Devise Google Omniauth本地正常但生产环境无法使用求助
生产环境下Devise + Google OAuth2无法正常工作
生产环境中点击Google登录后直接跳回登录页,日志显示请求进入了failure回调:
Started POST "/users/auth/google_oauth2" for 112.205.146.56 at 2023-01-27 01:14:38 +0000 Processing by Users::OmniauthCallbacksController#failure as HTML Parameters: {"authenticity_token"=>"[FILTERED]", "commit.x"=>"25", "commit.y"=>"16"} Redirected to https://automateton.com/users/sign_in
但本地环境完全正常,日志能正常进入请求阶段:
Started POST "/users/auth/google_oauth2" for ::1 at 2023-01-27 09:20:01 +0800 DEBUG -- omniauth: (google_oauth2) Request phase initiated.
环境配置
- 生产环境通过
.rbenv-vars配置了密钥、数据库凭证及Google OAuth相关凭证 - Gemfile包含以下依赖:
gem 'devise' gem 'omniauth' gem 'omniauth-google-oauth2' gem 'omniauth-rails_csrf_protection'
- Google开发者控制台配置的重定向URI:
- 本地:
localhost:3000/users/auth/google_oauth2/callback - 生产环境:
www.example.com/users/auth/google_oauth2/callback
- 本地:
已尝试操作
- 配置Let's Encrypt SSL证书
- 添加生产环境回调URI到Google开发者控制台
- 将Google OAuth从测试模式切换为生产模式
补充说明
曾切换到Sorcery gem尝试解决,但问题依旧。怀疑是CSRF相关问题,试过skip_verify_token、protect_from_forgery prepend: true等方案,用户仍会被重定向回登录页,因此回到Devise寻求解决办法。
内容的提问来源于stack exchange,提问作者kimonoso
相关产品推荐
相关产品推荐

