Rails应用Devise集成FB OAuth登录:PC正常安卓Chrome异常
Hey there, let's tackle this Facebook login issue on Android Chrome with your Rails/Devise setup. I've run into similar problems with mobile OAuth flows before, so here are the most likely fixes to try out:
1. 强制启用HTTPS(移动端最核心的问题)
Android Chrome and Facebook's OAuth system are far stricter about non-HTTPS connections compared to desktop browsers. Since your app is hosted on Heroku, fixing this is straightforward:
- Update your Rails production config (
config/environments/production.rb) to force SSL:config.force_ssl = true - Head to your Facebook Developer Dashboard, navigate to Products > Facebook Login > Settings, and replace your existing HTTP callback URI with the HTTPS version:
https://consiliumnsit.herokuapp.com/users/auth/facebook/callback
2. 完善Facebook应用的移动端OAuth配置
Sometimes mobile-specific settings get overlooked in the Facebook app setup:
- In the same Facebook Login settings page, make sure Client OAuth Login, Web OAuth Login, and Mobile Browser Login are all toggled on
- Double-check that the HTTPS callback URI is added to the Valid OAuth Redirect URIs list—even a tiny typo here can break the flow on mobile
3. Tweak OmniAuth settings for mobile popups
Android Chrome handles popups differently than desktop browsers, so adjusting your Devise OmniAuth config can help:
- Open
config/initializers/devise.rb, find your Facebook OmniAuth block, and adddisplay: 'popup'along with the explicit HTTPS callback URL:config.omniauth :facebook, 'YOUR_CLIENT_ID', 'YOUR_CLIENT_SECRET', scope: 'public_profile,email', display: 'popup', callback_url: 'https://consiliumnsit.herokuapp.com/users/auth/facebook/callback' - Always use Rails route helpers like
user_facebook_omniauth_authorize_pathfor your login links instead of hardcoding URLs—this avoids path mismatches on mobile
4. Clear Android Chrome's cache and cookies
Stale browser data often causes unexpected OAuth failures. Have your users try this:
- Open Android Chrome → Settings → Privacy and security → Clear browsing data
- Check "Cookies and site data" and "Cached images and files", then tap "Clear data"
5. Update the OmniAuth-Facebook gem
Your error link uses Facebook API v2.11, which is extremely outdated and no longer supported. Updating the gem will pull in the latest API version:
- Update your Gemfile:
gem 'omniauth-facebook', '~> 9.0' # Use the latest stable version - Run
bundle update omniauth-facebookto apply the change
If none of these fix the issue, have users enable Chrome's dev tools on Android (Settings → Developer options → Debug WebView) and check the console for specific errors—things like CORS blocks or redirect restrictions will show up there and help narrow down the problem.
内容的提问来源于stack exchange,提问作者user9187456

