You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Vaadin21+Spring Security OAuth2谷歌登录提示找不到oauth2/authorization/google路由

异常原因与解决方案

触发原因

  1. Vaadin 21(底层对应Flow 8.x版本)的路由拦截逻辑相比Vaadin 14更严格:默认会拦截所有相对路径的跳转请求,优先匹配Vaadin内部注册的路由。而/oauth2/authorization/google是Spring Security提供的认证端点,不属于Vaadin的路由管理范围,因此Vaadin匹配不到对应路由就抛出NotFoundException。
  2. 你当前的安全配置中,既注释了父类VaadinWebSecurityConfigurerAdapter的configure(http)默认逻辑,也没有显式将/oauth2/**路径加入白名单,导致该路径的请求没有被提前转交给Spring Security处理,直接进入了Vaadin的路由匹配流程。

解决步骤

  • 第一步:修改安全配置,调整HttpSecurity规则,放行/oauth2/**路径,参考配置如下:
@Override
protected void configure(HttpSecurity http) throws Exception {
    super.configure(http);
    http.authorizeRequests()
            .requestMatchers(SecurityUtils::isFrameworkInternalRequest).permitAll()
            // 放行oauth2相关端点
            .antMatchers("/oauth2/**").permitAll()
            .anyRequest().authenticated()
            .and().csrf().disable()
            .logout().logoutUrl(LOGOUT_URL).logoutSuccessUrl(LOGOUT_SUCCESS_URL)
            .and().oauth2Login().loginPage(LOGIN_URL).permitAll();
    setLoginView(http, LoginView.class);
}
  • 第二步:修改登录视图中的Anchor组件,配置忽略Vaadin路由,触发浏览器原生跳转:
Anchor googleLoginButton = new Anchor(URL, "Login with Google");
// 新增该行配置,禁止使用Vaadin客户端路由跳转该链接
googleLoginButton.setRouterIgnore(true);
  • 第三步:重启项目验证即可,原有application.properties中的谷歌OAuth2配置无需修改。

内容的提问来源于stack exchange,提问作者Eager

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.25 05:06:04