You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nextcloud集成Authelia OIDC登录redirect_uri不匹配故障排查

问题背景

正在配置支持OpenID Connect协议的Authelia身份提供商,作为多款应用的统一单点登录服务,第一个计划接入的应用是Nextcloud,配置过程参照官方集成指引操作,但登录时持续报错提示重定向URL无效,即便使用文档给出的官方回调地址也会触发错误。

Authelia侧返回的报错信息如下:

{
  "error": "invalid_request",
  "error_description": "The request is missing a required parameter, includes an invalid parameter value, includes a parameter more than once, or is otherwise malformed. The 'redirect_uri' parameter does not match any of the OAuth 2.0 Client's pre-registered redirect urls."
}

部署环境说明:使用Nginx Proxy Manager作为反向代理,Nginx Proxy Manager、Authelia、Nextcloud三个服务均通过Docker运行。

现有配置

Authelia配置(真实服务域名已替换为example.com)

jwt_secret: ac5Tmfbue44TxPTrCpCWNNZKm7AmvBS6
default_redirection_url: https://example.com

server:
  host: 0.0.0.0
  port: 9091

log:
  level: debug

totp:
  issuer: example.com

authentication_backend:
  file:
    path: /config/users_database.yml

access_control:
  default_policy: one_factor
  rules:
    - domain: auth.example.com
      policy: bypass
    - domain:
        - example.com
        - proxy.example.com
        - nextcloud.example.com
      policy: one_factor

identity_providers:
  oidc:
    hmac_secret: GhuVkMctBBFratABE6fMUacCWKhGgNa23SuDuN62Ug6vxQhJJTsLXca3ZdXyuL7n
    issuer_private_key: {KEY}
    access_token_lifespan: 1h
    authorize_code_lifespan: 1m
    id_token_lifespan: 1h
    refresh_token_lifespan: 90m
    enable_client_debug_messages: false
    enforce_pkce: public_clients_only
    cors:
      endpoints:
        - authorization
        - token
        - revocation
        - introspection
      allowed_origins:
        - https://example.com
      allowed_origins_from_client_redirect_uris: false
    clients:
      - id: nextcloud
        secret: nextcloud_client_secret
        public: false
        authorization_policy: one_factor
        scopes:
          - openid
          - profile
          - groups
        redirect_uris:
          - https://nextcloud.example.com/apps/oidc_login/oidc
        userinfo_signing_algorithm: none

session:
  name: authelia_session
  secret: kHT5S9ed8ArygSwyVZWm48Pyjt4qyXg9
  expiration: 3600
  inactivity: 300
  domain: example.com

regulation:
  max_retries: 3
  find_time: 120
  ban_time: 300

storage:
  encryption_key: nqcWgCG22YM6Uttj4GQw5eeNsWKwr4Xm
  local:
    path: /config/db.sqlite3

notifier:
  filesystem:
    filename: /config/notification.txt

Nextcloud配置(使用OpenID Connect Login插件)

