You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

NGINX中OAuth2认证后重定向至错误URL的问题求助

问题描述

在服务器上使用OAuth2做用户认证时,用户成功认证后会被重定向到主域名,而非预期的子路径/example/。尝试通过请求头传递重定向目标,但auth_request /oauth2/auth指令会剥离所有自定义请求头,多次尝试保留均无效,已排查2天,需要新的排查方向,同时确认是否和Docker容器有关。

当前配置

Nginx配置

location /example {
    # Perform OAuth2 authentication
    auth_request /oauth2/auth;
    error_page 401 = /oauth2/sign_in;

    # If the user is authenticated, attempt to preserve headers
    auth_request_set $user $upstream_http_x_user;

    # Debugging headers - we’ve tried setting them for troubleshooting
    add_header X-Debug-User $user always;
    add_header X-Debug-Redirect $upstream_http_x_auth_request_redirect always;

    # Also tried sending the headers without the body
    auth_request_set $auth_redirect $upstream_http_x_auth_request_redirect;
    proxy_pass_request_body off;  # This was used to pass only the headers
    proxy_set_header Content-Length "";  # No content length since body is removed

    # Attempted to add headers after authentication for custom redirection
    proxy_set_header X-User $user;
    proxy_set_header X-Auth-Request-Redirect $auth_redirect;

    # Forward to the internal service after authentication
    proxy_pass https://localhost:6521/;
    proxy_ssl_verify off;
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;
}

location /oauth2/ {
    proxy_pass http://localhost:4180;  # OAuth2 Proxy port
    proxy_pass_request_body off;  # Pass only headers
    proxy_set_header Content-Length "";  # No content length since body is removed
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;
}

OAuth2 Proxy配置

client_id= "12345678901234567890.apps.googleusercontent.com"
client_secret= "abcde-abcdefghijklomn"
provider = "google"
redirect_url = "https://mydns/oauth2/callback"
pass_access_token = true
pass_host_header = true
pass_authorization_header = true
set_xauthrequest = true

cookie_secret = "1235467890abcdefghijkl"
cookie_secure = true
authenticated_emails_file = "/etc/oauth2_proxy/authorized_emails.txt"

upstreams = ["https://192.168.0.10:6521/"]

修复方案与排查方向

核心逻辑修正

auth_request发起子请求时,默认不会传递原始请求的自定义头,这是Nginx的设计特性。但重定向路径不需要靠请求头传递,应该通过把原始请求路径作为参数传给登录入口,再由OAuth2 Proxy保存,认证完成后跳转回来。

具体修复步骤

  1. 调整Nginx配置,传递原始请求路径
    修改/example和/oauth2/的location块,把原始请求URI作为参数传递给登录流程:

    location /example {
        # 保存用户的原始请求路径
        auth_request_set $original_uri $request_uri;
        auth_request /oauth2/auth;
        # 把原始路径作为rd参数传给登录页面
        error_page 401 = /oauth2/sign_in?rd=$original_uri;
    
        # 获取认证后的用户信息
        auth_request_set $user $upstream_http_x_user;
    
        # 调试用头(可选保留)
        add_header X-Debug-User $user always;
        add_header X-Debug-Original-URI $original_uri always;
    
        # 转发到内部服务
        proxy_pass https://localhost:6521/;
        proxy_ssl_verify off;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header X-User $user;
    }
    
    location /oauth2/ {
        proxy_pass http://localhost:4180;
        proxy_pass_request_body off;
        proxy_set_header Content-Length "";
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        # 把原始路径传给OAuth2 Proxy
        proxy_set_header X-Auth-Request-Redirect $arg_rd;
    }
    
  2. 修改OAuth2 Proxy配置

    • 把upstreams改为["file:///dev/null"]:因为请求转发由Nginx处理,不需要OAuth2 Proxy直接转发,避免路径混乱
    • 添加cookie_path = "/example/":限制认证Cookie只在/example/路径下生效,防止跨路径干扰
    client_id= "12345678901234567890.apps.googleusercontent.com"
    client_secret= "abcde-abcdefghijklomn"
    provider = "google"
    redirect_url = "https://mydns/oauth2/callback"
    pass_access_token = true
    pass_host_header = true
    pass_authorization_header = true
    set_xauthrequest = true
    
    cookie_secret = "1235467890abcdefghijkl"
    cookie_secure = true
    cookie_path = "/example/" # 新增:限制Cookie生效路径
    authenticated_emails_file = "/etc/oauth2_proxy/authorized_emails.txt"
    
    upstreams = ["file:///dev/null"] # 修改:无需上游转发
    

额外排查方向

  • Docker容器网络检查:如果Nginx和OAuth2 Proxy在不同容器,测试容器间通信是否正常:
    进入Nginx容器,执行curl -H "X-Auth-Request-Redirect: /example/test" http://<oauth2-container-ip>:4180/oauth2/auth,查看返回头是否包含X-Auth-Request-Redirect,确认网络是否有拦截。
  • Nginx全局配置干扰:检查主配置文件是否有proxy_hide_header、proxy_set_header的全局规则,可能会覆盖location里的设置。
  • OAuth2 Proxy日志调试:启动时加--log-level debug,查看认证流程中是否收到X-Auth-Request-Redirect头,以及回调时的重定向逻辑。
  • Google OAuth配置校验:确认开发者控制台的“授权重定向URI”和redirect_url完全一致,包括协议、域名、路径,任何差异都会导致重定向异常。

内容的提问来源于stack exchange,提问作者Jimmy Forester

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 05:22:11