You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security导致访问/login返回404且提示“No static resource login”的问题求助

Spring Security导致访问/login返回404且提示“No static resource login”的问题求助

我折腾出了一个简单的复现例子,搜了好多谷歌结果但都没解决问题,已经卡了两天了,实在搞不懂哪里出问题,求各位大佬帮忙看看!

问题概述

我写了一个简单的测试,访问/login接口期望返回200,但加上Spring Security的配置后,测试总是返回404,提示“No static resource login”。如果把配置类里的SecurityFilterChain Bean注释掉,测试就能正常通过。

测试代码

import org.junit.jupiter.api.Test;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.test.autoconfigure.web.servlet.WebMvcTest;
import org.springframework.test.context.ContextConfiguration;
import org.springframework.test.web.servlet.MockMvc;

import static org.springframework.test.web.servlet.request.MockMvcRequestBuilders.get;
import static org.springframework.test.web.servlet.result.MockMvcResultMatchers.status;

@WebMvcTest(TestController.class)
@ContextConfiguration(classes={SimpleTestConfig.class})
public class Producing404ExampleTest {

    @Autowired
    private MockMvc mvc;

    @Test
    public void givenAuthRequestOnPrivateService_shouldSucceedWith200() throws Exception {
        mvc.perform(get("/login"))
            .andExpect(status().isOk());
    }
}

测试控制器代码

@Controller
public class TestController {

    @RequestMapping(value = "/login", method = RequestMethod.GET)
    public String login(Model model ) {
        model.addAttribute("app_name", "testing");
        model.addAttribute("page_description", "login page");
        return "login";
    }
}

配置类代码

import org.springframework.boot.SpringBootConfiguration;
import org.springframework.context.annotation.Bean;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;

@SpringBootConfiguration
public class SimpleTestConfig {

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(authorize -> authorize
                .requestMatchers("/static**", "/logout/**", "/login/**", "/health/**").permitAll()
                .requestMatchers("/admin/**").hasRole("ADMIN")
                .anyRequest().permitAll()
        );

        return http.build();
    }
}

测试运行结果

MockHttpServletRequest:
  HTTP Method = GET
  Request URI = /login
   Parameters = {}
      Headers = []
         Body = null
Session Attrs = {}

Handler:
         Type = org.springframework.web.servlet.resource.ResourceHttpRequestHandler

Async:
    Async started = false
     Async result = null

Resolved Exception:
         Type = org.springframework.web.servlet.resource.NoResourceFoundException

ModelAndView:
    View name = null
         View = null
        Model = null

FlashMap:
   Attributes = null

MockHttpServletResponse:
       Status = 404
Error message = No static resource login.
      Headers = [Vary:"Origin", "Access-Control-Request-Method", "Access-Control-Request-Headers", X-Content-Type-Options:"nosniff", X-XSS-Protection:"0", Cache-Control:"no-cache, no-store, max-age=0, must-revalidate", Pragma:"no-cache", Expires:"0", X-Frame-Options:"DENY"]
 Content type = null
         Body = 
Forwarded URL = null
Redirected URL = null
      Cookies = []

Status
Expected :200
Actual   :404

补充信息

  • 操作系统:Windows 10
  • JDK版本:21
  • Spring Boot版本:3.2.3
  • 测试框架:Junit Jupiter

实在搞不懂为什么加了Security配置后,请求就被当成静态资源处理了,明明控制器里已经映射了/login路径,求各位帮忙分析下问题所在!

备注:内容来源于stack exchange,提问作者Ian

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.17 12:48:11