You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring MVC应用中如何实现会话过期自动跳转至登录页?

解决Spring MVC会话过期自动重定向到登录页的问题

首先得明确一个核心关键点:你用的SessionDestroyedListener是服务器端触发的事件,但HTTP是请求-响应模式——没有客户端主动发起请求的话,服务器没法主动给浏览器发重定向指令。这就是为什么监听器里没法实现自动跳转的根本原因。

要实现会话过期时自动让用户跳转到登录页,最可行的方案是前端定时检测会话状态,配合Spring Security的会话配置来完成,下面是具体步骤:

1. 配置Spring Security的会话管理

先在Spring Security配置里设置会话无效/过期后的跳转URL,同时确保基础认证配置正确:

@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            // 配置权限规则
            .authorizeRequests()
                .anyRequest().authenticated()
                .and()
            // 配置登录页
            .formLogin()
                .loginPage("/login")
                .permitAll()
                .and()
            // 会话管理配置
            .sessionManagement()
                // 用户操作时会话无效,会跳转到该URL
                .invalidSessionUrl("/login?sessionExpired=true")
                // 可选:限制单用户登录,异地登录时触发跳转
                .maximumSessions(1)
                .expiredUrl("/login?sessionExpired=true");
    }
}

2. 后端添加会话检测接口

写一个轻量接口,用来让前端查询当前会话是否有效:

@Controller
public class SessionCheckController {

    @GetMapping("/check-session")
    @ResponseBody
    public ResponseEntity<Void> checkSession(HttpServletRequest request) {
        // 传入false:如果会话不存在,返回null,不会创建新会话
        if (request.getSession(false) == null) {
            // 会话已过期/不存在,返回401未授权状态
            return ResponseEntity.status(HttpStatus.UNAUTHORIZED).build();
        }
        // 会话有效,返回200状态
        return ResponseEntity.ok().build();
    }
}

3. 前端定时检测会话状态

在所有页面都引入的公共JS文件里,添加定时检测逻辑,主动向服务器查询会话状态,一旦发现过期就跳转:

// 检测间隔建议比服务器会话超时时间短一些(比如服务器设30分钟,这里设25分钟)
const CHECK_INTERVAL = 25 * 60 * 1000;

setInterval(() => {
    fetch('/check-session', {
        credentials: 'include' // 必须携带Cookie,否则服务器无法识别当前会话
    })
    .then(response => {
        if (!response.ok) {
            // 会话无效,跳转到登录页
            window.location.href = '/login?sessionExpired=true';
        }
    })
    .catch(err => {
        console.error('会话状态检测失败:', err);
    });
}, CHECK_INTERVAL);

补充优化建议

  • 如果想提升用户体验,可以在会话即将过期前(比如提前5分钟)弹出提示,让用户选择是否刷新会话,再决定是否跳转。
  • 若你的项目已经集成了WebSocket,也可以用它实现服务器主动推送会话过期通知,但对于大多数场景,前端定时AJAX的方案更轻量、易维护。

内容的提问来源于stack exchange,提问作者saidfagan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:22:19