Spring Boot启用SSL时如何正确配置oauth2Login?
我在配置Spring Boot OAuth2客户端时,遇到了oauth2Login()的设置问题:访问https://localhost:8080时,会直接被重定向到https://localhost:8443/oauth2/authorization/spring-addons-public启动登录流程,但预期应该先跳转到Spring客户端(端口8080)的对应授权端点,再由客户端重定向到认证服务器(端口8443)的authorization-uri。
手动访问https://localhost:8080/oauth2/authorization/spring-addons-public时,授权码流程可以正常触发。请问我遗漏了什么配置?
最简重现代码
pom.xml
<?xml version="1.0" encoding="UTF-8"?> <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <parent> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-parent</artifactId> <version>3.0.0</version> <relativePath /> <!-- lookup parent from repository --> </parent> <artifactId>demo</artifactId> <properties> <java.version>17</java.version> </properties> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-oauth2-client</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-test</artifactId> <scope>test</scope> </dependency> </dependencies> <build> <plugins> <plugin> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-maven-plugin</artifactId> </plugin> </plugins> </build> </project>
application.yaml
spring: security: oauth2: client: registration: spring-addons-public: client-id: "spring-addons-public" client-secret: "" client-name: "spring-addons-public" provider: "keycloak" scope: - "openid" - "profile" redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}" client-authentication-method: "none" authorization-grant-type: "authorization_code" provider: keycloak: issuer-uri: "https://localhost:8443/realms/master" authorization-uri: "https://localhost:8443/realms/master/protocol/openid-connect/auth" token-uri: "https://localhost:8443/realms/master/protocol/openid-connect/token"
SecurityConfig.java
@Configuration @EnableWebSecurity public class SecurityConfig { @Bean SecurityFilterChain uiFilterChain(HttpSecurity http) throws Exception { // @formatter:off http.authorizeHttpRequests() .requestMatchers("/oauth2/**").permitAll() .requestMatchers("/login/**").permitAll() .anyRequest().authenticated(); // @formatter:on http.oauth2Login(); return http.build(); } }
src/main/resources/static/index.html
<!DOCTYPE html> <head> <title>secured</title> </head> <body> <h1>Secured</h1> </body>
补充信息
我的Spring Boot应用默认启用了SSL(已设置SERVER_SSL_KEY_PASSWORD、SERVER_SSL_KEY_STORE和SERVER_SSL_KEY_STORE_PASSWORD环境变量),显式设置server.ssl.enabled=false禁用SSL后,重定向端口恢复正常。
问题原因与解决方案
原因
当Spring Boot应用启用SSL时,Spring Security OAuth2客户端在生成重定向到授权端点的URL时,错误地使用了认证服务器的端口(8443),而非自身的端口(8080)。这是因为SSL启用后,客户端内部的baseUrl解析出现偏差,导致重定向目标错误指向认证服务器地址。
解决方案
方案一:显式指定客户端外部访问地址
在application.yaml中添加配置,让OAuth2客户端正确识别自身地址:server: forward-headers-strategy: framework ssl: enabled: true port: 8080 # 显式设置外部访问URL external-url: "https://localhost:8080"或者,直接将redirect-uri设置为绝对URL,避免依赖
{baseUrl}解析:spring: security: oauth2: client: registration: spring-addons-public: redirect-uri: "https://localhost:8080/login/oauth2/code/spring-addons-public"方案二:禁用SSL(已验证有效)
保持server.ssl.enabled=false配置,这是你已经测试通过的方式。
额外检查
确认认证服务器(Keycloak)的客户端配置中,Valid Redirect URIs包含https://localhost:8080/login/oauth2/code/spring-addons-public,避免后续回调流程失败。
内容的提问来源于stack exchange,提问作者ch4mp

