You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot启用SSL时如何正确配置oauth2Login?

问题:Spring Boot OAuth2客户端oauth2Login()重定向异常

我在配置Spring Boot OAuth2客户端时,遇到了oauth2Login()的设置问题:访问https://localhost:8080时,会直接被重定向到https://localhost:8443/oauth2/authorization/spring-addons-public启动登录流程,但预期应该先跳转到Spring客户端(端口8080)的对应授权端点,再由客户端重定向到认证服务器(端口8443)的authorization-uri。

手动访问https://localhost:8080/oauth2/authorization/spring-addons-public时,授权码流程可以正常触发。请问我遗漏了什么配置?

最简重现代码

pom.xml

<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
    <modelVersion>4.0.0</modelVersion>
    <parent>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-parent</artifactId>
        <version>3.0.0</version>
        <relativePath /> <!-- lookup parent from repository -->
    </parent>
    <artifactId>demo</artifactId>
    <properties>
        <java.version>17</java.version>
    </properties>
    <dependencies>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-oauth2-client</artifactId>
        </dependency>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-web</artifactId>
        </dependency>
        
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-test</artifactId>
            <scope>test</scope>
        </dependency>
    </dependencies>

    <build>
        <plugins>
            <plugin>
                <groupId>org.springframework.boot</groupId>
                <artifactId>spring-boot-maven-plugin</artifactId>
            </plugin>
        </plugins>
    </build>

</project>

application.yaml

spring:
  security:
    oauth2:
      client:
        registration:
          spring-addons-public:
            client-id: "spring-addons-public"
            client-secret: ""
            client-name: "spring-addons-public"
            provider: "keycloak"
            scope: 
              - "openid"
              - "profile"
            redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}"
            client-authentication-method: "none"
            authorization-grant-type: "authorization_code"

        provider:
          keycloak:
            issuer-uri: "https://localhost:8443/realms/master"
            authorization-uri: "https://localhost:8443/realms/master/protocol/openid-connect/auth"
            token-uri: "https://localhost:8443/realms/master/protocol/openid-connect/token"

SecurityConfig.java

@Configuration
@EnableWebSecurity
public class SecurityConfig {
    @Bean
    SecurityFilterChain uiFilterChain(HttpSecurity http) throws Exception {
        // @formatter:off
        http.authorizeHttpRequests()
            .requestMatchers("/oauth2/**").permitAll()
            .requestMatchers("/login/**").permitAll()
            .anyRequest().authenticated();
        // @formatter:on
        http.oauth2Login();

        return http.build();
    }
}

src/main/resources/static/index.html

<!DOCTYPE html>
<head>
    <title>secured</title>
</head>
<body>
    <h1>Secured</h1>
</body>

补充信息

我的Spring Boot应用默认启用了SSL(已设置SERVER_SSL_KEY_PASSWORD、SERVER_SSL_KEY_STORE和SERVER_SSL_KEY_STORE_PASSWORD环境变量),显式设置server.ssl.enabled=false禁用SSL后,重定向端口恢复正常。


问题原因与解决方案

原因

当Spring Boot应用启用SSL时,Spring Security OAuth2客户端在生成重定向到授权端点的URL时,错误地使用了认证服务器的端口(8443),而非自身的端口(8080)。这是因为SSL启用后,客户端内部的baseUrl解析出现偏差,导致重定向目标错误指向认证服务器地址。

解决方案

  • 方案一:显式指定客户端外部访问地址
    在application.yaml中添加配置,让OAuth2客户端正确识别自身地址:

    server:
      forward-headers-strategy: framework
      ssl:
        enabled: true
      port: 8080
      # 显式设置外部访问URL
      external-url: "https://localhost:8080"
    

    或者,直接将redirect-uri设置为绝对URL,避免依赖{baseUrl}解析:

    spring:
      security:
        oauth2:
          client:
            registration:
              spring-addons-public:
                redirect-uri: "https://localhost:8080/login/oauth2/code/spring-addons-public"
    
  • 方案二:禁用SSL(已验证有效)
    保持server.ssl.enabled=false配置,这是你已经测试通过的方式。

额外检查

确认认证服务器(Keycloak)的客户端配置中,Valid Redirect URIs包含https://localhost:8080/login/oauth2/code/spring-addons-public,避免后续回调流程失败。


内容的提问来源于stack exchange,提问作者ch4mp

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 00:01:16