You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security OAuth2授权与资源服务器Postman测试报错排查

中文问题翻译

我已按照Baeldung教程(第2、3节)搭建了Spring Security OAuth2授权服务器与资源服务器,但使用Postman调用API时出现如下错误:

This application has no explicit mapping for /error, so you are seeing this as a fallback.

Sun Aug 21 08:24:17 EDT 2022
There was an unexpected error (type=None, status=999).

我怀疑是回调URL配置问题,但不清楚默认情况下正确的回调URL应该是什么。我的Postman配置如图所示。请问我哪里配置错误?


问题排查与解决

你遇到的/error fallback错误(状态码999),核心原因是授权服务器注册的客户端回调URL与Postman配置不匹配,以下是具体修正步骤:

1. 确认授权服务器的客户端回调URL

查看你搭建授权服务器时的客户端注册代码(对应教程第2节内容),应该有类似如下配置:

RegisteredClient registeredClient = RegisteredClient.withId(UUID.randomUUID().toString())
    .clientId("client")
    .clientSecret("{noop}secret")
    .clientAuthenticationMethod(ClientAuthenticationMethod.CLIENT_SECRET_BASIC)
    .authorizationGrantType(AuthorizationGrantType.AUTHORIZATION_CODE)
    .redirectUri("http://localhost:8080/login/oauth2/code/client") // 关键回调URL
    .scope("read")
    .scope("write")
    .build();

这里的redirectUri值必须和Postman中填写的Callback URL完全一致,包括协议、主机、端口和路径,不能有任何差异。

2. 修正Postman配置

  • 将Postman的Callback URL替换为授权服务器中配置的redirectUri值(比如上述示例中的http://localhost:8080/login/oauth2/code/client)
  • 同步检查其他参数:
    • Auth URL:填写授权服务器的授权端点,通常为http://localhost:8080/oauth2/authorize
    • Access Token URL:填写授权服务器的令牌端点,通常为http://localhost:8080/oauth2/token
    • Client ID和Client Secret:必须与授权服务器注册的clientId、clientSecret完全匹配(教程中客户端密码为{noop}secret,所以Postman直接填secret即可)

3. 额外排查项

若配置无误仍报错:

  • 确认授权服务器与资源服务器端口不冲突(建议分别用8080和8081)
  • 授权码模式需先完成用户登录:Postman会弹出授权服务器的登录页面,登录后才能获取授权码
  • 查看授权服务器日志,若出现invalid redirect_uri类提示,说明回调URL仍不匹配,需再次核对

内容的提问来源于stack exchange,提问作者Jason

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 09:48:16