You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SpringBoot 2.1.4 Web应用Web端登录失败(Bad credential)求助

Troubleshooting "Bad Credential" Error in Spring Boot Web Login (Works with REST)

Hey there, let's break down why your web form login is throwing a Bad credential error while your REST authentication endpoint works perfectly—even though logs confirm the user is being retrieved correctly. The key lies in the differences between how Spring Security handles web form authentication vs. your custom REST flow, so let's walk through the most likely issues to check:

1. Mismatched Form Parameter Names

Spring Security's default UsernamePasswordAuthenticationFilter expects form fields named username and password. If your Thymeleaf login form uses different names (like email instead of username, or pass instead of password), the filter won't pick up the correct credentials—even though your REST endpoint might be explicitly mapping custom parameter names to the authentication logic.

  • Check your login form: Verify the name attributes of your input fields match what Spring Security expects. For example:
    <input type="text" name="username" th:field="*{username}"/>
    <input type="password" name="password" th:field="*{password}"/>
    
  • Override if needed: If you need custom parameter names, configure them in your WebSecurityConfig:
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.formLogin()
            .usernameParameter("email") // Match your form's username field name
            .passwordParameter("pass")  // Match your form's password field name
            .loginPage("/login")
            .loginProcessingUrl("/perform-login");
    }
    

2. Inconsistent Password Encoding Configuration

This is one of the most common culprits. Even if your REST endpoint correctly verifies passwords using a PasswordEncoder, the web form authentication flow might not be using the same encoder.

  • REST vs Web Flow Difference: Your REST endpoint might be manually checking passwords with passwordEncoder.matches(rawPassword, encodedPassword), but if your WebSecurityConfig doesn't explicitly set the encoder, Spring Security will fall back to NoOpPasswordEncoder (which expects plain-text passwords)—causing a mismatch with your encoded database passwords.
  • Fix the Configuration: Ensure your WebSecurityConfig uses the same PasswordEncoder as your UserSecurityService:
    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder(); // Or whatever encoder you're using
    }
    
    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        auth.userDetailsService(userSecurityService)
            .passwordEncoder(passwordEncoder()); // Bind the encoder to the authentication manager
    }
    

3. Missing CSRF Token in Web Form

Spring Security enables CSRF protection by default for web forms. If your login form doesn't include the CSRF token, the authentication request might be rejected—and in some cases, this can manifest as a Bad credential error (instead of a clear 403 Forbidden).

  • Add CSRF Token to Your Form: Include this hidden field in your Thymeleaf login form to pass the token:
    <form th:action="@{/perform-login}" method="post">
        <!-- Your username/password fields -->
        <input type="hidden" th:name="${_csrf.parameterName}" th:value="${_csrf.token}"/>
        <button type="submit">Login</button>
    </form>
    
  • Verify the Token is Sent: Use browser dev tools (Network tab) to check that the _csrf parameter is included in the form submission payload.

4. Incorrect Login Processing URL

Double-check that your form's action attribute matches the loginProcessingUrl configured in WebSecurityConfig. If they don't align, the request won't reach the UsernamePasswordAuthenticationFilter, and the credentials won't be processed correctly.

  • Example Configuration:
    http.formLogin()
        .loginProcessingUrl("/perform-login"); // Must match your form's action URL
    
  • Form Action:
    <form th:action="@{/perform-login}" method="post">...</form>
    

5. User Account Status Mismatches

Even if the password is correct, Spring Security will reject authentication if the user's UserDetails has any of these flags set to false:

  • accountNonExpired
  • accountNonLocked
  • credentialsNonExpired
  • enabled

Your REST endpoint might be skipping these checks (e.g., only verifying the password), but the web form flow enforces them. Check your UserSecurityService's loadUserByUsername method to ensure all these status flags are set to true for the user you're testing.


内容的提问来源于stack exchange,提问作者Nunyet Calçada

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 05:24:50