Azure AD SSO认证成功后重定向异常问题(Kotlin+React)
问题概述
配置Azure AD单点登录时,认证流程显示成功(服务器日志、Azure AD面板均有有效记录,会话Cookie已生成),但Azure AD回调重定向到{YOUR_URL}/central-api/login/oauth2/code/azure-dev时出现404错误,已确认Azure AD与后端配置的redirectURI完全一致。
技术栈:前端React TypeScript,后端Kotlin(Spring Boot + Spring Security + Spring JPA)
排查与解决步骤
1. 验证后端上下文路径配置
重定向URL中的central-api应为后端服务的上下文路径,需确认配置文件(application.yml/application.properties)中是否正确设置:
# application.yml示例 server: servlet: context-path: /central-api
若未配置该参数,后端服务根路径为/,则/central-api路径不存在,直接导致404。
2. 核对OAuth2客户端注册配置
检查后端OAuth2客户端配置,确保redirect-uri使用动态占位符匹配上下文路径,避免硬编码错误:
# application.yml示例 spring: security: oauth2: client: registration: azure-dev: client-id: YOUR_CLIENT_ID client-secret: YOUR_CLIENT_SECRET redirect-uri: "{baseUrl}/login/oauth2/code/azure-dev" provider: azure-dev: authorization-uri: https://login.microsoftonline.com/{TENANT_ID}/oauth2/v2.0/authorize token-uri: https://login.microsoftonline.com/{TENANT_ID}/oauth2/v2.0/token user-info-uri: https://graph.microsoft.com/oidc/userinfo jwk-set-uri: https://login.microsoftonline.com/{TENANT_ID}/discovery/v2.0/keys
{baseUrl}会自动拼接服务器地址+上下文路径,确保redirect-uri与Azure AD中配置完全匹配。
3. 确保回调路径被Spring Security放行
虽然Spring Security默认允许/login/oauth2/code/**路径,但可显式添加规则避免拦截:
修改SecurityConfig中的authorizeHttpRequests配置:
.authorizeHttpRequests { authorize -> authorize .requestMatchers("/public/**", "/login/oauth2/code/**").permitAll() .anyRequest().authenticated() }
4. 检查自定义认证成功处理器的启用
你已实现customAuthenticationSuccessHandler,但当前配置中未启用,仍使用默认的defaultSuccessUrl。若需自定义跳转逻辑,需替换配置:
.oauth2Login { oauth2Login -> oauth2Login .successHandler(customAuthenticationSuccessHandler()) // 若仍需默认跳转作为 fallback,可保留defaultSuccessUrl,优先级低于successHandler // .defaultSuccessUrl("YOUR_URL_HERE", true) }
5. 排查反向代理/网关配置
若前端与后端之间存在反向代理(如Nginx),需确认代理规则是否正确转发/central-api路径:
# Nginx示例配置 location /central-api/ { proxy_pass http://backend-service:8080/; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; }
避免代理过程中丢失路径前缀或错误重写URL。
内容的提问来源于stack exchange,提问作者Belury

