You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot OAuth2 Client未向PingFederate SSO传递client_id问题排查

问题:Spring Security OAuth2 Client对接PingFederate时缺失client_id参数

我正在使用spring-security-starter-oauth2-client配置Spring Boot应用,对接公司部署在不同域名的PingFederate SSO页面。当前配置下,未授权用户会被转发至SSO页面,但URL中未携带client_id等必要参数,导致认证失败。

application.yaml

spring:
  mvc.servlet.path: /my-app/
  security:
    oauth2:
      client:
        registration:
          pingfed:
            authorization-grant-type: authorization_code
            client-id: foo
            client-secret: bar
            scope: openid, profile, email
        provider:
          pingfed:
            authorization-uri: https://sso.company.com/as/authorization.oauth2
            issuer-uri: https://sso.company.com
            token-uri: https://sso.company.com/as/token.oauth2
            user-info-uri: https://sso.company.com/idp/userinfo.openid
            jwk-set-uri: https://sso.company.com/pf/JWKS

Oauth2Config.java

@Configuration
public class OAuth2ClientConfig {
    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http
                .authorizeRequests()
                .anyRequest().authenticated()
                .and()
                .oauth2Login();
        return http.build();
    }
}

运行应用访问受保护页面时,会跳转至登录页面https://sso.company.com/as/authorization.oauth2,并收到“client_id not found”类错误。而正常工作的非Spring应用访问该SSO时,URL会包含client_id=foo、code_challenge=xyz、scope=openid等预期参数。

更新:注释掉mvc.servlet.path后功能恢复正常,推测问题源于Spring默认登录端点为http://localhost:8080/oauth2/authorization/pingfed,但应用实际运行在http://localhost:8080/my-app/,不清楚如何适配配置。


解决方案

问题核心

当设置了spring.mvc.servlet.path=/my-app/后,Spring Security的OAuth2登录端点路径未自动适配该上下文路径,导致跳转逻辑异常,无法正确携带client_id等参数。

适配配置方法

方法1:显式配置OAuth2授权请求路径

在SecurityFilterChain中指定授权请求的路径前缀,使其匹配应用上下文:

@Configuration
public class OAuth2ClientConfig {
    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http
                .authorizeRequests()
                .anyRequest().authenticated()
                .and()
                .oauth2Login(oauth2 -> oauth2
                        .authorizationEndpoint(auth -> auth
                                .baseUri("/my-app/oauth2/authorization")
                        )
                );
        return http.build();
    }
}

方法2:通过配置属性统一设置路径前缀

在application.yaml中添加Spring Security过滤器路径配置,让所有过滤器自动适配上下文:

spring:
  security:
    filter:
      path: /my-app/

原理说明

Spring Security默认的OAuth2授权请求路径为/oauth2/authorization/{registrationId},当应用设置了spring.mvc.servlet.path后,必须确保该路径被正确映射到应用上下文路径下,否则Spring Security无法正确处理授权请求,最终导致跳转SSO时缺失必要参数。


内容的提问来源于stack exchange,提问作者LoganBlack

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 09:42:47