You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security登录始终跳转至无提示错误页面问题求助

Troubleshooting Login Redirect to Error Page in Spring Security

Hey there! Let's figure out why your login form keeps sending you to an error page. Since you shared a snippet of your SecurityConfiguration.java, let's walk through the most common issues and how to fix them:

1. Mismatched Form Parameter Names

Spring Security expects the username and password fields in your form to have the names username and password by default. If your HTML form uses different names (like user_email or pass), authentication will fail immediately.

  • Fix: Either update your form's input names to match the defaults, or explicitly configure custom parameter names in your security config:
    .formLogin()
        .loginPage("/login")
        .usernameParameter("your-custom-username-field-name")
        .passwordParameter("your-custom-password-field-name")
        .defaultSuccessUrl("/dashboard")
        .failureUrl("/login?error");
    

2. Misconfigured Database Authentication (Since You're Using DataSource)

If you're using JDBC authentication, a few things can go wrong here:

  • Incorrect table/query structure: Make sure your users table has username, password, and enabled columns, and your authorities table has username and authority columns. Double-check your query statements:
    .jdbcAuthentication()
        .dataSource(dataSource)
        .usersByUsernameQuery("SELECT username, password, enabled FROM users WHERE username = ?")
        .authoritiesByUsernameQuery("SELECT username, authority FROM authorities WHERE username = ?");
    
  • Unencrypted passwords: If your database stores plain-text passwords but Spring Security expects an encoded hash, authentication will fail. For testing purposes, you can temporarily use a no-op encoder (never use this in production!):
    .jdbcAuthentication()
        .dataSource(dataSource)
        .passwordEncoder(NoOpPasswordEncoder.getInstance()); // Only for testing
    
    For production, use a strong encoder like BCryptPasswordEncoder.

3. Incorrect Authorization Rules

If you're redirecting to a page the user doesn't have permission to access, or if your login page isn't accessible to anonymous users:

  • Ensure your login page is allowed for unauthenticated users:
    .authorizeRequests()
        .antMatchers("/login", "/css/**", "/js/**").permitAll() // Allow login page and static assets
        .anyRequest().authenticated();
    
  • Check that the defaultSuccessUrl points to a path your user has roles/permissions for. For example, if you set .defaultSuccessUrl("/admin") but the user only has the USER role, they'll be blocked.

4. Missing CSRF Token

Spring Security enables CSRF protection by default. If your login form doesn't include the CSRF token, the request will be rejected, leading to an error redirect.

  • Fix: Add the CSRF token to your HTML form:
    <form action="/login" method="post">
        <!-- Your username/password fields -->
        <input type="hidden" name="${_csrf.parameterName}" value="${_csrf.token}"/>
        <button type="submit">Login</button>
    </form>
    
    (If you're using Thymeleaf, this can be simplified with th:action="@{/login}" which automatically includes the CSRF token.)

5. Check Authentication Logs

Enable debug logging for Spring Security to see exactly why authentication is failing. Add this to your application.properties:

logging.level.org.springframework.security=DEBUG

Look for logs like BadCredentialsException (wrong password), DisabledException (user account is disabled), or LockedException (account locked)—these will tell you the exact issue.

If you can share the full SecurityConfiguration.java code and your login form HTML, I can help narrow it down even more!

内容的提问来源于stack exchange,提问作者ffuentes

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 07:52:55