You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD SSO认证成功后重定向异常问题(Kotlin+React)

Azure AD SSO重定向404问题排查方案

问题概述

配置Azure AD单点登录时,认证流程显示成功(服务器日志、Azure AD面板均有有效记录,会话Cookie已生成),但Azure AD回调重定向到{YOUR_URL}/central-api/login/oauth2/code/azure-dev时出现404错误,已确认Azure AD与后端配置的redirectURI完全一致。

技术栈:前端React TypeScript,后端Kotlin(Spring Boot + Spring Security + Spring JPA)

排查与解决步骤

1. 验证后端上下文路径配置

重定向URL中的central-api应为后端服务的上下文路径,需确认配置文件(application.yml/application.properties)中是否正确设置:

# application.yml示例
server:
  servlet:
    context-path: /central-api

若未配置该参数,后端服务根路径为/,则/central-api路径不存在,直接导致404。

2. 核对OAuth2客户端注册配置

检查后端OAuth2客户端配置,确保redirect-uri使用动态占位符匹配上下文路径,避免硬编码错误:

# application.yml示例
spring:
  security:
    oauth2:
      client:
        registration:
          azure-dev:
            client-id: YOUR_CLIENT_ID
            client-secret: YOUR_CLIENT_SECRET
            redirect-uri: "{baseUrl}/login/oauth2/code/azure-dev"
        provider:
          azure-dev:
            authorization-uri: https://login.microsoftonline.com/{TENANT_ID}/oauth2/v2.0/authorize
            token-uri: https://login.microsoftonline.com/{TENANT_ID}/oauth2/v2.0/token
            user-info-uri: https://graph.microsoft.com/oidc/userinfo
            jwk-set-uri: https://login.microsoftonline.com/{TENANT_ID}/discovery/v2.0/keys

{baseUrl}会自动拼接服务器地址+上下文路径,确保redirect-uri与Azure AD中配置完全匹配。

3. 确保回调路径被Spring Security放行

虽然Spring Security默认允许/login/oauth2/code/**路径,但可显式添加规则避免拦截:
修改SecurityConfig中的authorizeHttpRequests配置:

.authorizeHttpRequests { authorize ->
    authorize
            .requestMatchers("/public/**", "/login/oauth2/code/**").permitAll()
            .anyRequest().authenticated()
}

4. 检查自定义认证成功处理器的启用

你已实现customAuthenticationSuccessHandler,但当前配置中未启用,仍使用默认的defaultSuccessUrl。若需自定义跳转逻辑,需替换配置:

.oauth2Login { oauth2Login -> oauth2Login
        .successHandler(customAuthenticationSuccessHandler())
        // 若仍需默认跳转作为 fallback,可保留defaultSuccessUrl,优先级低于successHandler
        // .defaultSuccessUrl("YOUR_URL_HERE", true)
}

5. 排查反向代理/网关配置

若前端与后端之间存在反向代理(如Nginx),需确认代理规则是否正确转发/central-api路径:

# Nginx示例配置
location /central-api/ {
    proxy_pass http://backend-service:8080/;
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
}

避免代理过程中丢失路径前缀或错误重写URL。

内容的提问来源于stack exchange,提问作者Belury

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 17:55:54