未认证时Spring Security阻止Bootstrap Webjars加载的问题求助
问题描述
我是Spring Boot新手,正在开发电商Demo项目练习Spring Boot和Thymeleaf。遇到的问题是:未认证状态下,登录页面无法加载Bootstrap CSS文件。
HTML链接标签
<link th:rel="stylesheet" th:href="@{/webjars/bootstrap/4.0.0-2/css/bootstrap.min.css}" />
pom.xml依赖配置
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-validation</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-thymeleaf</artifactId> </dependency> <dependency> <groupId>org.webjars</groupId> <artifactId>bootstrap</artifactId> <version>4.1.2</version> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.liquibase</groupId> <artifactId>liquibase-core</artifactId> </dependency> <dependency> <groupId>org.thymeleaf.extras</groupId> <artifactId>thymeleaf-extras-springsecurity6</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-devtools</artifactId> <scope>runtime</scope> <optional>true</optional> </dependency> <dependency> <groupId>com.mysql</groupId> <artifactId>mysql-connector-j</artifactId> <scope>runtime</scope> </dependency>
Spring Security配置类
@Configuration public class SecurityConfig { //bcrypt bean definition @Bean public BCryptPasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } @Bean public DaoAuthenticationProvider authenticationProvider(UserService userService) { DaoAuthenticationProvider auth = new DaoAuthenticationProvider(); auth.setUserDetailsService(userService); //set the custom user details service auth.setPasswordEncoder(passwordEncoder()); //set the password encoder - bcrypt return auth; } @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http.authorizeHttpRequests(configurer -> configurer.requestMatchers("/register/**", "/css/**", "/js/**", "/webjars/**").permitAll() .anyRequest().authenticated() ) .formLogin(form -> form .loginPage("/showLoginPage") .loginProcessingUrl("/authenticateUser") .permitAll() ) .logout(logout -> logout.permitAll() ) .exceptionHandling(configurer -> configurer.accessDeniedPage("/access-denied") ); return http.build(); } }
问题分析与解决
核心问题
- 版本不匹配:pom.xml中引入的Bootstrap版本是
4.1.2,但HTML中引用的路径版本是4.0.0-2,路径与依赖版本不一致,导致无法定位资源文件。 - 你的Security配置已经正确放开了
/webjars/**的匿名访问权限,这部分写法是Spring Security 6+的正确用法(替代已废弃的authorizeRequests().antMatchers()),无需修改。
修复步骤
- 统一版本路径:把HTML中的引用路径改成和pom.xml一致的版本:
<link th:rel="stylesheet" th:href="@{/webjars/bootstrap/4.1.2/css/bootstrap.min.css}" /> - 可选优化:可以省略路径中的版本号,让WebJars自动匹配依赖版本,避免后续升级时手动修改路径:
<link th:rel="stylesheet" th:href="@{/webjars/bootstrap/css/bootstrap.min.css}" />
验证方法
启动项目后,直接访问http://localhost:8080/webjars/bootstrap/4.1.2/css/bootstrap.min.css(端口根据自己项目调整),如果能正常返回CSS内容,说明资源路径没问题,再刷新登录页面即可。
内容的提问来源于stack exchange,提问作者Youssef ElZawawy
相关产品推荐
相关产品推荐

