You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

HAproxy对接ADFS时根路径重定向到指定页面失败如何解决?

解决方案

核心错误点

你的配置问题出在重定向规则的目标地址缺少https://协议前缀,当前写法会被浏览器判定为相对路径,最终跳转地址会变成https://adfsstg.xxx.com/adfsstg.xxx.com/adfs/ls/IdpInitiatedSignOn.aspx,和预期不符。
额外建议:测试阶段优先使用302临时重定向,避免301永久重定向被浏览器缓存,导致后续配置修改后无法立即验证效果。

修改后的前端配置

frontend adfsstg
  bind 10.129.10.3:443 ssl crt /etc/ssl/certs/wildcard.pem
  mode http
  redirect scheme https if !{ ssl_fc }
  acl is_root path -i /
  # 两种写法二选一:硬编码域名或者动态取请求头的Host值适配多场景
  # 写法1:固定域名
  redirect code 302 location https://adfsstg.xxx.com/adfs/ls/IdpInitiatedSignOn.aspx if is_root
  # 写法2:动态适配域名,无需硬编码
  # redirect code 302 location https://%[req.hdr(Host)]/adfs/ls/IdpInitiatedSignOn.aspx if is_root
  use_backend adfsstg

验证方法

配置修改完成后重载HAProxy服务,使用curl命令直接验证重定向规则是否生效:

curl -I https://adfsstg.xxx.com

正常返回结果中会包含Location: https://adfsstg.xxx.com/adfs/ls/IdpInitiatedSignOn.aspx字段,确认无误后可以把302改为301正式使用。

内容的提问来源于stack exchange,提问作者Marshall

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.30 08:18:05