You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置安全的Micronaut应用中JS/CSS文件返回403错误求助

Micronaut 3.8.9静态资源JS/CSS访问403问题解决

问题背景

使用Micronaut 3.8.9开发的应用包含REST API、前端静态资源(JS/CSS)、HTML视图及会话认证授权功能,应用运行正常,但访问/static/index.js和/static/index.css时返回403 Forbidden错误。

目录结构:

src/main/resources
  /static
    index.js
    index.css
  /views
    index.html

现有application.yml配置:

micronaut:
  application:
    name: micronautguide
  
  security:
    authentication: session
    redirect:
      login-success: /app/home
      login-failure: /login/authFailed
  
  router:
    static-resources:
      default:
        enabled: true
        mapping: [/static/**, /views/**]
        paths: [classpath:static, classpath:views]

尝试过的无效操作:

  • 在HTML中使用../static/index.js或Thymeleaf的@{./index.js}引用资源
  • 添加空的@Controller("/static")并标注@PermitAll、@Secured(SecurityRule.IS_ANONYMOUS)

日志关键输出:

10:01:03.183 DEBUG InterceptUrlMapRule.check:105 - No url map pattern match found for path [/static/index.js]. Returning unknown.
10:01:03.183 DEBUG SecurityFilter.lambda$checkRules$8:187 - Authorized request GET /static/index.js. No rule provider authorized or rejected the request.
10:01:03.187 DEBUG RoutingInBoundHandler.syncWriteAndFlushNettyResponse:1323 - Response 403 - GET /static/index.js

解决方案

1. 配置安全规则,明确允许匿名访问静态资源

在application.yml的micronaut.security节点下添加intercept-url-map,指定静态资源路径无需认证:

micronaut:
  # 保留原有配置...
  security:
    authentication: session
    redirect:
      login-success: /app/home
      login-failure: /login/authFailed
    # 新增安全规则配置
    intercept-url-map:
      - pattern: /static/**
        access:
          - isAnonymous()
      - pattern: /login/**
        access:
          - isAnonymous()
      # 按需配置需要认证的路径,比如业务接口
      - pattern: /app/**
        access:
          - isAuthenticated()

2. 优化静态资源路由配置

移除/views/**的静态资源映射(Thymeleaf视图由模板引擎处理,无需作为静态资源暴露):

micronaut:
  # 保留原有配置...
  router:
    static-resources:
      default:
        enabled: true
        mapping: /static/**
        paths: classpath:static

3. 修正HTML中静态资源的引用路径

使用Thymeleaf的绝对路径语法,确保资源引用正确:

<script type="module" th:src="@{/static/index.js}"></script>
<link rel="stylesheet" th:href="@{/static/index.css}" />

4. 移除无效的空控制器

直接删除之前添加的空JSCSSController,静态资源路由已能处理路径映射,空控制器无实际作用。

验证

重启应用后,直接访问http://localhost:8080/static/index.js应能正常返回文件内容,HTML页面也可正确加载JS和CSS资源。

内容的提问来源于stack exchange,提问作者Lucas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 23:03:23