You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security OAuth2 Google未授权请求后跳转默认URL而非原请求URL问题

Spring Security OAuth2对接Google登录后重定向异常问题

我正在使用Spring Security OAuth 2.0对接Google作为身份提供商,在会话超时和重新认证的处理上遇到了问题。

场景描述

  • 会话超时后发起某REST API请求
  • 前端捕获HTTP 403状态码,展示带有Spring Security登录端点跳转链接的页面
  • 用户点击该链接后,Spring生成重定向到Google登录页的响应,携带code、state等必要参数,用户完成身份认证

当前表现

  • 登录完成后Google重定向到之前请求的REST API地址,导致用户在浏览器中看到JSON返回结果。我不清楚应用哪部分逻辑保存了该请求地址,已关闭所有相关配置

预期表现

  • 登录完成后Google重定向到指定的UI首页

初始配置代码

import org.springframework.beans.factory.annotation.Value
import org.springframework.context.annotation.Configuration
import org.springframework.security.config.annotation.web.builders.HttpSecurity
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter
import org.springframework.security.web.authentication.Http403ForbiddenEntryPoint
import org.springframework.security.web.authentication.SimpleUrlAuthenticationSuccessHandler

@Configuration
@EnableWebSecurity
class WebSecurityConfiguration: WebSecurityConfigurerAdapter() {

    @Value("\${app.security.oauth2.defaultSuccessUrl}")
    lateinit var defaultSuccessUrl: String

    @Throws(Exception::class)
    override fun configure(httpSecurity: HttpSecurity) {
        val successHandler = SimpleUrlAuthenticationSuccessHandler()
        successHandler.setUseReferer(false)
        httpSecurity
            .antMatcher("/**")
            .authorizeRequests()
            .antMatchers("/", "/login**", "/js/**", "/error**").permitAll()
            .anyRequest().authenticated()
            .and().oauth2Login()
            .successHandler(successHandler)
            .defaultSuccessUrl(defaultSuccessUrl)
            .and().logout().logoutSuccessUrl("/login").deleteCookies("JSESSIONID").permitAll()
            .and()
            .csrf().disable()
            .exceptionHandling()
            .authenticationEntryPoint(Http403ForbiddenEntryPoint())
    }

}

已做配置说明

  • defaultSuccessUrl已配置为预期跳转的UI页面地址
  • 已将成功处理器替换为SimpleUrlAuthenticationSuccessHandler,而非默认的SavedRequestAwareAuthenticationSuccessHandler,关闭Spring保存请求地址的能力
  • 设置successHandler.setUseReferer(false)关闭HTTP层面Referer头的读取逻辑
  • 使用Http403ForbiddenEntryPoint()在会话超时时直接返回HTTP 403状态码,由前端处理该状态并展示携带Spring Security登录地址的登录页

问题原因与修复方案

配置的核心问题是:在Spring Security中,如果自定义了登录成功处理器successHandler,那么oauth2Login节点下配置的defaultSuccessUrl参数不会生效。你初始化SimpleUrlAuthenticationSuccessHandler时没有传入默认跳转地址,导致处理器无法识别预期的首页路径,仍然沿用了原有重定向逻辑。

修复方式为:初始化SimpleUrlAuthenticationSuccessHandler时直接传入你配置的defaultSuccessUrl,同时移除oauth2Login节点下重复的defaultSuccessUrl配置即可。

修复后最终配置

import org.springframework.beans.factory.annotation.Value
import org.springframework.context.annotation.Configuration
import org.springframework.security.config.annotation.web.builders.HttpSecurity
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter
import org.springframework.security.web.authentication.Http403ForbiddenEntryPoint
import org.springframework.security.web.authentication.SimpleUrlAuthenticationSuccessHandler

@Configuration
@EnableWebSecurity
class WebSecurityConfiguration: WebSecurityConfigurerAdapter() {

    @Value("\${app.security.oauth2.defaultSuccessUrl}")
    lateinit var defaultSuccessUrl: String

    @Throws(Exception::class)
    override fun configure(httpSecurity: HttpSecurity) {
        val successHandler = SimpleUrlAuthenticationSuccessHandler(defaultSuccessUrl)
        successHandler.setUseReferer(false)
        httpSecurity
            .antMatcher("/**")
            .authorizeRequests()
            .antMatchers("/", "/login**", "/js/**", "/error**").permitAll()
            .anyRequest().authenticated()
            .and().oauth2Login()
            .successHandler(successHandler)
            .and().logout().logoutSuccessUrl("/login").deleteCookies("JSESSIONID").permitAll()
            .and()
            .csrf().disable()
            .exceptionHandling()
            .authenticationEntryPoint(Http403ForbiddenEntryPoint())
    }

}

内容的提问来源于stack exchange,提问作者yaromir

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.30 22:18:04