Spring Boot OAuth2 Client未向PingFederate SSO传递client_id问题排查
我正在使用spring-security-starter-oauth2-client配置Spring Boot应用,对接公司部署在不同域名的PingFederate SSO页面。当前配置下,未授权用户会被转发至SSO页面,但URL中未携带client_id等必要参数,导致认证失败。
application.yaml
spring: mvc.servlet.path: /my-app/ security: oauth2: client: registration: pingfed: authorization-grant-type: authorization_code client-id: foo client-secret: bar scope: openid, profile, email provider: pingfed: authorization-uri: https://sso.company.com/as/authorization.oauth2 issuer-uri: https://sso.company.com token-uri: https://sso.company.com/as/token.oauth2 user-info-uri: https://sso.company.com/idp/userinfo.openid jwk-set-uri: https://sso.company.com/pf/JWKS
Oauth2Config.java
@Configuration public class OAuth2ClientConfig { @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .authorizeRequests() .anyRequest().authenticated() .and() .oauth2Login(); return http.build(); } }
运行应用访问受保护页面时,会跳转至登录页面https://sso.company.com/as/authorization.oauth2,并收到“client_id not found”类错误。而正常工作的非Spring应用访问该SSO时,URL会包含client_id=foo、code_challenge=xyz、scope=openid等预期参数。
更新:注释掉mvc.servlet.path后功能恢复正常,推测问题源于Spring默认登录端点为http://localhost:8080/oauth2/authorization/pingfed,但应用实际运行在http://localhost:8080/my-app/,不清楚如何适配配置。
问题核心
当设置了spring.mvc.servlet.path=/my-app/后,Spring Security的OAuth2登录端点路径未自动适配该上下文路径,导致跳转逻辑异常,无法正确携带client_id等参数。
适配配置方法
方法1:显式配置OAuth2授权请求路径
在SecurityFilterChain中指定授权请求的路径前缀,使其匹配应用上下文:
@Configuration public class OAuth2ClientConfig { @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http .authorizeRequests() .anyRequest().authenticated() .and() .oauth2Login(oauth2 -> oauth2 .authorizationEndpoint(auth -> auth .baseUri("/my-app/oauth2/authorization") ) ); return http.build(); } }
方法2:通过配置属性统一设置路径前缀
在application.yaml中添加Spring Security过滤器路径配置,让所有过滤器自动适配上下文:
spring: security: filter: path: /my-app/
原理说明
Spring Security默认的OAuth2授权请求路径为/oauth2/authorization/{registrationId},当应用设置了spring.mvc.servlet.path后,必须确保该路径被正确映射到应用上下文路径下,否则Spring Security无法正确处理授权请求,最终导致跳转SSO时缺失必要参数。
内容的提问来源于stack exchange,提问作者LoganBlack

