Spring Security默认登录页不显示及自定义登录页配置求助
解决Spring Security登录页不显示的问题
很高兴你已经定位到核心问题啦!我来帮你梳理完整的操作流程,不管是默认登录页测试还是后续切换自定义登录页,都能顺利运行:
一、让默认登录页正常显示
你已经找到关键配置了——必须在web.xml中添加Spring Security的过滤器链,这是Security规则生效的基础。因为Spring Security所有的认证、授权逻辑都是通过springSecurityFilterChain这个核心过滤器来处理的,如果没配置它,你的Security配置类相当于没起作用,自然不会触发默认登录页。
把这段配置添加到web.xml中:
<filter> <filter-name>springSecurityFilterChain</filter-name> <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class> </filter> <filter-mapping> <filter-name>springSecurityFilterChain</filter-name> <url-pattern>/*</url-pattern> </filter-mapping>
然后看你的SecurityConf配置,本身是没问题的,这里帮你微调下路径写法避免匹配异常:
@Configuration @EnableWebSecurity @EnableGlobalMethodSecurity(prePostEnabled = true) public class SecurityConf extends WebSecurityConfigurerAdapter { @Autowired private UserService userDetailsService; @Override protected void configure(HttpSecurity http) throws Exception { http.csrf().disable(); http.authorizeRequests() .antMatchers("/**/secured/**").authenticated() // 补充前导斜杠,避免路径匹配问题 .anyRequest().permitAll() .and() .formLogin().permitAll(); // 启用默认登录页,允许所有人访问 } @Override protected void configure(AuthenticationManagerBuilder auth) throws Exception { auth.userDetailsService(userDetailsService).passwordEncoder(getPasswordEncoder()); } private PasswordEncoder getPasswordEncoder() { return new PasswordEncoder() { @Override public boolean matches(CharSequence rawPassword, String encodedPassword) { return encode(rawPassword).equals(encodedPassword); } @Override public String encode(CharSequence rawPassword) { return rawPassword.toString(); } }; } }
现在重启应用,访问/secured/xxx这类受保护的链接,就会自动跳转到Spring Security的默认登录页了。
二、切换为自定义登录页
当你测试完默认认证功能后,就可以替换成自己的登录页了,按照以下步骤操作:
- 确认自定义登录页可访问:你已经确认
/login页面能直接访问,这步没问题。 - 修改Security配置:调整
formLogin部分的配置,指定自定义登录页路径,同时补充必要的登录处理规则(注意Java字符串要用双引号):
@Override protected void configure(HttpSecurity http) throws Exception { http.csrf().disable(); http.authorizeRequests() .antMatchers("/**/secured/**").authenticated() .anyRequest().permitAll() .and() .formLogin() .loginPage("/login") // 指定自定义登录页的访问路径 .loginProcessingUrl("/doLogin") // Security自动处理登录请求的接口(无需自己实现) .usernameParameter("username") // 页面用户名输入框的name属性(默认值,可省略) .passwordParameter("password") // 页面密码输入框的name属性(默认值,可省略) .defaultSuccessUrl("/secured/home") // 登录成功后默认跳转的页面 .failureUrl("/login?error") // 登录失败跳转回登录页,并携带错误参数 .permitAll(); // 允许所有人访问登录页和登录处理接口 }
- 调整自定义登录页的表单:确保表单提交路径是
/doLogin,请求方法为POST,输入框name属性和配置一致。比如Thymeleaf页面示例:
<!DOCTYPE html> <html xmlns:th="http://www.thymeleaf.org"> <head> <title>自定义登录页</title> </head> <body> <form th:action="@{/doLogin}" method="post"> <div> <label>用户名:</label> <input type="text" name="username" required> </div> <div> <label>密码:</label> <input type="password" name="password" required> </div> <button type="submit">登录</button> <!-- 显示登录错误提示 --> <span th:if="${param.error}" style="color: red;">用户名或密码错误</span> </form> </body> </html>
这样配置后,访问受保护链接时会自动跳转到你的自定义登录页,提交表单后Security会处理认证逻辑,成功跳转指定页面,失败则返回登录页并显示错误提示。
内容的提问来源于stack exchange,提问作者Matteo_B
相关产品推荐
相关产品推荐

