Spring Security OAuth2授权完成后回调返回404错误如何解决?
问题排查与解决方案
核心问题原因
- 你自定义了授权回调地址
http://localhost:8555/oauth/callback,但Spring Security OAuth2客户端默认的授权码回调处理端点路径为{baseUrl}/login/oauth2/code/{registrationId},你没有配置Spring Security使用你自定义的路径作为回调处理端点,导致该路径没有对应服务处理,返回404。 - 配置存在拼写错误:provider下的
user-name-atttibute多了一个t,正确属性名为user-name-attribute,这个错误会影响后续用户信息解析,需要修正。 - 安全配置路径匹配冗余:你配置的
/callback/路径带尾斜杠,和实际回调路径不匹配,虽然你同时配置了/oauth/**放行了回调路径,但属于不严谨配置。
修复方案
方案1:使用Spring Security默认回调路径(推荐,改动最小)
将application.yml里的redirect-uri修改为默认格式即可,同时修正拼写错误:
spring: security: oauth2: client: registration: octa: client-id: <confidential> client-secret: <confidential> scope: openid # 修改为默认回调路径,octa对应你的registrationId redirect-uri: http://localhost:8555/login/oauth2/code/octa clientName: octa provider: octa provider: octa: issuer-uri: https://dev-7858070.okta.com/oauth2/default # 修正拼写错误 user-name-attribute: name server: port: 8555
修改完成后去Okta授权服务器后台,把允许的重定向地址更新为上面的默认路径即可。
方案2:保留自定义的回调路径
如果你需要保留/oauth/callback作为回调地址,需要在安全配置中指定该路径为回调处理端点,同时修正yml的拼写错误:
@Configuration public class ApplicationSecurityConfiguration extends WebSecurityConfigurerAdapter { @Override public void configure(HttpSecurity http) throws Exception { http.antMatcher("/**").authorizeRequests() .antMatchers("/", "/login**","/webjars/**", "/error**", "/oauth/**") .permitAll() .anyRequest().authenticated() .and() .oauth2Login() // 指定自定义回调路径的处理规则 .redirectionEndpoint() .baseUri("/oauth/callback"); } }
内容的提问来源于stack exchange,提问作者zilcuanu
相关产品推荐
相关产品推荐

