Spring Boot 3.0.2登录后自动添加continue请求参数问题咨询
Spring Boot 3.0.2登录URL自动添加
continue参数的解决方案 问题原因
Spring Boot 3.x基于Spring Security 6.0,该版本对表单登录的默认跳转逻辑做了调整:当用户访问需要认证的受保护资源时,框架会自动在登录URL后追加continue查询参数,用于记录用户原本请求的地址,方便登录成功后自动跳转。这个行为是框架默认实现,和你自定义的AuthenticationSuccessHandler无关。
解决方案
1. 完全禁用continue参数生成
在SecurityFilterChain配置中,自定义认证入口点(authenticationEntryPoint),跳过框架默认的参数追加逻辑,直接跳转到登录页:
@Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth .anyRequest().authenticated() ) .formLogin(form -> form .loginPage("/login") // 你的自定义登录页路径 .successHandler(yourCustomSuccessHandler) // 你已实现的成功处理器 .authenticationEntryPoint((request, response, authException) -> { // 直接跳转登录页,不追加continue参数 response.sendRedirect("/login"); }) ); return http.build(); }
2. 保留跳转逻辑但修改参数名(可选)
如果需要保留登录后跳转原地址的功能,但不想用continue作为参数名,可以通过自定义RequestCache来修改:
@Bean public RequestCache requestCache() { HttpSessionRequestCache requestCache = new HttpSessionRequestCache(); requestCache.setMatchingRequestParameterName("your-custom-param"); // 替换为你想要的参数名 return requestCache; } // 在SecurityFilterChain中配置 @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .requestCache(cache -> cache.requestCache(requestCache())) // 其他配置... .formLogin(form -> form .successHandler(yourCustomSuccessHandler) ); return http.build(); }
3. 自定义成功处理器时忽略参数
如果只是不想在跳转时携带continue参数,可在自定义的AuthenticationSuccessHandler的onAuthenticationSuccess方法中,直接指定固定跳转路径,忽略原请求的参数:
@Override public void onAuthenticationSuccess(HttpServletRequest request, HttpServletResponse response, Authentication authentication) throws IOException, ServletException { // 直接跳转到首页或指定页面,不使用带continue参数的地址 response.sendRedirect("/dashboard"); }
内容的提问来源于stack exchange,提问作者Karol Majewski
相关产品推荐
相关产品推荐

