You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SpringBoot使用Thymeleaf返回带token的HTML页面报404如何解决

问题解决方案

根因梳理

404问题由Thymeleaf模板存放/配置错误、请求参数注解误用两个核心原因导致,按以下步骤修改即可解决:

修复步骤

  • 步骤1:调整模板文件存放位置

    将reset_password_form.html移动到src/main/resources/templates目录下。注意:static目录用于存放不需要动态渲染的静态资源,Thymeleaf默认只会读取templates目录下的文件做变量替换渲染。
  • 步骤2:修正Controller请求参数注解

    当前代码中用的@Param是MyBatis用于DAO层的参数注解,Spring MVC接收GET请求查询参数需使用@RequestParam,修改后代码如下:
    @GetMapping("/reset-password")
    public String showResetPasswordForm(@RequestParam(value = "token") String token, Model model) {
        model.addAttribute("token", token);
        return "reset_password_form";
    }
    
  • 步骤3:确认Thymeleaf默认配置

    检查项目application.properties或application.yml文件,确认没有覆盖Thymeleaf的默认配置,如有修改请调整为以下值:
    以properties格式为例:
    # Thymeleaf默认配置无修改可直接生效,如有自定义配置请对齐以下值
    spring.thymeleaf.prefix=classpath:/templates/
    spring.thymeleaf.suffix=.html
    spring.thymeleaf.mode=HTML
    # 开发环境建议关闭缓存,避免修改模板后刷新不生效
    spring.thymeleaf.cache=false
    
  • 步骤4:补充Spring Security放行规则

    当前的安全配置仅关闭了CSRF和CORS校验,未放开接口访问权限,需补充放行规则避免接口被拦截:
    @Configuration
    public class SecurityConfiguration extends WebSecurityConfigurerAdapter {
        @Override
        protected void configure(HttpSecurity http) throws Exception {
            http.authorizeRequests()
                // 放行重置密码接口
                .antMatchers("/api/v1/reset-password").permitAll()
                .anyRequest().authenticated()
                .and()
                .cors().and().csrf().disable();
        }
    }
    

验证方式

修改完成后启动项目,访问http://{你的服务地址}/api/v1/reset-password?token=测试值,即可看到页面正常加载,且token变量已被替换为传入的测试值。

内容的提问来源于stack exchange,提问作者Anurag Gupta

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.07 15:36:04