Spring Boot H2控制台登录提示‘Bad credentials’排查求助
H2控制台登录提示“Bad credentials”问题排查
问题描述
访问http://localhost:8080/h2-console时,输入application.properties中配置的用户名sa、密码test,却出现“Bad credentials”错误。以下是我的配置文件,且未编写任何Spring Security相关代码,请问是否配置有误?
application.properties配置
spring.jpa.database-platform=org.hibernate.dialect.H2Dialect spring.datasource.url=jdbc:h2:mem:testdb spring.datasource.driverClassName=org.h2.Driver spring.datasource.username=sa spring.datasource.password=test spring.h2.console.enabled=true spring.h2.console.path=/h2-console spring.jpa.hibernate.ddl-auto=create-drop spring.jpa.show-sql=true logging.level.org.hibernate.SQL=DEBUG logging.level.org.hibernate.orm.jdbc.bind=trace spring.jackson.mapper.default-view-inclusion=true
build.gradle配置
plugins { id 'java' id 'org.springframework.boot' version '3.0.5' id 'io.spring.dependency-management' version '1.1.0' } group = 'com.example' version = '0.0.1-SNAPSHOT' sourceCompatibility = '17' repositories { mavenCentral() } dependencies { implementation 'org.springframework.boot:spring-boot-starter-cache' implementation 'org.springframework.boot:spring-boot-starter-data-jpa' implementation 'org.springframework.boot:spring-boot-starter-security' implementation 'org.springframework.boot:spring-boot-starter-web' developmentOnly 'org.springframework.boot:spring-boot-devtools' implementation 'com.h2database:h2' testImplementation 'org.springframework.boot:spring-boot-starter-test' testImplementation 'org.springframework.security:spring-security-test' implementation 'com.google.code.gson:gson:2.8.6' } tasks.named('test') { useJUnitPlatform() }
问题原因与解决方案
问题根源在于你的build.gradle中已经引入了Spring Security依赖——哪怕你没写任何自定义安全配置,Spring Security也会自动启用默认规则:
- 默认生成随机密码,打印在项目启动日志里(格式:
Using generated security password: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx) - 默认用户名是
user,而非你配置的sa
有两种解决方式:
方式一:移除Spring Security依赖(如果不需要安全功能)
直接删掉build.gradle中这两行依赖:
implementation 'org.springframework.boot:spring-boot-starter-security' testImplementation 'org.springframework.security:spring-security-test'
重新构建项目后,H2控制台就能用你配置的sa和test正常登录。
方式二:配置Spring Security放行H2控制台(如果需要保留安全功能)
添加一个Spring Security配置类,放行H2控制台的请求并允许iframe访问:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.util.matcher.AntPathRequestMatcher; @Configuration @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http // 禁用CSRF,避免拦截H2控制台的请求 .csrf(csrf -> csrf.ignoringRequestMatchers(AntPathRequestMatcher.antMatcher("/h2-console/**"))) // 允许所有访问H2控制台的请求 .authorizeHttpRequests(auth -> auth .requestMatchers(AntPathRequestMatcher.antMatcher("/h2-console/**")).permitAll() .anyRequest().authenticated() ) // 允许H2控制台使用iframe .headers(headers -> headers.frameOptions(frame -> frame.sameOrigin())); return http.build(); } }
配置完成后,重启项目即可用sa和test登录H2控制台。
内容的提问来源于stack exchange,提问作者itsmarziparzi
相关产品推荐
相关产品推荐

