Spring Boot 3集成Spring Boot Admin后登录异常重定向求助
Spring Boot Admin 登录异常(401重定向/跳转到CSS文件)修复方案
问题背景
使用Spring Boot 3.0.0 + Spring Boot Admin 3.0.0-M6集成安全认证后,登录时出现两种异常:
- 输入账号密码后重定向回登录页,提示
Login required to access the resource (Error: 401). - 直接跳转到
variables.css文件
禁用Spring Security后所有功能恢复正常。
修复方案
1. 修正Security配置类
核心问题是静态资源放行不全,以及登录跳转逻辑优化:
@Configuration(proxyBeanMethods = false) @EnableWebSecurity @AllArgsConstructor public class AdminSecurityConfig { private final AdminServerProperties adminServerProperties; private final SecurityProperties securityProperties; private final AuthenticationConfiguration authenticationConfiguration; @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { SavedRequestAwareAuthenticationSuccessHandler successHandler = new SavedRequestAwareAuthenticationSuccessHandler(); successHandler.setTargetUrlParameter("redirectTo"); successHandler.setDefaultTargetUrl(this.adminServerProperties.path("/")); successHandler.setAlwaysUseDefaultTargetUrl(false); // 避免强制跳转默认页 http .authorizeHttpRequests(authorizeRequests -> authorizeRequests // 放行所有SBA UI静态资源 .requestMatchers(this.adminServerProperties.path("/assets/**")).permitAll() .requestMatchers(this.adminServerProperties.path("/js/**")).permitAll() .requestMatchers(this.adminServerProperties.path("/*.css")).permitAll() .requestMatchers(this.adminServerProperties.path("/*.js")).permitAll() .requestMatchers(this.adminServerProperties.path("/favicon.ico")).permitAll() .requestMatchers(this.adminServerProperties.path("/webjars/**")).permitAll() // 放行健康检查与登录页 .requestMatchers(this.adminServerProperties.path("/actuator/info")).permitAll() .requestMatchers(this.adminServerProperties.path("/actuator/health")).permitAll() .requestMatchers(this.adminServerProperties.path("/login")).permitAll() .anyRequest().authenticated() ) .formLogin(formLogin -> formLogin .loginPage(this.adminServerProperties.path("/login")) .successHandler(successHandler) ) .logout(logout -> logout.logoutUrl(this.adminServerProperties.path("/logout")) .logoutSuccessUrl(this.adminServerProperties.path("/login")) ) .httpBasic(Customizer.withDefaults()) .csrf(csrf -> csrf.csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse()) .ignoringRequestMatchers( new AntPathRequestMatcher(this.adminServerProperties.path("/instances"), HttpMethod.POST.name()), new AntPathRequestMatcher(this.adminServerProperties.path("/instances/*"), HttpMethod.DELETE.name()), new AntPathRequestMatcher(this.adminServerProperties.path("/actuator/**")) ) ); return http.build(); } @Bean public AuthenticationManager authenticationManager() throws Exception { return authenticationConfiguration.getAuthenticationManager(); } @Bean public UserDetailsService userDetailsService() { UserDetails user = User.withUsername(securityProperties.getUser().getName()) .password("{noop}" + securityProperties.getUser().getPassword()) .roles("USER") .build(); return new InMemoryUserDetailsManager(user); } }
2. 修正application.yaml配置
原配置存在缩进错误,boot节点需归属于spring节点:
spring: security: user: name: admin password: admin roles: - USER boot: admin: monitor: status-interval: 30000 status-lifetime: 30000 ui: title: "Invoice Matching Admin" remember-me-enabled: false
3. 版本兼容性验证
Spring Boot Admin 3.0.0-M6是适配Spring Boot 3的预览版本,若问题仍存在,建议升级到Spring Boot Admin正式版(如3.0.0及以上),确保与Spring Boot 3.0.0完全兼容。
问题原因说明
- 静态资源放行不全:Spring Boot Admin 3.x UI依赖
/js、/webjars等目录下的资源,未放行会导致这些请求被拦截,触发登录流程,干扰页面跳转逻辑,出现跳转到CSS文件的异常。 - 配置文件缩进错误:原配置中
boot节点未归属于spring,导致AdminServerProperties无法正确读取路径配置,引发权限匹配异常。 - 登录跳转逻辑优化:添加
alwaysUseDefaultTargetUrl(false)确保仅在无redirectTo参数时跳转到首页,避免强制跳转导致的异常。
内容的提问来源于stack exchange,提问作者Mike
相关产品推荐
相关产品推荐

