You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel Passport跳过redirect_uri验证 需配置还是自定义接口

Laravel Passport 跳过 redirect_uri 验证实现方案

首先明确:redirect_uri 验证仅针对 OAuth2 授权码、隐式授权模式,密码模式、客户端凭证模式默认无需传递和校验 redirect_uri,不需要额外处理。

实现前提

该需求无法仅通过官方基础配置完成,需要自定义扩展 Passport 的默认校验逻辑。


具体实现方法

方法1:全局跳过所有客户端的 redirect_uri 校验

核心思路是重写 OAuth 授权类的校验逻辑,替换 Passport 默认使用的授权类:

  1. 创建自定义授权码授权类,继承官方基础类,重写校验方法直接返回true跳过验证:
<?php
namespace App\OAuth2\Grant;

use League\OAuth2\Server\Grant\AuthCodeGrant as BaseAuthCodeGrant;

class AuthCodeGrant extends BaseAuthCodeGrant
{
    protected function validateRedirectUri($requestedRedirectUri, $clientRedirectUri)
    {
        // 直接跳过校验
        return true;
    }
}

如果使用的是隐式授权模式,同步重写ImplicitGrant类即可:

<?php
namespace App\OAuth2\Grant;

use League\OAuth2\Server\Grant\ImplicitGrant as BaseImplicitGrant;

class ImplicitGrant extends BaseImplicitGrant
{
    protected function validateRedirectUri($requestedRedirectUri, $clientRedirectUri)
    {
        return true;
    }
}
  1. 在app/Providers/AppServiceProvider.php的register方法中,替换 Passport 默认的授权类:
use App\OAuth2\Grant\AuthCodeGrant;
use App\OAuth2\Grant\ImplicitGrant;
use Laravel\Passport\Passport;
use League\OAuth2\Server\AuthorizationServer;

public function register()
{
    $this->app->afterResolving(AuthorizationServer::class, function ($server) {
        $reflection = new \ReflectionClass($server);
        $enabledGrantsProperty = $reflection->getProperty('enabledGrants');
        $enabledGrantsProperty->setAccessible(true);
        $grants = $enabledGrantsProperty->getValue($server);

        // 替换授权码授权
        unset($grants['authorization_code']);
        $authCodeGrant = new AuthCodeGrant(
            $this->app->make(\Laravel\Passport\Bridge\AuthCodeRepository::class),
            $this->app->make(\Laravel\Passport\Bridge\RefreshTokenRepository::class),
            new \DateInterval('PT10M')
        );
        $authCodeGrant->setRefreshTokenTTL(Passport::refreshTokensExpireIn());
        $server->enableGrantType($authCodeGrant, Passport::tokensExpireIn());

        // 如需替换隐式授权,添加以下代码
        unset($grants['implicit']);
        $implicitGrant = new ImplicitGrant(new \DateInterval('PT10M'));
        $server->enableGrantType($implicitGrant, Passport::tokensExpireIn());

        $enabledGrantsProperty->setValue($server, $grants);
    });
}

方法2:指定白名单客户端跳过校验(更安全)

不需要全局放开的场景下,可在重写的validateRedirectUri方法中加入客户端判断逻辑,仅给指定客户端开白:

protected function validateRedirectUri($requestedRedirectUri, $clientRedirectUri)
{
    // 允许client_id为1、2的客户端跳过校验,其他客户端走默认校验逻辑
    $allowClientIds = [1, 2];
    if (in_array($this->getClient()->getIdentifier(), $allowClientIds)) {
        return true;
    }
    return parent::validateRedirectUri($requestedRedirectUri, $clientRedirectUri);
}

注意事项

跳过 redirect_uri 校验会大幅降低 OAuth2 授权流程的安全性,可能导致授权码被恶意拦截后重定向到钓鱼站点窃取用户凭证,仅建议在内部测试环境、可信私有系统场景下使用,生产环境不推荐放开该限制。

内容的提问来源于stack exchange,提问作者Silviu ION

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.05 11:18:01