Thymeleaf downloads login blank file instead navigate to login.html (Springboot)

Viewed 131

Can't navigate from index.html to any other page, when clicking the button to navigate a blank login file is downloaded. I think this problem is linked to security file because at the beginning I didn't had it but after adding it many things have been broken.

This is the html code :

<a href="login" th:href="@{/login}" id = "LOGIN" class="active">Log In</a>

And this is security file :

@Configuration
@EnableWebSecurity

public class Security extends WebSecurityConfigurerAdapter{
    // https://spring.io/guides/gs/securing-web/
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .authorizeRequests()
                .antMatchers("/","/register","/login","/css/**", "/js/**", "/images/**").permitAll()
                .anyRequest().authenticated()
                .and()
            .formLogin()
                .loginPage("/login")
                .permitAll()
                .and()
            .logout()
                .permitAll();
    }
    @Bean
    public PasswordEncoder encoder() {
        return new BCryptPasswordEncoder(11);
    }
}

There is a login.html file in templates.

1 Answers

As soon as you override the default login page by specifying .loginPage(some_string), then the Spring Security default login configuration will be deactivated.

It does not matter what the value of some_string is, it is considered a custom login page even if the value is "/login".

In other words, with your current configuration, when you are overriding the default login page, Spring Security expects you to create the mapping for your custom login endpoint.

As Ratul Sharker said in the comment above, you need to add a @GetMapping("/login") that returns your custom login page.

Related