You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无WebSecurityConfigurerAdapter实现认证遇/login路由异常问题

问题分析与解决方案

核心问题

  1. 自定义登录页未实现:你在SecurityConfig中设置了loginPage("/login"),但没有编写对应的Controller处理GET /login请求以返回登录表单,导致访问该路径时出现404,无法提交登录数据。
  2. UserDetailsService未正确绑定:你的configure(AuthenticationManagerBuilder)方法缺少@Autowired注解,Spring容器无法识别并调用它,导致自定义的CustomUserDetailsService没有绑定到认证管理器,即便登录页正常,认证逻辑也会失效。

修复步骤

1. 添加登录页Controller

创建Controller处理登录页的GET请求,以Thymeleaf模板为例:

package com.authentication.take.controller;

import org.springframework.stereotype.Controller;
import org.springframework.web.bind.annotation.GetMapping;

@Controller
public class LoginController {
    @GetMapping("/login")
    public String showLoginPage() {
        return "login"; // 对应resources/templates/login.html模板文件
    }
}

2. 修正SecurityConfig配置

调整SecurityConfig,确保UserDetailsService正确配置,同时规范登录流程:

package com.authentication.take.security;

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.authentication.AuthenticationManager;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.authentication.configuration.AuthenticationConfiguration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.crypto.password.NoOpPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.security.web.SecurityFilterChain;

import com.authentication.take.services.CustomUserDetailsService;

@Configuration
@EnableWebSecurity
public class SecurityConfig {
    
    private final CustomUserDetailsService customUserDetailsService;
    private final AuthenticationConfiguration configuration;

    public SecurityConfig(CustomUserDetailsService customUserDetailsService,
            AuthenticationConfiguration configuration) {
        this.customUserDetailsService = customUserDetailsService;
        this.configuration = configuration;
    }
    
    @Bean
    public PasswordEncoder getPasswordEncoder() {
        return NoOpPasswordEncoder.getInstance();
    }
    
    @Bean
    protected SecurityFilterChain filterChain(HttpSecurity http) 
    throws Exception {
        http
                .cors().and().csrf().disable()
                .authorizeRequests()
                .antMatchers("/yolo/**").permitAll()
                .anyRequest().authenticated()
                .and().formLogin()
                .loginPage("/login")
                .loginProcessingUrl("/login") // 登录表单提交地址,默认即为/login,可省略
                .permitAll()
                .and()
                .logout().permitAll();
        return http.build();
    }
    
    @Bean
    AuthenticationManager authenticationManager() throws Exception {
        return configuration.getAuthenticationManager();
    }
    
    // 添加@Autowired,让Spring自动调用配置认证管理器
    @Autowired
    void configureAuthentication(AuthenticationManagerBuilder builder) throws Exception {
        builder.userDetailsService(customUserDetailsService)
               .passwordEncoder(getPasswordEncoder());
    }
}

3. 确保登录表单正确

登录表单需指向正确的处理地址,示例login.html:

<!DOCTYPE html>
<html xmlns:th="http://www.thymeleaf.org">
<head>
    <title>Login</title>
</head>
<body>
    <form th:action="@{/login}" method="post">
        <div>
            <label>Username: <input type="text" name="username"/></label>
        </div>
        <div>
            <label>Password: <input type="password" name="password"/></label>
        </div>
        <div>
            <input type="submit" value="Login"/>
        </div>
    </form>
</body>
</html>

额外提示

  • NoOpPasswordEncoder仅适用于测试场景,生产环境必须使用BCryptPasswordEncoder等安全的密码编码器。
  • 若无需自定义登录页,可删除loginPage("/login")配置,直接使用Spring Security默认登录页。

内容的提问来源于stack exchange,提问作者coolguy123

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.24 18:06:31