You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring OAuth2经HTTPS代理登录后跳转回HTTP的问题解决

解决方案:修复OAuth2登录后重定向的协议与端口问题

1. 确保Apache反向代理正确传递请求头

首先检查并修正你的Apache配置,必须正确设置X-Forwarded-Proto、X-Forwarded-Host、X-Forwarded-Port这几个核心请求头,让后端应用能识别真实的外部请求协议和域名:

<VirtualHost *:443>
    ServerName reactrax.com

    # SSL证书配置(根据实际路径调整)
    SSLEngine on
    SSLCertificateFile /path/to/your/cert.pem
    SSLCertificateKeyFile /path/to/your/key.pem

    # 反向代理核心配置
    ProxyPass / http://localhost:8080/
    ProxyPassReverse / http://localhost:8080/

    # 强制传递真实请求属性
    RequestHeader set X-Forwarded-Proto "https"
    RequestHeader set X-Forwarded-Host "reactrax.com"
    RequestHeader set X-Forwarded-Port "443"

    # 可选:传递客户端真实IP
    RequestHeader set X-Forwarded-For "%{REMOTE_ADDR}s"
</VirtualHost>

注意:若Apache未启用mod_headers模块,先执行a2enmod headers命令启用,再重启Apache服务。

2. 正确配置Spring Boot的Forwarded Header处理

Spring Boot 2.7.x需要明确开启Forwarded Header的识别逻辑,且要保证Filter执行顺序优先于Spring Security:

方式一:通过配置文件启用

在application.properties中添加:

# 启用原生Forwarded Header处理策略
server.forward-headers-strategy=NATIVE
# 信任代理服务器IP,避免恶意头伪造
server.tomcat.remoteip.trusted-proxies=127.0.0.1,::1
# Wildfly基于Undertow容器,需开启对应配置
server.undertow.forward-headers-enabled=true

方式二:自定义Filter并设置优先级

若配置文件方式无效,手动注册Filter并确保其在Spring Security之前执行:

import org.springframework.boot.web.servlet.FilterRegistrationBean;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.filter.ForwardedHeaderFilter;

@Configuration
public class ProxyConfig {

    @Bean
    public FilterRegistrationBean<ForwardedHeaderFilter> forwardedHeaderFilter() {
        FilterRegistrationBean<ForwardedHeaderFilter> filterBean = new FilterRegistrationBean<>();
        filterBean.setFilter(new ForwardedHeaderFilter());
        // 设置优先级为-100,确保在Spring Security Filter之前运行
        filterBean.setOrder(-100);
        return filterBean;
    }
}

3. 修正Spring Security OAuth2的重定向配置

确保OAuth2客户端的重定向逻辑完全适配代理后的HTTPS地址:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .anyRequest().authenticated()
            )
            .oauth2Login(oauth2 -> oauth2
                // 使用相对路径或完整HTTPS地址作为成功跳转目标
                .defaultSuccessUrl("/loginSuccess", true)
                .redirectionEndpoint(redir -> redir
                    .baseUri("/login/oauth2/code/google")
                )
            );
        return http.build();
    }
}

同时,必须在Google Cloud控制台的OAuth2客户端配置中,将重定向URI设置为https://reactrax.com/login/oauth2/code/google,禁止使用带8080端口的地址。

4. 检查Wildfly容器配置(可选)

若上述配置仍未解决问题,检查Wildfly的standalone.xml/domain.xml,确保Undertow子系统开启了Forwarded Header支持:

<subsystem xmlns="urn:jboss:domain:undertow:10.0" default-server="default-server" default-virtual-host="default-host">
    <server name="default-server">
        <http-listener name="default" socket-binding="http" redirect-socket="https"/>
        <host name="default-host" alias="localhost">
            <location name="/" handler="welcome-content"/>
            <!-- 添加forward-headers过滤器引用 -->
            <filter-ref name="forward-headers"/>
        </host>
    </server>
    <filters>
        <!-- 定义forward-headers过滤器 -->
        <forward-headers-filter name="forward-headers"/>
    </filters>
</subsystem>

关键注意事项

  • 所有配置需保持一致:Apache传递的请求头、Spring信任的代理IP、Google控制台的重定向URI必须统一指向https://reactrax.com
  • 不要同时启用server.forward-headers-strategy=NATIVE和自定义ForwardedHeaderFilter,二选一即可
  • 测试前清除浏览器缓存与Cookie,避免旧的重定向缓存干扰结果

内容的提问来源于stack exchange,提问作者Gary Kephart

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 19:42:46