Vaadin21+Spring Security OAuth2谷歌登录提示找不到oauth2/authorization/google路由
异常原因与解决方案
触发原因
- Vaadin 21(底层对应Flow 8.x版本)的路由拦截逻辑相比Vaadin 14更严格:默认会拦截所有相对路径的跳转请求,优先匹配Vaadin内部注册的路由。而
/oauth2/authorization/google是Spring Security提供的认证端点,不属于Vaadin的路由管理范围,因此Vaadin匹配不到对应路由就抛出NotFoundException。 - 你当前的安全配置中,既注释了父类
VaadinWebSecurityConfigurerAdapter的configure(http)默认逻辑,也没有显式将/oauth2/**路径加入白名单,导致该路径的请求没有被提前转交给Spring Security处理,直接进入了Vaadin的路由匹配流程。
解决步骤
- 第一步:修改安全配置,调整
HttpSecurity规则,放行/oauth2/**路径,参考配置如下:
@Override protected void configure(HttpSecurity http) throws Exception { super.configure(http); http.authorizeRequests() .requestMatchers(SecurityUtils::isFrameworkInternalRequest).permitAll() // 放行oauth2相关端点 .antMatchers("/oauth2/**").permitAll() .anyRequest().authenticated() .and().csrf().disable() .logout().logoutUrl(LOGOUT_URL).logoutSuccessUrl(LOGOUT_SUCCESS_URL) .and().oauth2Login().loginPage(LOGIN_URL).permitAll(); setLoginView(http, LoginView.class); }
- 第二步:修改登录视图中的
Anchor组件,配置忽略Vaadin路由,触发浏览器原生跳转:
Anchor googleLoginButton = new Anchor(URL, "Login with Google"); // 新增该行配置,禁止使用Vaadin客户端路由跳转该链接 googleLoginButton.setRouterIgnore(true);
- 第三步:重启项目验证即可,原有
application.properties中的谷歌OAuth2配置无需修改。
内容的提问来源于stack exchange,提问作者Eager
相关产品推荐
相关产品推荐

