You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security默认登录页不显示及自定义登录页配置求助

解决Spring Security登录页不显示的问题

很高兴你已经定位到核心问题啦!我来帮你梳理完整的操作流程,不管是默认登录页测试还是后续切换自定义登录页,都能顺利运行:

一、让默认登录页正常显示

你已经找到关键配置了——必须在web.xml中添加Spring Security的过滤器链,这是Security规则生效的基础。因为Spring Security所有的认证、授权逻辑都是通过springSecurityFilterChain这个核心过滤器来处理的,如果没配置它,你的Security配置类相当于没起作用,自然不会触发默认登录页。

把这段配置添加到web.xml中:

<filter>
    <filter-name>springSecurityFilterChain</filter-name>
    <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
</filter>
<filter-mapping>
    <filter-name>springSecurityFilterChain</filter-name>
    <url-pattern>/*</url-pattern>
</filter-mapping>

然后看你的SecurityConf配置,本身是没问题的,这里帮你微调下路径写法避免匹配异常:

@Configuration 
@EnableWebSecurity 
@EnableGlobalMethodSecurity(prePostEnabled = true) 
public class SecurityConf extends WebSecurityConfigurerAdapter { 
    @Autowired 
    private UserService userDetailsService; 

    @Override 
    protected void configure(HttpSecurity http) throws Exception { 
        http.csrf().disable(); 
        http.authorizeRequests() 
            .antMatchers("/**/secured/**").authenticated() // 补充前导斜杠,避免路径匹配问题
            .anyRequest().permitAll() 
            .and() 
            .formLogin().permitAll(); // 启用默认登录页,允许所有人访问
    } 

    @Override 
    protected void configure(AuthenticationManagerBuilder auth) throws Exception { 
        auth.userDetailsService(userDetailsService).passwordEncoder(getPasswordEncoder()); 
    } 

    private PasswordEncoder getPasswordEncoder() { 
        return new PasswordEncoder() { 
            @Override 
            public boolean matches(CharSequence rawPassword, String encodedPassword) { 
                return encode(rawPassword).equals(encodedPassword); 
            } 
            @Override 
            public String encode(CharSequence rawPassword) { 
                return rawPassword.toString(); 
            } 
        }; 
    } 
}

现在重启应用,访问/secured/xxx这类受保护的链接,就会自动跳转到Spring Security的默认登录页了。

二、切换为自定义登录页

当你测试完默认认证功能后,就可以替换成自己的登录页了,按照以下步骤操作:

  1. 确认自定义登录页可访问:你已经确认/login页面能直接访问,这步没问题。
  2. 修改Security配置:调整formLogin部分的配置,指定自定义登录页路径,同时补充必要的登录处理规则(注意Java字符串要用双引号):
@Override 
protected void configure(HttpSecurity http) throws Exception { 
    http.csrf().disable(); 
    http.authorizeRequests() 
        .antMatchers("/**/secured/**").authenticated() 
        .anyRequest().permitAll() 
        .and() 
        .formLogin()
            .loginPage("/login") // 指定自定义登录页的访问路径
            .loginProcessingUrl("/doLogin") // Security自动处理登录请求的接口(无需自己实现)
            .usernameParameter("username") // 页面用户名输入框的name属性(默认值,可省略)
            .passwordParameter("password") // 页面密码输入框的name属性(默认值,可省略)
            .defaultSuccessUrl("/secured/home") // 登录成功后默认跳转的页面
            .failureUrl("/login?error") // 登录失败跳转回登录页,并携带错误参数
            .permitAll(); // 允许所有人访问登录页和登录处理接口
}
  1. 调整自定义登录页的表单:确保表单提交路径是/doLogin,请求方法为POST,输入框name属性和配置一致。比如Thymeleaf页面示例:
<!DOCTYPE html>
<html xmlns:th="http://www.thymeleaf.org">
<head>
    <title>自定义登录页</title>
</head>
<body>
    <form th:action="@{/doLogin}" method="post">
        <div>
            <label>用户名:</label>
            <input type="text" name="username" required>
        </div>
        <div>
            <label>密码:</label>
            <input type="password" name="password" required>
        </div>
        <button type="submit">登录</button>
        <!-- 显示登录错误提示 -->
        <span th:if="${param.error}" style="color: red;">用户名或密码错误</span>
    </form>
</body>
</html>

这样配置后,访问受保护链接时会自动跳转到你的自定义登录页,提交表单后Security会处理认证逻辑,成功跳转指定页面,失败则返回登录页并显示错误提示。

内容的提问来源于stack exchange,提问作者Matteo_B

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:31:01