You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 6+下Vaadin因Security配置HTML生成401禁止问题求助

Spring Security + Vaadin 权限配置适配方案(Spring Boot 6+)

你的问题核心是Spring Security拦截了Vaadin渲染页面所需的内部资源请求,导致/login页面的HTML元素加载失败返回401。除了直接放行/login路径,还必须放行Vaadin运行时依赖的各类静态资源与内部接口,才能保证登录页正常渲染。

以下是适配Spring Boot 6+的完整配置代码:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            // 禁用Spring Security CSRF,Vaadin自带CSRF防护机制,避免冲突
            .csrf(csrf -> csrf.disable())
            .authorizeHttpRequests(auth -> auth
                // 放行登录页及所有Vaadin核心资源
                .requestMatchers(
                    "/login",
                    "/VAADIN/**",
                    "/frontend/**",
                    "/webjars/**",
                    "/icons/**",
                    "/manifest.json",
                    "/sw.js",
                    "/offline-page.html"
                ).permitAll()
                // 根路径及其他所有请求必须经过认证
                .anyRequest().authenticated()
            )
            // 指定登录页路径,允许所有用户访问
            .formLogin(form -> form
                .loginPage("/login")
                .permitAll()
            )
            // 配置注销逻辑,允许所有用户执行注销
            .logout(logout -> logout
                .permitAll()
            );

        return http.build();
    }
}

关键配置说明:

  • Vaadin资源放行:/VAADIN/**、/frontend/**等路径是Vaadin渲染页面、加载前端组件与静态资源的核心路径,必须放行,否则登录页的HTML元素会因资源请求被拦截而无法正常生成。
  • CSRF禁用:Vaadin框架内置了CSRF防护机制,与Spring Security的CSRF规则会产生冲突,因此需要禁用Spring Security的CSRF配置。
  • 登录页配置:通过formLogin().loginPage("/login")指定登录入口,确保未认证用户可以直接访问登录视图。

额外注意事项:

  1. 确保你的Vaadin登录视图使用@Route("login")注解,保证路由路径与配置中的/login匹配。
  2. 测试前清空浏览器缓存,避免旧资源缓存导致的加载异常。
  3. 若使用自定义Vaadin主题,需将主题对应的资源路径也加入requestMatchers的放行列表中。

内容的提问来源于stack exchange,提问作者AleXeNoN

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 21:53:17