<?php
$CONFIG = array (
  'htaccess.RewriteBase' => '/',
  'memcache.local' => '\OC\Memcache\APCu',
  'apps_paths' => 
  array (
    0 => 
    array (
      'path' => '/var/www/html/apps',
      'url' => '/apps',
      'writable' => false,
    ),
    1 => 
    array (
      'path' => '/var/www/html/custom_apps',
      'url' => '/custom_apps',
      'writable' => true,
    ),
  ),
  'instanceid' => 'owd1s341ok',
  'passwordsalt' => 'Kt7fjLgAGjGMtAdrfdsXR4BEEz5pqzmv',
  'secret' => '64kSvSXtpQ2HUMBEdQTf5NusZ9SnQhBN64kSvSXtpQ2HUe',
  'trusted_domains' => 
  array (
    0 => 'nextcloud.example.com',
  ),
  'datadirectory' => '/var/www/html/data',
  'dbtype' => 'sqlite3',
  'version' => '24.0.1.1',
  'overwrite.cli.url' => 'http://nextcloud.example.com',
  'installed' => true,
  'allow_user_to_change_display_name' => false,
  'lost_password_link' => 'disabled',
  'oidc_login_provider_url' => 'https://auth.example.com',
  'oidc_login_client_id' => 'nextcloud',
  'oidc_login_client_secret' => 'nextcloud_client_secret',
  'oidc_login_auto_redirect' => false,
  'oidc_login_end_session_redirect' => false,
  'oidc_login_button_text' => 'Log in with Authelia',
  'oidc_login_hide_password_form' => false,
  'oidc_login_use_id_token' => true,
  'oidc_login_attributes' => array (
    'id' => 'preferred_username',
    'name' => 'name',
    'mail' => 'email',
    'groups' => 'groups',
  ),
  'oidc_login_default_group' => 'oidc',
  'oidc_login_use_external_storage' => false,
  'oidc_login_scope' => 'openid profile groups',
  'oidc_login_proxy_ldap' => false,
  'oidc_login_disable_registration' => true,
  'oidc_login_redir_fallback' => false,
  'oidc_login_alt_login_page' => 'assets/login.php',
  'oidc_login_tls_verify' => true,
  'oidc_create_groups' => false,
  'oidc_login_webdav_enabled' => false,
  'oidc_login_password_authentication' => false,
  'oidc_login_public_key_caching_time' => 86400,
  'oidc_login_min_time_between_jwks_requests' => 10,
  'oidc_login_well_known_caching_time' => 86400,
  'oidc_login_update_avatar' => false,
);
排查进展

排查过程中发现,触发报错时的授权请求URL如下:

https://auth.example.com/api/oidc/authorization?response_type=code&redirect_uri=http%3A%2F%nextcloud.example.com%2Fapps%2Foidc_login%2Foidc&client_id=nextcloud&nonce=9a2986f054d7044bcb3050ed3c38a1b6&state=9384d2d39924b436f8a0eb6b8bd334ad&scope=openid+profile+groups+openid

手动删除URL查询参数中的redirect_uri参数后重载页面,可正常弹出授权确认请求,同意授权后即可成功登录。

根因与修复方案

问题核心是协议不匹配+Nextcloud反向代理信任配置缺失:

  • Authelia侧预注册的回调地址是https前缀的https://nextcloud.example.com/apps/oidc_login/oidc,但Nextcloud实际发起授权请求时携带的redirect_uri是http前缀,两者字符串完全不匹配,直接触发重定向URL校验失败。
  • 根源是Nextcloud配置里的overwrite.cli.url写的是http://nextcloud.example.com,同时没有配置反向代理可信IP和协议转发规则,识别不到Nginx Proxy Manager转发的HTTPS请求,默认认为自身运行在HTTP协议下,生成回调地址时自动使用了HTTP前缀。

按以下步骤修改即可修复:

  1. 编辑Nextcloud的config.php文件,替换原有overwrite.cli.url配置,同时新增反向代理适配配置:
// 替换原有overwrite.cli.url配置
'overwrite.cli.url' => 'https://nextcloud.example.com',
// 新增以下配置
'trusted_proxies' => 
  array (
    0 => '172.16.0.0/12', // Docker默认网桥网段,自定义Docker网络的话替换为对应网关网段即可
  ),
'overwriteprotocol' => 'https',
'forwarded_for_headers' => array('HTTP_X_FORWARDED_FOR', 'HTTP_X_FORWARDED_PROTO'),
  1. 检查Nginx Proxy Manager中Nextcloud的代理规则,确认已开启WebSockets支持,如果默认没有携带协议转发头,在高级配置里补加:
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Port $server_port;
  1. 重启Nextcloud、Authelia容器,清空浏览器缓存后重新测试登录即可。

额外说明:抓到的授权请求里scope参数重复携带了两次openid,是旧版OpenID Connect Login插件的已知问题,升级插件到最新版就能解决,不影响核心登录流程。

内容的提问来源于stack exchange,提问作者Ypselon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.29 23:27:17