You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel Passport OAuth授权页无法自动跳转至SSL问题排查

解决方案:Laravel Passport OAuth/authorize 不自动跳转HTTPS问题

针对双层Nginx反向代理+Docker架构下的Laravel Passport重定向问题,按以下步骤排查修复:

1. 修正Laravel环境变量与代理信任配置

  • 更新.env环境变量:确保APP_URL设置为HTTPS协议的正式域名,生产环境建议关闭调试模式:
    APP_NAME=Laravel
    APP_ENV=production
    APP_DEBUG=false
    APP_URL=https://authtest.example.com
    
  • 配置Trusted Proxies:编辑app/Http/Middleware/TrustProxies.php,让Laravel信任反向代理的请求头,正确识别外部HTTPS协议:
    <?php
    
    namespace App\Http\Middleware;
    
    use Illuminate\Http\Middleware\TrustProxies as Middleware;
    use Illuminate\Http\Request;
    
    class TrustProxies extends Middleware
    {
        /**
         * 可信代理列表,生产环境建议指定具体IP段而非通配符
         * @var array<int, string>|string|null
         */
        protected $proxies = '*';
    
        /**
         * 用于识别代理的请求头
         * @var int
         */
        protected $headers = Request::HEADER_X_FORWARDED_FOR | Request::HEADER_X_FORWARDED_HOST | Request::HEADER_X_FORWARDED_PROTO;
    }
    
    执行配置缓存刷新:
    php artisan config:clear
    php artisan cache:clear
    

2. 完善容器内Nginx的FastCGI参数

容器内Nginx需要将外层代理传递的X-Forwarded-Proto等头正确转发给PHP-FPM,修改容器内Nginx配置的location ~ \.php$段:

location ~ \.php$ {
    include fastcgi_params;
    fastcgi_param SCRIPT_FILENAME $request_filename;
    # 添加转发头参数,确保Laravel能获取到外层的协议信息
    fastcgi_param HTTP_X_FORWARDED_FOR $remote_addr;
    fastcgi_param HTTP_X_FORWARDED_HOST $host;
    fastcgi_param HTTP_X_FORWARDED_PROTO $http_x_forwarded_proto;
    fastcgi_pass unix:/run/php/php8.1-fpm.sock;
}

同时将容器内Nginx的server_name修改为与外层一致的authtest.example.com,避免Host头不一致导致Laravel生成错误URL。

3. 修正外层Nginx配置细节

  • 修复SSL证书路径的错误:将authtest..com修正为authtest.example.com
  • 补充完善代理转发头,确保协议、地址信息完整传递:
location / {
    proxy_set_header X-Forwarded-Proto $scheme;
    proxy_set_header X-Forwarded-For $remote_addr;
    proxy_set_header Host $host;
    proxy_pass http://landings;
}

4. 验证核心逻辑

Laravel Passport生成authorize URL时依赖request()->getSchemeAndHttpHost(),上述配置生效后,Laravel会正确识别外层的HTTPS协议,自动生成HTTPS的授权页面地址,解决手动修改URL的问题。


内容的提问来源于stack exchange,提问作者Armin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 22:48:20