I am working on spring boot application and JSP. I want to display custom styled 404 error page when a user hits some different URLs like https://www.example.com/about/random-unauthorized-url so, https://www.example.com/about is a valid URL but https://www.example.com/about/random-unauthorized-url is not a valid URL. So I want when this thing happens, 404 page should get displayed instead of redirection on home page. Current scenario is when I supply some invalid URLs with domain name, it gets redirected to index or home page, which I don't want. So I tried using some properties in application.yml file as below:
server:
port: 1207
error:
whitelabel:
enabled: false
spring:
autoconfigure:
exclude: org.springframework.boot.autoconfigure.web.servlet.error.ErrorMvcAutoConfiguration
Below is custom security configuration
@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {
@Bean
@Override
public AuthenticationManager authenticationManagerBean() throws Exception {
return super.authenticationManagerBean();
}
@Override
protected void configure(final HttpSecurity http) throws Exception {
http
.httpBasic().disable()
.csrf().disable()
.sessionManagement()
.sessionCreationPolicy(SessionCreationPolicy.IF_REQUIRED)
.and()
.authorizeRequests()
.antMatchers("/public/**").permitAll()
.antMatchers(WebUrl.index).permitAll()
.antMatchers(WebUrl.about).permitAll()
.antMatchers(WebUrl.pageNotFound).permitAll()
.antMatchers("/error").permitAll().anyRequest().authenticated().and()
.apply(new JwtConfigurer(jwtTokenProvider));
http.exceptionHandling().authenticationEntryPoint(unauthenticatedRequestHandler());
http.exceptionHandling().accessDeniedPage("/403");
http.exceptionHandling().authenticationEntryPoint(unauthenticatedRequestHandler());
}
@Bean
public AuthenticationEntryPoint unauthorizedEntryPoint() {
return (request, response, authException) -> response.sendRedirect("/login");
}
@Bean
UnauthenticatedRequestHandler unauthenticatedRequestHandler() {
return new UnauthenticatedRequestHandler();
}
}
This is to handle unauthenticated requests
public class UnauthenticatedRequestHandler implements AuthenticationEntryPoint {
@Override
public void commence(HttpServletRequest request, HttpServletResponse response, AuthenticationException authException) throws IOException {
System.out.println("Request coming here....!!! "+request.getServletPath());
if(request.getServletPath().startsWith("/admin/")) {
response.sendRedirect("/admin/login");
}else {
response.sendRedirect("/");
}
}
}
and created custom error handling controller also
@Controller
public class CustomErrorController implements ErrorController{
@Override
public String getErrorPath() {
return WebUrl.pageNotFound;
}
@RequestMapping(value= {WebUrl.pageNotFound},method= {RequestMethod.GET,RequestMethod.POST})
public ModelAndView handleError(HttpServletRequest request) {
ModelAndView modelAndView = null;
Object status = request.getAttribute(RequestDispatcher.ERROR_STATUS_CODE);
if(status != null) {
Integer statusCode = Integer.valueOf(status.toString());
if(statusCode == HttpStatus.NOT_FOUND.value()) {
modelAndView = new ModelAndView(WebUrl.pageNotFound);
}
}
return modelAndView;
}
}
Below is the structure of view:
src/main/webapp/views/page-not-found.jsp
Unfortunately, above solutions did not worked for me or maybe I mixed things. Please help me on this to solve.
