You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何消除Vaadin+Spring Security的静态资源路径忽略警告?

解决Vaadin 23.1.2 + Java 17下Spring Security静态资源忽略路径警告问题

你需要把原来通过WebSecurity.ignoring()配置的静态资源路径,迁移到HttpSecurity.authorizeHttpRequests()中用permitAll()授权,具体步骤如下:

  1. 移除WebSecurity中的忽略配置
    找到你SecurityConfiguration类里的configure(WebSecurity web)方法,删除其中web.ignoring().antMatchers(...)的相关代码;如果这个方法只用来配置忽略路径,直接删掉整个方法也可以。

  2. 在HttpSecurity中配置permitAll授权
    重写configure(HttpSecurity http)方法,添加对目标静态资源路径的无认证访问许可:

@Override
protected void configure(HttpSecurity http) throws Exception {
    super.configure(http);
    // 为静态资源设置无需认证即可访问
    http.authorizeHttpRequests(auth -> auth
            .antMatchers("/favicon.ico", "/themes/**", "/VAADIN/**")
            .permitAll()
    );
}

注:/VAADIN/**是Vaadin内置静态资源的路径,建议一并加入,避免遗漏相关资源的授权。

  1. 验证结果
    重启应用后,检查日志中的警告是否消失,同时确认静态资源能正常加载,应用的认证流程不受影响。

这种方式符合Spring Security的推荐实践,用显式的授权规则替代路径忽略,既消除了警告,也能更清晰地管理资源访问权限。

内容的提问来源于stack exchange,提问作者mmo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 11:15:44