You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署WAR包至Tomcat时登出接口出现404错误

问题描述

我的应用在IntelliJ集成的嵌入式Tomcat中运行正常,但将WAR包部署到Tomcat 8后,登出URL返回404错误(登录功能可正常使用)。使用IntelliJ搭配Tomcat时无此问题。

POM文件内容

<parent>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-parent</artifactId>
    <version>2.6.2</version>
    <relativePath/> 
</parent>

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-test</artifactId>
</dependency>

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-data-jpa</artifactId>
</dependency>

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-web</artifactId>
</dependency>

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-aop</artifactId>
</dependency>
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-tomcat</artifactId>
    <scope>provided</scope>
</dependency>

Spring Security配置代码

protected void configure(HttpSecurity http) throws Exception {

    http
        .csrf().disable();
    http
        .headers()
            .frameOptions().disable();

    http
        .authorizeRequests()
            .anyRequest().permitAll();
}

更新信息

  • 切换至Tomcat 9后问题仍存在。
  • 应用包含JSF视图。

解决方案
  1. 修正登出URL的上下文路径
    嵌入式Tomcat默认以根路径(/)运行应用,而外部Tomcat部署WAR包时,上下文路径是WAR包名称(如/myapp)。如果前端登出请求用了硬编码的/logout,在外部Tomcat下实际应该是/myapp/logout,这会导致404。建议在JSF视图中通过上下文路径动态拼接:

    <a href="#{request.contextPath}/logout">登出</a>
    
  2. 补充Spring Security登出配置
    当前配置未显式定义登出逻辑,嵌入式Tomcat可能自动处理,但外部Tomcat需要明确配置。在configure(HttpSecurity http)方法中添加:

    http
        .logout()
            .logoutUrl("/logout")
            .logoutSuccessUrl("/login")
            .invalidateHttpSession(true)
            .deleteCookies("JSESSIONID");
    
  3. 排查JSF与Spring MVC的路径冲突
    JSF的默认Servlet映射可能和Spring DispatcherServlet路径冲突。可在配置文件中明确两者的路径规则:

    spring.mvc.servlet.path=/
    spring.faces.servlet.path=/faces/*
    

    或者调整登出URL为/app/logout这类不会冲突的地址,同步更新前端请求和Security配置。

  4. 验证WAR包完整性
    解压WAR包检查目录结构,确认Spring Security配置类、Servlet映射配置等文件是否被正确打包,避免构建时遗漏关键文件。


内容的提问来源于stack exchange,提问作者mehran arbabian

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 20:35:21