You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot H2控制台登录提示‘Bad credentials’排查求助

H2控制台登录提示“Bad credentials”问题排查

问题描述

访问http://localhost:8080/h2-console时,输入application.properties中配置的用户名sa、密码test,却出现“Bad credentials”错误。以下是我的配置文件,且未编写任何Spring Security相关代码,请问是否配置有误?

application.properties配置

spring.jpa.database-platform=org.hibernate.dialect.H2Dialect
spring.datasource.url=jdbc:h2:mem:testdb
spring.datasource.driverClassName=org.h2.Driver
spring.datasource.username=sa
spring.datasource.password=test
spring.h2.console.enabled=true
spring.h2.console.path=/h2-console
spring.jpa.hibernate.ddl-auto=create-drop
spring.jpa.show-sql=true
logging.level.org.hibernate.SQL=DEBUG
logging.level.org.hibernate.orm.jdbc.bind=trace
spring.jackson.mapper.default-view-inclusion=true

build.gradle配置

plugins {
    id 'java'
    id 'org.springframework.boot' version '3.0.5'
    id 'io.spring.dependency-management' version '1.1.0'
}

group = 'com.example'
version = '0.0.1-SNAPSHOT'
sourceCompatibility = '17'

repositories {
    mavenCentral()
}

dependencies {
    implementation 'org.springframework.boot:spring-boot-starter-cache'
    implementation 'org.springframework.boot:spring-boot-starter-data-jpa'
    implementation 'org.springframework.boot:spring-boot-starter-security'
    implementation 'org.springframework.boot:spring-boot-starter-web'
    developmentOnly 'org.springframework.boot:spring-boot-devtools'
    implementation 'com.h2database:h2'
    testImplementation 'org.springframework.boot:spring-boot-starter-test'
    testImplementation 'org.springframework.security:spring-security-test'
    implementation 'com.google.code.gson:gson:2.8.6'
}

tasks.named('test') {
    useJUnitPlatform()
}

问题原因与解决方案

问题根源在于你的build.gradle中已经引入了Spring Security依赖——哪怕你没写任何自定义安全配置,Spring Security也会自动启用默认规则:

  • 默认生成随机密码,打印在项目启动日志里(格式:Using generated security password: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx)
  • 默认用户名是user,而非你配置的sa

有两种解决方式:

方式一:移除Spring Security依赖(如果不需要安全功能)

直接删掉build.gradle中这两行依赖:

implementation 'org.springframework.boot:spring-boot-starter-security'
testImplementation 'org.springframework.security:spring-security-test'

重新构建项目后,H2控制台就能用你配置的sa和test正常登录。

方式二:配置Spring Security放行H2控制台(如果需要保留安全功能)

添加一个Spring Security配置类,放行H2控制台的请求并允许iframe访问:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.util.matcher.AntPathRequestMatcher;

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            // 禁用CSRF,避免拦截H2控制台的请求
            .csrf(csrf -> csrf.ignoringRequestMatchers(AntPathRequestMatcher.antMatcher("/h2-console/**")))
            // 允许所有访问H2控制台的请求
            .authorizeHttpRequests(auth -> auth
                .requestMatchers(AntPathRequestMatcher.antMatcher("/h2-console/**")).permitAll()
                .anyRequest().authenticated()
            )
            // 允许H2控制台使用iframe
            .headers(headers -> headers.frameOptions(frame -> frame.sameOrigin()));
        return http.build();
    }
}

配置完成后,重启项目即可用sa和test登录H2控制台。

内容的提问来源于stack exchange,提问作者itsmarziparzi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 21:12:28