You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WebFlux OAuth2集成Google登录后重定向异常问题求助

问题分析与解决方案

核心问题排查

  • Google开发者控制台重定向URI未匹配:Spring OAuth2 Client默认的Google登录回调端点是/login/oauth2/code/google,必须确保Google控制台的OAuth2客户端配置中添加了对应环境的该URI(本地开发为http://localhost:8181/login/oauth2/code/google),不匹配会直接导致重定向失败。
  • WebFlux会话配置错误:项目使用Spring Cloud Gateway(WebFlux响应式框架),但原配置用了Servlet环境的server.servlet.session.cookie.same-site=lax,该配置在WebFlux中不生效,需替换为对应前缀的配置。
  • Controller映射路径错误:@RestController("/hello")写法错误,@RestController的参数是Bean名称而非请求路径,导致/hello/wow无法被正确识别,可能让你误以为重定向失败。
  • 未明确登录成功重定向策略:默认重定向逻辑会回到登录前的请求路径,但如果路径不存在或权限配置有问题,会引发302循环。

修改后的代码配置

1. 修正SecurityConfig(添加登录成功处理器)

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.oauth2.client.registration.ReactiveClientRegistrationRepository;
import org.springframework.security.config.annotation.web.reactive.EnableWebFluxSecurity;
import org.springframework.security.config.web.server.ServerHttpSecurity;
import org.springframework.security.web.server.SecurityWebFilterChain;
import org.springframework.security.web.server.authentication.RedirectServerAuthenticationSuccessHandler;

@Configuration
@EnableWebFluxSecurity
public class SecurityConfig {

    @Bean
    public SecurityWebFilterChain springSecurityFilterChain(ServerHttpSecurity serverHttpSecurity, ReactiveClientRegistrationRepository clientRegistrationRepository) {
        // 配置登录成功后固定重定向到指定端点
        RedirectServerAuthenticationSuccessHandler successHandler = new RedirectServerAuthenticationSuccessHandler();
        successHandler.setRedirectUri("/hello/wow");

        serverHttpSecurity
                .csrf(ServerHttpSecurity.CsrfSpec::disable)
                .authorizeExchange(exchange ->
                        exchange.pathMatchers("/eureka/**", "/login/oauth2/code/google")
                                .permitAll()
                                .anyExchange()
                                .authenticated())
                .oauth2Login(oauth2 -> oauth2
                        .clientRegistrationRepository(clientRegistrationRepository)
                        .authenticationSuccessHandler(successHandler));
        return serverHttpSecurity.build();
    }
}

2. 修正application.properties配置

spring.application.name=api-gateway
eureka.client.serviceUrl.defaultZone=http://eureka:password@localhost:8761/eureka
app.eureka-server=localhost

## Product Service Route
spring.cloud.gateway.routes[0].id=product-service
spring.cloud.gateway.routes[0].uri=lb://product-service
spring.cloud.gateway.routes[0].predicates[0]=Path=/api/product

## Order Service Route
spring.cloud.gateway.routes[1].id=order-service
spring.cloud.gateway.routes[1].uri=lb://order-service
spring.cloud.gateway.routes[1].predicates[0]=Path=/api/order

## Discover Server Route
spring.cloud.gateway.routes[2].id=discovery-server
spring.cloud.gateway.routes[2].uri=http://eureka:password@${app.eureka-server}:8761
spring.cloud.gateway.routes[2].predicates[0]=Path=/eureka/web
spring.cloud.gateway.routes[2].filters[0]=SetPath=/

## Discover Server Static Resources Route
spring.cloud.gateway.routes[3].id=discovery-server-static
spring.cloud.gateway.routes[3].uri=http://eureka:password@${app.eureka-server}:8761
spring.cloud.gateway.routes[3].predicates[0]=Path=/eureka/**

spring.security.oauth2.client.registration.google.client-id= 186452584986-77gtfh20v3k0thtskoti1akgvgoclhbt.apps.googleusercontent.com
spring.security.oauth2.client.registration.google.client-secret= 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
spring.security.oauth2.client.registration.google.scope=openid,profile,email
# 替换为WebFlux兼容的会话配置
server.web.session.cookie.same-site=lax

management.zipkin.tracing.endpoint=http://localhost:9411/api/v2/spans
management.tracing.sampling.probability=1.0

# Actuator Prometheus Endpoint
management.endpoints.web.exposure.include= prometheus
server.port=8181
logging.pattern.level=%5p [${spring.application.name:},%X{traceId:-},%X{spanId:-}]

3. 修正Controller映射

@RestController
@RequestMapping("/hello") // 将请求路径配置到@RequestMapping注解上
public class ApiGateWayCtrl {
    @GetMapping("/wow")
    public String get(){
        return "hello world!";
    }
}

额外注意事项

  • Google控制台配置校验:登录Google开发者控制台,找到目标OAuth2客户端,在「授权重定向URI」列表中添加http://localhost:8181/login/oauth2/code/google,线上环境需替换为对应域名。
  • WebFlux与Servlet差异:WebFlux作为响应式框架,所有会话、安全相关配置需使用server.web.*前缀,而非Servlet的server.servlet.*。
  • 权限规则一致性:确保重定向目标路径符合SecurityConfig中的授权规则,当前配置中anyExchange().authenticated()已保证登录后的访问权限。

内容的提问来源于stack exchange,提问作者Hmar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 18:54:50