Spring Security+Thymeleaf登录页面调试及问题排查求助
Hey there! Let's break down the issues in your code step by step—you're close, just a few misconfigurations are causing the login loop and 405 error.
1. Your custom /login controller is overriding Spring Security's native login processing
You added a @PostMapping("/login") controller method, but Spring Security already handles the /login POST endpoint for authentication under the hood. By defining your own, you're taking over that responsibility, so Spring Security never gets to validate your username/password. That's exactly why your credentials aren't working and you're stuck in a login loop.
Fix: Delete that entire debug GreetingController (or just the /login POST method if you need the rest of the controller). Let Spring Security handle the login request natively.
2. Mismatched login page path and form action
Let's align your config and template:
- In your
WebSecurityConfig, you set.loginPage("/login")—this tells Spring Security to redirect unauthenticated users to the GET/loginendpoint to show the login form. But your controller only has a POST mapping for/login, so when Spring Security tries to redirect, you get the 405 "Request method 'GET' not supported" error. - Your form's action is
@{/login.html}, but Spring Security expects the login form to submit to its default processing endpoint (which is/loginPOST, unless you explicitly change it withloginProcessingUrl).
Fix: Pick one of these two options to align everything:
Option A: Use /login as your login page URL
Add a GET mapping to serve the login form:
@Controller public class LoginController { @GetMapping("/login") public String showLoginForm() { return "login"; // matches your Thymeleaf template filename (login.html) } }
And update your form's action to submit to Spring Security's processing endpoint:
<form th:action="@{/login}" method="post">
Option B: Use /login.html as your login page URL
Update your WebSecurityConfig to match the actual URL of your login page:
.formLogin() .loginPage("/login.html") // match your template's URL .defaultSuccessUrl("/homepage.html", true) .failureUrl("/login.html?error=true") .permitAll()
Then keep your form's action as @{/login} (Spring Security's default processing endpoint).
3. Minor fixes to avoid future issues
- Duplicate
</body>tag: Your login HTML has two closing</body>tags at the end—clean that up to prevent rendering quirks. - Thymeleaf Spring Security namespace: You're using
xmlns:sec="https://www.thymeleaf.org/thymeleaf-extras-springsecurity4"—if you're using Spring Security 5.x or newer, switch to the v5 namespace:
xmlns:sec="https://www.thymeleaf.org/extras/spring-security5"
This isn't causing your current login problem, but it aligns with modern Spring versions.
Quick recap of the fix steps
- Remove your custom
@PostMapping("/login")controller method. - Align your login page URL between
WebSecurityConfigand your controller (or template path). - Update your form's
th:actionto submit to/login(Spring Security's default processing endpoint). - Clean up the duplicate
</body>tag and update the Thymeleaf sec namespace if needed.
After making these changes, submitting user/password should trigger Spring Security's credential validation, and you'll be redirected to /homepage.html as expected.
内容的提问来源于stack exchange,提问作者Nestor Milyaev

