You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

未认证时Spring Security阻止Bootstrap Webjars加载的问题求助

问题描述

我是Spring Boot新手,正在开发电商Demo项目练习Spring Boot和Thymeleaf。遇到的问题是:未认证状态下,登录页面无法加载Bootstrap CSS文件。


HTML链接标签

<link th:rel="stylesheet" th:href="@{/webjars/bootstrap/4.0.0-2/css/bootstrap.min.css}" />

pom.xml依赖配置

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-validation</artifactId>
</dependency>

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-thymeleaf</artifactId>
</dependency>
<dependency>
    <groupId>org.webjars</groupId>
    <artifactId>bootstrap</artifactId>
    <version>4.1.2</version>
</dependency>
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-web</artifactId>
</dependency>
<dependency>
    <groupId>org.liquibase</groupId>
    <artifactId>liquibase-core</artifactId>
</dependency>
<dependency>
    <groupId>org.thymeleaf.extras</groupId>
    <artifactId>thymeleaf-extras-springsecurity6</artifactId>
</dependency>

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-devtools</artifactId>
    <scope>runtime</scope>
    <optional>true</optional>
</dependency>
<dependency>
    <groupId>com.mysql</groupId>
    <artifactId>mysql-connector-j</artifactId>
    <scope>runtime</scope> 
</dependency> 

Spring Security配置类

@Configuration
public class SecurityConfig {
    //bcrypt bean definition
    @Bean
    public BCryptPasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }

    @Bean
    public DaoAuthenticationProvider authenticationProvider(UserService userService) {
        DaoAuthenticationProvider auth = new DaoAuthenticationProvider();
        auth.setUserDetailsService(userService); //set the custom user details service
        auth.setPasswordEncoder(passwordEncoder()); //set the password encoder - bcrypt
        return auth;
    }

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {

        http.authorizeHttpRequests(configurer ->
                        configurer.requestMatchers("/register/**",
                                               "/css/**",
                                               "/js/**",
                                               "/webjars/**").permitAll()
                                .anyRequest().authenticated()
                )
                .formLogin(form ->
                        form
                                .loginPage("/showLoginPage")
                                .loginProcessingUrl("/authenticateUser")
                                .permitAll()
                )
                .logout(logout -> logout.permitAll()
                )
                .exceptionHandling(configurer ->
                        configurer.accessDeniedPage("/access-denied")
                );

        return http.build();
    }
}

问题分析与解决

核心问题

  1. 版本不匹配:pom.xml中引入的Bootstrap版本是4.1.2,但HTML中引用的路径版本是4.0.0-2,路径与依赖版本不一致,导致无法定位资源文件。
  2. 你的Security配置已经正确放开了/webjars/**的匿名访问权限,这部分写法是Spring Security 6+的正确用法(替代已废弃的authorizeRequests().antMatchers()),无需修改。

修复步骤

  • 统一版本路径:把HTML中的引用路径改成和pom.xml一致的版本:
    <link th:rel="stylesheet" th:href="@{/webjars/bootstrap/4.1.2/css/bootstrap.min.css}" />
    
  • 可选优化:可以省略路径中的版本号,让WebJars自动匹配依赖版本,避免后续升级时手动修改路径:
    <link th:rel="stylesheet" th:href="@{/webjars/bootstrap/css/bootstrap.min.css}" />
    

验证方法

启动项目后,直接访问http://localhost:8080/webjars/bootstrap/4.1.2/css/bootstrap.min.css(端口根据自己项目调整),如果能正常返回CSS内容,说明资源路径没问题,再刷新登录页面即可。


内容的提问来源于stack exchange,提问作者Youssef ElZawawy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 23:45:38