Spring Security OAuth2 Google未授权请求后跳转默认URL而非原请求URL问题
Spring Security OAuth2对接Google登录后重定向异常问题
我正在使用Spring Security OAuth 2.0对接Google作为身份提供商,在会话超时和重新认证的处理上遇到了问题。
场景描述
- 会话超时后发起某REST API请求
- 前端捕获HTTP 403状态码,展示带有Spring Security登录端点跳转链接的页面
- 用户点击该链接后,Spring生成重定向到Google登录页的响应,携带code、state等必要参数,用户完成身份认证
当前表现
- 登录完成后Google重定向到之前请求的REST API地址,导致用户在浏览器中看到JSON返回结果。我不清楚应用哪部分逻辑保存了该请求地址,已关闭所有相关配置
预期表现
- 登录完成后Google重定向到指定的UI首页
初始配置代码
import org.springframework.beans.factory.annotation.Value import org.springframework.context.annotation.Configuration import org.springframework.security.config.annotation.web.builders.HttpSecurity import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter import org.springframework.security.web.authentication.Http403ForbiddenEntryPoint import org.springframework.security.web.authentication.SimpleUrlAuthenticationSuccessHandler @Configuration @EnableWebSecurity class WebSecurityConfiguration: WebSecurityConfigurerAdapter() { @Value("\${app.security.oauth2.defaultSuccessUrl}") lateinit var defaultSuccessUrl: String @Throws(Exception::class) override fun configure(httpSecurity: HttpSecurity) { val successHandler = SimpleUrlAuthenticationSuccessHandler() successHandler.setUseReferer(false) httpSecurity .antMatcher("/**") .authorizeRequests() .antMatchers("/", "/login**", "/js/**", "/error**").permitAll() .anyRequest().authenticated() .and().oauth2Login() .successHandler(successHandler) .defaultSuccessUrl(defaultSuccessUrl) .and().logout().logoutSuccessUrl("/login").deleteCookies("JSESSIONID").permitAll() .and() .csrf().disable() .exceptionHandling() .authenticationEntryPoint(Http403ForbiddenEntryPoint()) } }
已做配置说明
defaultSuccessUrl已配置为预期跳转的UI页面地址- 已将成功处理器替换为
SimpleUrlAuthenticationSuccessHandler,而非默认的SavedRequestAwareAuthenticationSuccessHandler,关闭Spring保存请求地址的能力 - 设置
successHandler.setUseReferer(false)关闭HTTP层面Referer头的读取逻辑 - 使用
Http403ForbiddenEntryPoint()在会话超时时直接返回HTTP 403状态码,由前端处理该状态并展示携带Spring Security登录地址的登录页
问题原因与修复方案
配置的核心问题是:在Spring Security中,如果自定义了登录成功处理器successHandler,那么oauth2Login节点下配置的defaultSuccessUrl参数不会生效。你初始化SimpleUrlAuthenticationSuccessHandler时没有传入默认跳转地址,导致处理器无法识别预期的首页路径,仍然沿用了原有重定向逻辑。
修复方式为:初始化SimpleUrlAuthenticationSuccessHandler时直接传入你配置的defaultSuccessUrl,同时移除oauth2Login节点下重复的defaultSuccessUrl配置即可。
修复后最终配置
import org.springframework.beans.factory.annotation.Value import org.springframework.context.annotation.Configuration import org.springframework.security.config.annotation.web.builders.HttpSecurity import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter import org.springframework.security.web.authentication.Http403ForbiddenEntryPoint import org.springframework.security.web.authentication.SimpleUrlAuthenticationSuccessHandler @Configuration @EnableWebSecurity class WebSecurityConfiguration: WebSecurityConfigurerAdapter() { @Value("\${app.security.oauth2.defaultSuccessUrl}") lateinit var defaultSuccessUrl: String @Throws(Exception::class) override fun configure(httpSecurity: HttpSecurity) { val successHandler = SimpleUrlAuthenticationSuccessHandler(defaultSuccessUrl) successHandler.setUseReferer(false) httpSecurity .antMatcher("/**") .authorizeRequests() .antMatchers("/", "/login**", "/js/**", "/error**").permitAll() .anyRequest().authenticated() .and().oauth2Login() .successHandler(successHandler) .and().logout().logoutSuccessUrl("/login").deleteCookies("JSESSIONID").permitAll() .and() .csrf().disable() .exceptionHandling() .authenticationEntryPoint(Http403ForbiddenEntryPoint()) } }
内容的提问来源于stack exchange,提问作者yaromir
相关产品推荐
相关产品推荐

