NGINX中OAuth2认证后重定向至错误URL的问题求助
问题描述
在服务器上使用OAuth2做用户认证时,用户成功认证后会被重定向到主域名,而非预期的子路径/example/。尝试通过请求头传递重定向目标,但auth_request /oauth2/auth指令会剥离所有自定义请求头,多次尝试保留均无效,已排查2天,需要新的排查方向,同时确认是否和Docker容器有关。
当前配置
Nginx配置
location /example { # Perform OAuth2 authentication auth_request /oauth2/auth; error_page 401 = /oauth2/sign_in; # If the user is authenticated, attempt to preserve headers auth_request_set $user $upstream_http_x_user; # Debugging headers - we’ve tried setting them for troubleshooting add_header X-Debug-User $user always; add_header X-Debug-Redirect $upstream_http_x_auth_request_redirect always; # Also tried sending the headers without the body auth_request_set $auth_redirect $upstream_http_x_auth_request_redirect; proxy_pass_request_body off; # This was used to pass only the headers proxy_set_header Content-Length ""; # No content length since body is removed # Attempted to add headers after authentication for custom redirection proxy_set_header X-User $user; proxy_set_header X-Auth-Request-Redirect $auth_redirect; # Forward to the internal service after authentication proxy_pass https://localhost:6521/; proxy_ssl_verify off; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } location /oauth2/ { proxy_pass http://localhost:4180; # OAuth2 Proxy port proxy_pass_request_body off; # Pass only headers proxy_set_header Content-Length ""; # No content length since body is removed proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; }
OAuth2 Proxy配置
client_id= "12345678901234567890.apps.googleusercontent.com" client_secret= "abcde-abcdefghijklomn" provider = "google" redirect_url = "https://mydns/oauth2/callback" pass_access_token = true pass_host_header = true pass_authorization_header = true set_xauthrequest = true cookie_secret = "1235467890abcdefghijkl" cookie_secure = true authenticated_emails_file = "/etc/oauth2_proxy/authorized_emails.txt" upstreams = ["https://192.168.0.10:6521/"]
修复方案与排查方向
核心逻辑修正
auth_request发起子请求时,默认不会传递原始请求的自定义头,这是Nginx的设计特性。但重定向路径不需要靠请求头传递,应该通过把原始请求路径作为参数传给登录入口,再由OAuth2 Proxy保存,认证完成后跳转回来。
具体修复步骤
调整Nginx配置,传递原始请求路径
修改/example和/oauth2/的location块,把原始请求URI作为参数传递给登录流程:location /example { # 保存用户的原始请求路径 auth_request_set $original_uri $request_uri; auth_request /oauth2/auth; # 把原始路径作为rd参数传给登录页面 error_page 401 = /oauth2/sign_in?rd=$original_uri; # 获取认证后的用户信息 auth_request_set $user $upstream_http_x_user; # 调试用头(可选保留) add_header X-Debug-User $user always; add_header X-Debug-Original-URI $original_uri always; # 转发到内部服务 proxy_pass https://localhost:6521/; proxy_ssl_verify off; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-User $user; } location /oauth2/ { proxy_pass http://localhost:4180; proxy_pass_request_body off; proxy_set_header Content-Length ""; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # 把原始路径传给OAuth2 Proxy proxy_set_header X-Auth-Request-Redirect $arg_rd; }修改OAuth2 Proxy配置
- 把
upstreams改为["file:///dev/null"]:因为请求转发由Nginx处理,不需要OAuth2 Proxy直接转发,避免路径混乱 - 添加
cookie_path = "/example/":限制认证Cookie只在/example/路径下生效,防止跨路径干扰
client_id= "12345678901234567890.apps.googleusercontent.com" client_secret= "abcde-abcdefghijklomn" provider = "google" redirect_url = "https://mydns/oauth2/callback" pass_access_token = true pass_host_header = true pass_authorization_header = true set_xauthrequest = true cookie_secret = "1235467890abcdefghijkl" cookie_secure = true cookie_path = "/example/" # 新增:限制Cookie生效路径 authenticated_emails_file = "/etc/oauth2_proxy/authorized_emails.txt" upstreams = ["file:///dev/null"] # 修改:无需上游转发- 把
额外排查方向
- Docker容器网络检查:如果Nginx和OAuth2 Proxy在不同容器,测试容器间通信是否正常:
进入Nginx容器,执行curl -H "X-Auth-Request-Redirect: /example/test" http://<oauth2-container-ip>:4180/oauth2/auth,查看返回头是否包含X-Auth-Request-Redirect,确认网络是否有拦截。 - Nginx全局配置干扰:检查主配置文件是否有
proxy_hide_header、proxy_set_header的全局规则,可能会覆盖location里的设置。 - OAuth2 Proxy日志调试:启动时加
--log-level debug,查看认证流程中是否收到X-Auth-Request-Redirect头,以及回调时的重定向逻辑。 - Google OAuth配置校验:确认开发者控制台的“授权重定向URI”和
redirect_url完全一致,包括协议、域名、路径,任何差异都会导致重定向异常。
内容的提问来源于stack exchange,提问作者Jimmy Forester
相关产品推荐
相关产品推荐

