You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 3集成Spring Boot Admin后登录异常重定向求助

Spring Boot Admin 登录异常(401重定向/跳转到CSS文件)修复方案

问题背景

使用Spring Boot 3.0.0 + Spring Boot Admin 3.0.0-M6集成安全认证后,登录时出现两种异常:

  • 输入账号密码后重定向回登录页,提示Login required to access the resource (Error: 401).
  • 直接跳转到variables.css文件
    禁用Spring Security后所有功能恢复正常。

修复方案

1. 修正Security配置类

核心问题是静态资源放行不全,以及登录跳转逻辑优化:

@Configuration(proxyBeanMethods = false)
@EnableWebSecurity
@AllArgsConstructor
public class AdminSecurityConfig {
    private final AdminServerProperties adminServerProperties;
    private final SecurityProperties securityProperties;
    private final AuthenticationConfiguration authenticationConfiguration;

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        SavedRequestAwareAuthenticationSuccessHandler successHandler = new SavedRequestAwareAuthenticationSuccessHandler();
        successHandler.setTargetUrlParameter("redirectTo");
        successHandler.setDefaultTargetUrl(this.adminServerProperties.path("/"));
        successHandler.setAlwaysUseDefaultTargetUrl(false); // 避免强制跳转默认页

        http
                .authorizeHttpRequests(authorizeRequests ->
                        authorizeRequests
                                // 放行所有SBA UI静态资源
                                .requestMatchers(this.adminServerProperties.path("/assets/**")).permitAll()
                                .requestMatchers(this.adminServerProperties.path("/js/**")).permitAll()
                                .requestMatchers(this.adminServerProperties.path("/*.css")).permitAll()
                                .requestMatchers(this.adminServerProperties.path("/*.js")).permitAll()
                                .requestMatchers(this.adminServerProperties.path("/favicon.ico")).permitAll()
                                .requestMatchers(this.adminServerProperties.path("/webjars/**")).permitAll()
                                // 放行健康检查与登录页
                                .requestMatchers(this.adminServerProperties.path("/actuator/info")).permitAll()
                                .requestMatchers(this.adminServerProperties.path("/actuator/health")).permitAll()
                                .requestMatchers(this.adminServerProperties.path("/login")).permitAll()
                                .anyRequest().authenticated()
                )
                .formLogin(formLogin ->
                        formLogin
                                .loginPage(this.adminServerProperties.path("/login"))
                                .successHandler(successHandler)
                )
                .logout(logout ->
                        logout.logoutUrl(this.adminServerProperties.path("/logout"))
                                .logoutSuccessUrl(this.adminServerProperties.path("/login"))
                )
                .httpBasic(Customizer.withDefaults())
                .csrf(csrf ->
                        csrf.csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse())
                                .ignoringRequestMatchers(
                                        new AntPathRequestMatcher(this.adminServerProperties.path("/instances"), HttpMethod.POST.name()),
                                        new AntPathRequestMatcher(this.adminServerProperties.path("/instances/*"), HttpMethod.DELETE.name()),
                                        new AntPathRequestMatcher(this.adminServerProperties.path("/actuator/**"))
                                )
                );
        return http.build();
    }

    @Bean
    public AuthenticationManager authenticationManager() throws Exception {
        return authenticationConfiguration.getAuthenticationManager();
    }

    @Bean
    public UserDetailsService userDetailsService() {
        UserDetails user = User.withUsername(securityProperties.getUser().getName())
                .password("{noop}" + securityProperties.getUser().getPassword())
                .roles("USER")
                .build();
        return new InMemoryUserDetailsManager(user);
    }
}

2. 修正application.yaml配置

原配置存在缩进错误,boot节点需归属于spring节点:

spring:
  security:
    user:
      name: admin
      password: admin
      roles:
        - USER
  boot:
    admin:
      monitor:
        status-interval: 30000
        status-lifetime: 30000
      ui:
        title: "Invoice Matching Admin"
        remember-me-enabled: false

3. 版本兼容性验证

Spring Boot Admin 3.0.0-M6是适配Spring Boot 3的预览版本,若问题仍存在,建议升级到Spring Boot Admin正式版(如3.0.0及以上),确保与Spring Boot 3.0.0完全兼容。

问题原因说明

  • 静态资源放行不全:Spring Boot Admin 3.x UI依赖/js、/webjars等目录下的资源,未放行会导致这些请求被拦截,触发登录流程,干扰页面跳转逻辑,出现跳转到CSS文件的异常。
  • 配置文件缩进错误:原配置中boot节点未归属于spring,导致AdminServerProperties无法正确读取路径配置,引发权限匹配异常。
  • 登录跳转逻辑优化:添加alwaysUseDefaultTargetUrl(false)确保仅在无redirectTo参数时跳转到首页,避免强制跳转导致的异常。

内容的提问来源于stack exchange,提问作者Mike

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 20:43:53