无WebSecurityConfigurerAdapter实现认证遇/login路由异常问题
问题分析与解决方案
核心问题
- 自定义登录页未实现:你在SecurityConfig中设置了
loginPage("/login"),但没有编写对应的Controller处理GET /login请求以返回登录表单,导致访问该路径时出现404,无法提交登录数据。 - UserDetailsService未正确绑定:你的
configure(AuthenticationManagerBuilder)方法缺少@Autowired注解,Spring容器无法识别并调用它,导致自定义的CustomUserDetailsService没有绑定到认证管理器,即便登录页正常,认证逻辑也会失效。
修复步骤
1. 添加登录页Controller
创建Controller处理登录页的GET请求,以Thymeleaf模板为例:
package com.authentication.take.controller; import org.springframework.stereotype.Controller; import org.springframework.web.bind.annotation.GetMapping; @Controller public class LoginController { @GetMapping("/login") public String showLoginPage() { return "login"; // 对应resources/templates/login.html模板文件 } }
2. 修正SecurityConfig配置
调整SecurityConfig,确保UserDetailsService正确配置,同时规范登录流程:
package com.authentication.take.security; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.authentication.AuthenticationManager; import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; import org.springframework.security.config.annotation.authentication.configuration.AuthenticationConfiguration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.crypto.password.NoOpPasswordEncoder; import org.springframework.security.crypto.password.PasswordEncoder; import org.springframework.security.web.SecurityFilterChain; import com.authentication.take.services.CustomUserDetailsService; @Configuration @EnableWebSecurity public class SecurityConfig { private final CustomUserDetailsService customUserDetailsService; private final AuthenticationConfiguration configuration; public SecurityConfig(CustomUserDetailsService customUserDetailsService, AuthenticationConfiguration configuration) { this.customUserDetailsService = customUserDetailsService; this.configuration = configuration; } @Bean public PasswordEncoder getPasswordEncoder() { return NoOpPasswordEncoder.getInstance(); } @Bean protected SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .cors().and().csrf().disable() .authorizeRequests() .antMatchers("/yolo/**").permitAll() .anyRequest().authenticated() .and().formLogin() .loginPage("/login") .loginProcessingUrl("/login") // 登录表单提交地址,默认即为/login,可省略 .permitAll() .and() .logout().permitAll(); return http.build(); } @Bean AuthenticationManager authenticationManager() throws Exception { return configuration.getAuthenticationManager(); } // 添加@Autowired,让Spring自动调用配置认证管理器 @Autowired void configureAuthentication(AuthenticationManagerBuilder builder) throws Exception { builder.userDetailsService(customUserDetailsService) .passwordEncoder(getPasswordEncoder()); } }
3. 确保登录表单正确
登录表单需指向正确的处理地址,示例login.html:
<!DOCTYPE html> <html xmlns:th="http://www.thymeleaf.org"> <head> <title>Login</title> </head> <body> <form th:action="@{/login}" method="post"> <div> <label>Username: <input type="text" name="username"/></label> </div> <div> <label>Password: <input type="password" name="password"/></label> </div> <div> <input type="submit" value="Login"/> </div> </form> </body> </html>
额外提示
NoOpPasswordEncoder仅适用于测试场景,生产环境必须使用BCryptPasswordEncoder等安全的密码编码器。- 若无需自定义登录页,可删除
loginPage("/login")配置,直接使用Spring Security默认登录页。
内容的提问来源于stack exchange,提问作者coolguy123
相关产品推荐
相关产品推荐

