MvcRequestMatcher.Builder mvcMatcher = new MvcRequestMatcher.Builder(introspector);
    
    http.authorizeHttpRequests(auth -> auth
            // 放行指定页面
            .requestMatchers(mvcMatcher.pattern("/"), mvcMatcher.pattern("/home"), mvcMatcher.pattern("/signup")).permitAll()
            // 放行webjars静态资源
            .requestMatchers("/webjars/**").permitAll()
            // 其余请求需认证
            .anyRequest().authenticated()
        )
        // 启用默认登录页并放行
        .formLogin(form -> form.permitAll())
        // 放行登出请求
        .logout(logout -> logout.permitAll());
    
    return http.build();
}

3. 移除不必要的注解

从SpringSecurityConfig中移除@EnableWebMvc注解,该注解会覆盖Spring Boot的默认Web配置,可能干扰视图解析和资源映射逻辑。


验证步骤

  1. 确认视图解析配置和JSP文件路径正确
  2. 调整SecurityFilterChain配置后重启应用
  3. 访问/home应直接加载对应JSP页面;访问其他路径会跳转至默认登录页,登录后可正常访问受保护资源

内容的提问来源于stack exchange,提问作者Igor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 15:42:06