You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot无法使用自定义登录页面问题求助

Spring Boot 自定义登录页面配置无效问题

我正在尝试让Spring Boot使用自定义登录页面,完成所有必要配置后预期效果仍未实现。使用的spring-boot-starter-parent版本为3.4.5,Java版本为17。

POM文件依赖

<dependencies>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-thymeleaf</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-web</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-tomcat</artifactId>
        <scope>provided</scope>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-test</artifactId>
        <scope>test</scope>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-data-jpa</artifactId>
        <type>jar</type>
    </dependency>
    <dependency>
        <groupId>org.springframework.security</groupId>
        <artifactId>spring-security-config</artifactId>
        <type>jar</type>
    </dependency>
    <dependency>
        <groupId>org.springframework.security</groupId>
        <artifactId>spring-security-web</artifactId>
        <type>jar</type>
    </dependency>
    <dependency>
        <groupId>org.springframework.data</groupId>
        <artifactId>spring-data-jpa</artifactId>
        <type>jar</type>
    </dependency>
    <dependency>
        <groupId>jakarta.persistence</groupId>
        <artifactId>jakarta.persistence-api</artifactId>
        <type>jar</type>
    </dependency>
    <dependency>
        <groupId>org.mariadb.jdbc</groupId>
        <artifactId>mariadb-java-client</artifactId>
        <version>3.5.3</version>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-security</artifactId>
    </dependency>
    <dependency>
        <groupId>org.thymeleaf.extras</groupId>
        <artifactId>thymeleaf-extras-springsecurity6</artifactId>
        <version>3.1.3.RELEASE</version>
    </dependency>
</dependencies>

安全配置文件

import PollardCreations.Tjabal.Services.StudentDetailsService;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.authentication.dao.DaoAuthenticationProvider;
import org.springframework.security.config.Customizer;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
public class SecurityConfig
{
    @Bean
    public PasswordEncoder passwordEncoder()
    {
        return new BCryptPasswordEncoder();
    }

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception
    {
        return http
                .cors(Customizer.withDefaults())
                .authorizeHttpRequests
                    (auth -> auth
                        .requestMatchers("style.css").permitAll()
                        .requestMatchers("/signInPage.html").permitAll()
                        .requestMatchers("/error.html").permitAll()
                        .anyRequest().authenticated()
                    )
                .formLogin(form -> form
                        .loginPage("/signInPage.html").permitAll()
//                        .loginProcessingUrl("/SignInPage")
                        .defaultSuccessUrl("/signedInStudentAddSession.html", true)
                        .permitAll()
//                        .failureUrl("/SignInPage?error=true")
                )
                .logout(logout -> logout
                        .logoutSuccessUrl("/SignInPage?logout")
                )
                .build();
    }

    @Bean
    public DaoAuthenticationProvider authenticationProvider
        (StudentDetailsService userDetailsService, PasswordEncoder passwordEncoder)
    {
        DaoAuthenticationProvider provider = new DaoAuthenticationProvider();
        provider.setUserDetailsService(userDetailsService);
        provider.setPasswordEncoder(passwordEncoder);
        return provider;
    }
}

问题排查要点

  • 清理冗余依赖:spring-boot-starter-security已经包含spring-security-config和spring-security-web,重复引入易引发版本冲突,删除这两个单独的依赖。
  • 修正路径匹配:
    • 静态资源路径style.css需添加前缀/,改为requestMatchers("/style.css"),确保Spring能正确定位资源。
    • 确认signInPage.html模板文件存在于src/main/resources/templates目录,文件名大小写与配置完全一致。
  • 统一登录路径:若自定义登录表单的action是/SignInPage,取消注释.loginProcessingUrl("/SignInPage"),同时保证路径大小写一致。
  • 注销路径对齐:注销成功URL/SignInPage?logout与登录页面路径/signInPage.html大小写不匹配,统一为相同大小写格式,避免跳转失败。
  • 注册认证提供者:在SecurityFilterChain中添加.authenticationProvider(authenticationProvider(userDetailsService, passwordEncoder())),确保自定义的DaoAuthenticationProvider被Spring Security加载使用。

内容的提问来源于stack exchange,提问作者James Pollard

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 23:17:04