Spring Security导致访问/login返回404且提示“No static resource login”的问题求助
Spring Security导致访问/login返回404且提示“No static resource login”的问题求助
我折腾出了一个简单的复现例子,搜了好多谷歌结果但都没解决问题,已经卡了两天了,实在搞不懂哪里出问题,求各位大佬帮忙看看!
问题概述
我写了一个简单的测试,访问/login接口期望返回200,但加上Spring Security的配置后,测试总是返回404,提示“No static resource login”。如果把配置类里的SecurityFilterChain Bean注释掉,测试就能正常通过。
测试代码
import org.junit.jupiter.api.Test; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.boot.test.autoconfigure.web.servlet.WebMvcTest; import org.springframework.test.context.ContextConfiguration; import org.springframework.test.web.servlet.MockMvc; import static org.springframework.test.web.servlet.request.MockMvcRequestBuilders.get; import static org.springframework.test.web.servlet.result.MockMvcResultMatchers.status; @WebMvcTest(TestController.class) @ContextConfiguration(classes={SimpleTestConfig.class}) public class Producing404ExampleTest { @Autowired private MockMvc mvc; @Test public void givenAuthRequestOnPrivateService_shouldSucceedWith200() throws Exception { mvc.perform(get("/login")) .andExpect(status().isOk()); } }
测试控制器代码
@Controller public class TestController { @RequestMapping(value = "/login", method = RequestMethod.GET) public String login(Model model ) { model.addAttribute("app_name", "testing"); model.addAttribute("page_description", "login page"); return "login"; } }
配置类代码
import org.springframework.boot.SpringBootConfiguration; import org.springframework.context.annotation.Bean; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.web.SecurityFilterChain; @SpringBootConfiguration public class SimpleTestConfig { @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(authorize -> authorize .requestMatchers("/static**", "/logout/**", "/login/**", "/health/**").permitAll() .requestMatchers("/admin/**").hasRole("ADMIN") .anyRequest().permitAll() ); return http.build(); } }
测试运行结果
MockHttpServletRequest: HTTP Method = GET Request URI = /login Parameters = {} Headers = [] Body = null Session Attrs = {} Handler: Type = org.springframework.web.servlet.resource.ResourceHttpRequestHandler Async: Async started = false Async result = null Resolved Exception: Type = org.springframework.web.servlet.resource.NoResourceFoundException ModelAndView: View name = null View = null Model = null FlashMap: Attributes = null MockHttpServletResponse: Status = 404 Error message = No static resource login. Headers = [Vary:"Origin", "Access-Control-Request-Method", "Access-Control-Request-Headers", X-Content-Type-Options:"nosniff", X-XSS-Protection:"0", Cache-Control:"no-cache, no-store, max-age=0, must-revalidate", Pragma:"no-cache", Expires:"0", X-Frame-Options:"DENY"] Content type = null Body = Forwarded URL = null Redirected URL = null Cookies = [] Status Expected :200 Actual :404
补充信息
- 操作系统:Windows 10
- JDK版本:21
- Spring Boot版本:3.2.3
- 测试框架:Junit Jupiter
实在搞不懂为什么加了Security配置后,请求就被当成静态资源处理了,明明控制器里已经映射了/login路径,求各位帮忙分析下问题所在!
备注:内容来源于stack exchange,提问作者Ian
相关产品推荐
相关产品推荐

