Spring Security登录成功后重定向未遵循x-forwarded-prefix的context-path问题
这不是Spring Security的已知bug,是路由配置和Spring Security重定向逻辑的适配问题,不需要全量自定义重定向处理器,调整配置即可解决。
问题根因
- 你当前的路由配置对
/auth/**路径做了RewritePath规则,请求到达后端认证服务时已经被剥离了/auth前缀,Spring Security默认保存的未认证请求路径是剥离前缀后的/a-page - 你单独配置的
/login、/oauth2/**等路径的路由没有前缀,这部分请求到达后端时没有/auth上下文信息,登录成功后生成重定向地址时自然不会拼接/auth前缀 - 虽然你已经配置了
forward-headers-strategy: NATIVE,但默认规则需要网关透传X-Forwarded-Prefix请求头才能识别网关层的路径前缀
解决方案
方案1(推荐,无额外代码)
- 合并两个认证服务路由,去掉
RewritePath剥离前缀规则 - 给后端认证服务配置全局上下文路径:
server.servlet.context-path=/auth - 网关侧直接透传所有
/auth/**、/oauth2/**、/login相关路径到认证服务即可,无需路径改写,Spring Security会自动基于上下文路径生成正确的重定向地址
方案2(保留现有RewritePath规则)
- 网关侧的
/auth/**路由添加X-Forwarded-Prefix头透传配置:
filters: - RewritePath=/auth(?<segment>/?.*), $\{segment} - AddRequestHeader=X-Forwarded-Prefix, /auth
- 后端认证服务添加配置,开启转发前缀识别:
server: forward-headers-strategy: NATIVE spring: security: oauth2: client: login: use-forward-headers: true
配置完成后Spring Security会自动读取X-Forwarded-Prefix头的值拼接到重定向地址前,生成/auth/a-page的预期地址。
方案3(自定义重定向处理器)
如果以上配置不生效,可以自定义认证成功处理器调整重定向逻辑:
@Configuration @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth.anyRequest().authenticated()) .oauth2Login(oauth2 -> oauth2 .successHandler(authenticationSuccessHandler()) ); return http.build(); } private AuthenticationSuccessHandler authenticationSuccessHandler() { SavedRequestAwareAuthenticationSuccessHandler successHandler = new SavedRequestAwareAuthenticationSuccessHandler(); successHandler.setRedirectStrategy((request, response, url) -> { // 拼接网关前缀,也可从请求头动态获取X-Forwarded-Prefix的值 String targetUrl = "/auth" + url; response.sendRedirect(targetUrl); }); return successHandler; } }
内容的提问来源于stack exchange,提问作者Ioannis Deligiannis
相关产品推荐
相关产品推荐

