You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache反向代理Spring Boot+SSL环境下GET请求403问题求助

问题分析与解决方案

核心问题定位

当前场景下HTTPS代理后GET请求返回403,但HTTP直连、Insomnia通过SSL请求均正常,核心原因集中在代理环境下的请求头传递、Spring安全策略误判、CORS配置与前端环境不匹配三个方面。


分步解决方案

1. 配置Apache传递HTTPS请求头

Spring Boot无法直接感知Apache反向代理后的原始请求协议,需在443端口的VirtualHost配置中添加以下内容:

RequestHeader set X-Forwarded-Proto "https"
RequestHeader set X-Forwarded-Port "443"

同时启用Apache的mod_headers模块并重启服务:

a2enmod headers
systemctl restart apache2

2. 让Spring Boot识别代理头

在application.properties(或application.yml)中添加配置,确保应用正确解析代理传递的头信息:

# Spring Boot 2.2+版本使用
server.forward-headers-strategy=NATIVE

# 旧版本可替换为
# server.use-forward-headers=true

3. 调整CORS配置适配前端环境

Ionic/Cordova Android应用和Angular Web应用的请求源与普通网页不同,需针对性修改CORS配置:

@Bean
public CorsFilter corsFilter() {
    UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
    CorsConfiguration config = new CorsConfiguration();
    // 替换为你的前端实际域名,不能用*搭配allowCredentials=true
    config.setAllowedOrigins(Arrays.asList(
        "https://your-angular-domain.com",
        "capacitor://localhost",
        "ionic://localhost"
    ));
    config.setAllowedMethods(Arrays.asList("GET", "POST", "PUT", "DELETE", "OPTIONS"));
    config.setAllowedHeaders(Arrays.asList("*"));
    // 允许前端携带凭证(如Cookie)
    config.setAllowCredentials(true);
    source.registerCorsConfiguration("/**", config);
    return new CorsFilter(source);
}

4. 修正Spring Security的CSRF配置

若启用了Spring Security,默认CSRF保护会拦截未携带令牌的请求,需调整配置让前端能正确获取和传递令牌:

@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .csrf()
                // 允许前端从Cookie读取CSRF令牌
                .csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse())
            .and()
            .authorizeRequests()
                // 放行登录路径
                .antMatchers("/login").permitAll()
                // 其他路径需认证
                .anyRequest().authenticated();
    }
}

Angular端可通过拦截器自动携带CSRF令牌:

import { Injectable } from '@angular/core';
import { HttpInterceptor, HttpRequest, HttpHandler, HttpEvent } from '@angular/common/http';
import { Observable } from 'rxjs';

@Injectable()
export class CsrfInterceptor implements HttpInterceptor {
  intercept(req: HttpRequest<any>, next: HttpHandler): Observable<HttpEvent<any>> {
    const token = document.cookie.match(/XSRF-TOKEN=([^;]+)/)?.[1];
    if (token) {
      req = req.clone({
        setHeaders: { 'X-XSRF-TOKEN': token }
      });
    }
    return next.handle(req);
  }
}

5. 确保Apache不拦截OPTIONS预检请求

在443 VirtualHost中添加规则,避免拦截CORS预检的OPTIONS请求:

RewriteEngine On
RewriteCond %{REQUEST_METHOD} OPTIONS
RewriteRule ^(.*)$ $1 [R=200,L]

验证步骤

  1. 重启Apache和Spring Boot应用
  2. 用Angular或Ionic应用发送GET请求,检查浏览器控制台是否有CORS/CSRF相关错误
  3. 查看Spring Boot日志,确认请求的X-Forwarded-Proto头是否为https

内容的提问来源于stack exchange,提问作者Ossama Nasser

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.22 02:36:18