Facebook Login要求HTTPS:如何在ASP.NET MVC配置HTTPS重定向URL?
Got it, let's get this sorted out—Facebook's strict about using HTTPS for redirect URIs these days, so we need to tackle both the app settings and your system's URL generation to fix this.
Step 1: Update Facebook App's Allowed Redirect URIs
First, make sure your Facebook Developer Console is set up to accept HTTPS URLs:
- Head to your Facebook开发者后台 → Select your target app → Navigate to Products > Facebook Login > Settings
- Locate the Valid OAuth Redirect URIs section
- Remove any existing HTTP entries (like
http://example.com/signin-facebook) and add the HTTPS version:https://example.com/signin-facebook - Save your changes—this is non-negotiable, because Facebook will reject any redirect URI that isn't listed here, even if it's HTTPS.
Step 2: Fix Your System's URL Generation Logic
Next, adjust how your system builds the OAuth request URL:
- If you're manually constructing the URL (like in your example), replace
http://withhttps://in theredirect_uriparameter. Also, delete any extra spaces around the value—your example has a space afterredirect_uri=which will break parameter parsing.- ❌ Bad:
redirect_uri= http://example.com/signin-facebook - ✅ Good:
redirect_uri=https://example.com/signin-facebook
- ❌ Bad:
- If you're using an SDK (like for Node.js, ASP.NET, etc.), find the configuration option that sets the redirect URI. For example:
- In ASP.NET Core, set
options.CallbackPathto a relative path and ensure your app enables HTTPS redirection withUseHttpsRedirection()in Startup.cs - In Node.js with Passport.js, update the
callbackURLin the Facebook strategy to the full HTTPS address.
- In ASP.NET Core, set
Step 3: Verify Your Server's HTTPS Setup
Double-check that your website is running with a valid SSL certificate. If your server isn't serving HTTPS content, even if you set the redirect URI to HTTPS, users will hit security warnings—and Facebook might flag the redirect as unsafe.
Test the Generated URL
After making these changes, generate a new OAuth request URL and inspect the redirect_uri parameter. It should look like this:
https://www.facebook.com/v2.8/dialog/oauth?response_type=code&client_id=255162614498922&redirect_uri=https://example.com/signin-facebook&scope=&state=-x4AVtFysadfadsfsadROH6E1QJ82gv4e4j48s32K5xbmqlF-JFbE5Y2Tx_MAdSquCP6CjZjic8Ye6gwasdfdfask3PXWkyxS42Ajpks9IuumDOl6CUJsadfafsasfdasdfbfpEFUDyxJUR3fARlWc83Lysadffd...
That should resolve the issue! Once both the Facebook app settings and your system's URL generation are updated to HTTPS, the redirect will work as intended.
内容的提问来源于stack exchange,提问作者Luke

