You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

两个POST接口/login正常执行,/logout返回405 Method Not Allowed排查

问题排查:/logout接口返回405 Method Not Allowed

核心原因

Spring Security默认自带了/logout注销端点,该端点默认仅接受GET请求,会拦截你自定义的POST /logout请求,最终导致返回405方法不允许错误。

解决步骤

1. 禁用Spring Security默认logout配置

在SecurityConfig的configure(HttpSecurity http)方法中,显式关闭默认的logout处理逻辑:

@Override
protected void configure(HttpSecurity http) throws Exception {
    http
        .csrf().disable()
            .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS)
            .and()
        .addFilterBefore(tokenAuthFilter, BasicAuthenticationFilter.class)
        .authenticationProvider(tokenAuthProvider)
        // 新增:禁用默认logout配置,避免拦截自定义接口
        .logout().disable()
        .authorizeRequests()
            .antMatchers("/guests/**", "/rooms/**", "/maintenances/**")
            .authenticated()
            .and()
        .authorizeRequests()
            .antMatchers("/login/**", "/logout/**").permitAll();
}

2. 验证接口路径映射

检查控制器类是否存在类级别的@RequestMapping前缀,比如@RequestMapping("/api")会让实际接口路径变为/api/logout,而非你预期的/logout,确保请求路径和接口映射完全匹配。

3. 确认请求发送规范

调用/logout时必须使用POST方法,同时保证请求体结构与LoginDTO一致,避免因请求解析失败引发间接错误。

额外提示

如果令牌认证需要在注销时做失效处理,比如从数据库/缓存移除用户有效令牌,需确保自定义logout方法中完成对应业务逻辑。

内容的提问来源于stack exchange,提问作者cognosce

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.24 03:54:15