Nextcloud集成Authelia OIDC登录redirect_uri不匹配故障排查
问题背景
正在配置支持OpenID Connect协议的Authelia身份提供商,作为多款应用的统一单点登录服务,第一个计划接入的应用是Nextcloud,配置过程参照官方集成指引操作,但登录时持续报错提示重定向URL无效,即便使用文档给出的官方回调地址也会触发错误。
Authelia侧返回的报错信息如下:
{ "error": "invalid_request", "error_description": "The request is missing a required parameter, includes an invalid parameter value, includes a parameter more than once, or is otherwise malformed. The 'redirect_uri' parameter does not match any of the OAuth 2.0 Client's pre-registered redirect urls." }
部署环境说明:使用Nginx Proxy Manager作为反向代理,Nginx Proxy Manager、Authelia、Nextcloud三个服务均通过Docker运行。
现有配置
Authelia配置(真实服务域名已替换为example.com)
jwt_secret: ac5Tmfbue44TxPTrCpCWNNZKm7AmvBS6 default_redirection_url: https://example.com server: host: 0.0.0.0 port: 9091 log: level: debug totp: issuer: example.com authentication_backend: file: path: /config/users_database.yml access_control: default_policy: one_factor rules: - domain: auth.example.com policy: bypass - domain: - example.com - proxy.example.com - nextcloud.example.com policy: one_factor identity_providers: oidc: hmac_secret: GhuVkMctBBFratABE6fMUacCWKhGgNa23SuDuN62Ug6vxQhJJTsLXca3ZdXyuL7n issuer_private_key: {KEY} access_token_lifespan: 1h authorize_code_lifespan: 1m id_token_lifespan: 1h refresh_token_lifespan: 90m enable_client_debug_messages: false enforce_pkce: public_clients_only cors: endpoints: - authorization - token - revocation - introspection allowed_origins: - https://example.com allowed_origins_from_client_redirect_uris: false clients: - id: nextcloud secret: nextcloud_client_secret public: false authorization_policy: one_factor scopes: - openid - profile - groups redirect_uris: - https://nextcloud.example.com/apps/oidc_login/oidc userinfo_signing_algorithm: none session: name: authelia_session secret: kHT5S9ed8ArygSwyVZWm48Pyjt4qyXg9 expiration: 3600 inactivity: 300 domain: example.com regulation: max_retries: 3 find_time: 120 ban_time: 300 storage: encryption_key: nqcWgCG22YM6Uttj4GQw5eeNsWKwr4Xm local: path: /config/db.sqlite3 notifier: filesystem: filename: /config/notification.txt
Nextcloud配置(使用OpenID Connect Login插件)
<?php $CONFIG = array ( 'htaccess.RewriteBase' => '/', 'memcache.local' => '\OC\Memcache\APCu', 'apps_paths' => array ( 0 => array ( 'path' => '/var/www/html/apps', 'url' => '/apps', 'writable' => false, ), 1 => array ( 'path' => '/var/www/html/custom_apps', 'url' => '/custom_apps', 'writable' => true, ), ), 'instanceid' => 'owd1s341ok', 'passwordsalt' => 'Kt7fjLgAGjGMtAdrfdsXR4BEEz5pqzmv', 'secret' => '64kSvSXtpQ2HUMBEdQTf5NusZ9SnQhBN64kSvSXtpQ2HUe', 'trusted_domains' => array ( 0 => 'nextcloud.example.com', ), 'datadirectory' => '/var/www/html/data', 'dbtype' => 'sqlite3', 'version' => '24.0.1.1', 'overwrite.cli.url' => 'http://nextcloud.example.com', 'installed' => true, 'allow_user_to_change_display_name' => false, 'lost_password_link' => 'disabled', 'oidc_login_provider_url' => 'https://auth.example.com', 'oidc_login_client_id' => 'nextcloud', 'oidc_login_client_secret' => 'nextcloud_client_secret', 'oidc_login_auto_redirect' => false, 'oidc_login_end_session_redirect' => false, 'oidc_login_button_text' => 'Log in with Authelia', 'oidc_login_hide_password_form' => false, 'oidc_login_use_id_token' => true, 'oidc_login_attributes' => array ( 'id' => 'preferred_username', 'name' => 'name', 'mail' => 'email', 'groups' => 'groups', ), 'oidc_login_default_group' => 'oidc', 'oidc_login_use_external_storage' => false, 'oidc_login_scope' => 'openid profile groups', 'oidc_login_proxy_ldap' => false, 'oidc_login_disable_registration' => true, 'oidc_login_redir_fallback' => false, 'oidc_login_alt_login_page' => 'assets/login.php', 'oidc_login_tls_verify' => true, 'oidc_create_groups' => false, 'oidc_login_webdav_enabled' => false, 'oidc_login_password_authentication' => false, 'oidc_login_public_key_caching_time' => 86400, 'oidc_login_min_time_between_jwks_requests' => 10, 'oidc_login_well_known_caching_time' => 86400, 'oidc_login_update_avatar' => false, );
排查进展
排查过程中发现,触发报错时的授权请求URL如下:
https://auth.example.com/api/oidc/authorization?response_type=code&redirect_uri=http%3A%2F%nextcloud.example.com%2Fapps%2Foidc_login%2Foidc&client_id=nextcloud&nonce=9a2986f054d7044bcb3050ed3c38a1b6&state=9384d2d39924b436f8a0eb6b8bd334ad&scope=openid+profile+groups+openid
手动删除URL查询参数中的redirect_uri参数后重载页面,可正常弹出授权确认请求,同意授权后即可成功登录。
根因与修复方案
问题核心是协议不匹配+Nextcloud反向代理信任配置缺失:
- Authelia侧预注册的回调地址是
https前缀的https://nextcloud.example.com/apps/oidc_login/oidc,但Nextcloud实际发起授权请求时携带的redirect_uri是http前缀,两者字符串完全不匹配,直接触发重定向URL校验失败。 - 根源是Nextcloud配置里的
overwrite.cli.url写的是http://nextcloud.example.com,同时没有配置反向代理可信IP和协议转发规则,识别不到Nginx Proxy Manager转发的HTTPS请求,默认认为自身运行在HTTP协议下,生成回调地址时自动使用了HTTP前缀。
按以下步骤修改即可修复:
- 编辑Nextcloud的
config.php文件,替换原有overwrite.cli.url配置,同时新增反向代理适配配置:
// 替换原有overwrite.cli.url配置 'overwrite.cli.url' => 'https://nextcloud.example.com', // 新增以下配置 'trusted_proxies' => array ( 0 => '172.16.0.0/12', // Docker默认网桥网段,自定义Docker网络的话替换为对应网关网段即可 ), 'overwriteprotocol' => 'https', 'forwarded_for_headers' => array('HTTP_X_FORWARDED_FOR', 'HTTP_X_FORWARDED_PROTO'),
- 检查Nginx Proxy Manager中Nextcloud的代理规则,确认已开启WebSockets支持,如果默认没有携带协议转发头,在高级配置里补加:
proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Port $server_port;
- 重启Nextcloud、Authelia容器,清空浏览器缓存后重新测试登录即可。
额外说明:抓到的授权请求里scope参数重复携带了两次openid,是旧版OpenID Connect Login插件的已知问题,升级插件到最新版就能解决,不影响核心登录流程。
内容的提问来源于stack exchange,提问作者Ypselon
相关产品推荐
相关产品推荐

