Spring OAuth2经HTTPS代理登录后跳转回HTTP的问题解决
解决方案:修复OAuth2登录后重定向的协议与端口问题
1. 确保Apache反向代理正确传递请求头
首先检查并修正你的Apache配置,必须正确设置X-Forwarded-Proto、X-Forwarded-Host、X-Forwarded-Port这几个核心请求头,让后端应用能识别真实的外部请求协议和域名:
<VirtualHost *:443> ServerName reactrax.com # SSL证书配置(根据实际路径调整) SSLEngine on SSLCertificateFile /path/to/your/cert.pem SSLCertificateKeyFile /path/to/your/key.pem # 反向代理核心配置 ProxyPass / http://localhost:8080/ ProxyPassReverse / http://localhost:8080/ # 强制传递真实请求属性 RequestHeader set X-Forwarded-Proto "https" RequestHeader set X-Forwarded-Host "reactrax.com" RequestHeader set X-Forwarded-Port "443" # 可选:传递客户端真实IP RequestHeader set X-Forwarded-For "%{REMOTE_ADDR}s" </VirtualHost>
注意:若Apache未启用mod_headers模块,先执行a2enmod headers命令启用,再重启Apache服务。
2. 正确配置Spring Boot的Forwarded Header处理
Spring Boot 2.7.x需要明确开启Forwarded Header的识别逻辑,且要保证Filter执行顺序优先于Spring Security:
方式一:通过配置文件启用
在application.properties中添加:
# 启用原生Forwarded Header处理策略 server.forward-headers-strategy=NATIVE # 信任代理服务器IP,避免恶意头伪造 server.tomcat.remoteip.trusted-proxies=127.0.0.1,::1 # Wildfly基于Undertow容器,需开启对应配置 server.undertow.forward-headers-enabled=true
方式二:自定义Filter并设置优先级
若配置文件方式无效,手动注册Filter并确保其在Spring Security之前执行:
import org.springframework.boot.web.servlet.FilterRegistrationBean; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.web.filter.ForwardedHeaderFilter; @Configuration public class ProxyConfig { @Bean public FilterRegistrationBean<ForwardedHeaderFilter> forwardedHeaderFilter() { FilterRegistrationBean<ForwardedHeaderFilter> filterBean = new FilterRegistrationBean<>(); filterBean.setFilter(new ForwardedHeaderFilter()); // 设置优先级为-100,确保在Spring Security Filter之前运行 filterBean.setOrder(-100); return filterBean; } }
3. 修正Spring Security OAuth2的重定向配置
确保OAuth2客户端的重定向逻辑完全适配代理后的HTTPS地址:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.web.SecurityFilterChain; @Configuration @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth .anyRequest().authenticated() ) .oauth2Login(oauth2 -> oauth2 // 使用相对路径或完整HTTPS地址作为成功跳转目标 .defaultSuccessUrl("/loginSuccess", true) .redirectionEndpoint(redir -> redir .baseUri("/login/oauth2/code/google") ) ); return http.build(); } }
同时,必须在Google Cloud控制台的OAuth2客户端配置中,将重定向URI设置为https://reactrax.com/login/oauth2/code/google,禁止使用带8080端口的地址。
4. 检查Wildfly容器配置(可选)
若上述配置仍未解决问题,检查Wildfly的standalone.xml/domain.xml,确保Undertow子系统开启了Forwarded Header支持:
<subsystem xmlns="urn:jboss:domain:undertow:10.0" default-server="default-server" default-virtual-host="default-host"> <server name="default-server"> <http-listener name="default" socket-binding="http" redirect-socket="https"/> <host name="default-host" alias="localhost"> <location name="/" handler="welcome-content"/> <!-- 添加forward-headers过滤器引用 --> <filter-ref name="forward-headers"/> </host> </server> <filters> <!-- 定义forward-headers过滤器 --> <forward-headers-filter name="forward-headers"/> </filters> </subsystem>
关键注意事项
- 所有配置需保持一致:Apache传递的请求头、Spring信任的代理IP、Google控制台的重定向URI必须统一指向
https://reactrax.com - 不要同时启用
server.forward-headers-strategy=NATIVE和自定义ForwardedHeaderFilter,二选一即可 - 测试前清除浏览器缓存与Cookie,避免旧的重定向缓存干扰结果
内容的提问来源于stack exchange,提问作者Gary Kephart
相关产品推荐
相关产品推荐

