Spring Boot未创建登录页却直接跳转至登录页的问题解决
问题描述
我正在学习使用Spring Boot设计登录页面,并未创建任何名为login的文件,仅创建了index页面,但系统默认直接跳转到登录页。以下是我使用的代码:
package com.main.medipp; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; import javax.sql.DataSource; import org.springframework.context.annotation.Bean; import org.springframework.security.authentication.dao.DaoAuthenticationProvider; import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.core.userdetails.UserDetailsService; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; @SuppressWarnings("deprecation") public class WebSecurityConfig extends WebSecurityConfigurerAdapter { @Autowired private DataSource dataSource; @Bean public UserDetailsService userDetailsService() { return (UserDetailsService) new CustomUserDetailsService(); } @Bean public BCryptPasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } @Bean public DaoAuthenticationProvider authenticationProvider() { DaoAuthenticationProvider authProvider = new DaoAuthenticationProvider(); authProvider.setUserDetailsService(userDetailsService()); authProvider.setPasswordEncoder(passwordEncoder()); return authProvider; } @Override protected void configure(AuthenticationManagerBuilder auth) throws Exception { auth.authenticationProvider(authenticationProvider()); } @Override protected void configure(HttpSecurity http) throws Exception { http.authorizeRequests() .antMatchers("/sign_up").permitAll() .antMatchers("/users").authenticated() .anyRequest().permitAll() .and() .formLogin() .usernameParameter("email") .defaultSuccessUrl("/users") .permitAll() .and() .logout().logoutSuccessUrl("/").permitAll(); } }
修改方案
需要做两处关键修改:
1. 启用Spring Security配置
你的WebSecurityConfig类缺少必要注解,导致Spring无法识别并加载自定义配置,从而使用默认Security规则(默认拦截所有请求并跳转至/login)。需添加以下两个注解:
@Configuration:标记该类为配置类@EnableWebSecurity:启用Spring Security的Web安全支持
修改后的类头部代码:
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.context.annotation.Configuration; @SuppressWarnings("deprecation") @Configuration @EnableWebSecurity public class WebSecurityConfig extends WebSecurityConfigurerAdapter { // 原有代码保持不变 }
2. 指定自定义登录页面路径
由于登录表单放在index页面(对应路径/),需在表单登录配置中指定loginPage("/"),让Spring Security跳转到你的index页面而非默认的/login。同时要确保index页面的表单提交路径为/login(Spring Security默认登录处理路径),且用户名输入框的name属性为email(与配置的usernameParameter("email")一致)。
修改configure(HttpSecurity http)方法中的formLogin部分:
@Override protected void configure(HttpSecurity http) throws Exception { http.authorizeRequests() .antMatchers("/sign_up").permitAll() .antMatchers("/users").authenticated() .anyRequest().permitAll() .and() .formLogin() .loginPage("/") // 指定登录页面为根路径的index页面 .usernameParameter("email") .defaultSuccessUrl("/users") .permitAll() .and() .logout().logoutSuccessUrl("/").permitAll(); }
额外注意事项
- 确保index页面的表单代码符合要求,示例如下:
<form action="/login" method="post"> <input type="email" name="email" placeholder="邮箱"> <input type="password" name="password" placeholder="密码"> <button type="submit">登录</button> </form>
- 检查
CustomUserDetailsService是否正确实现UserDetailsService接口,确保loadUserByUsername方法能正确返回用户信息。
内容的提问来源于stack exchange,提问作者Rohit Nagar
相关产品推荐
相关产品推荐

