Google App Engine Node.js应用HTTPS下Google登录redirect_uri_mismatch问题
redirect_uri_mismatch on GAE Node.js (Express) with HTTPS I’ve run into this exact issue before with Google App Engine and Express—here’s how to fix it step by step:
The Root Cause
Google App Engine handles SSL termination at its load balancer, so your Express app actually receives HTTP traffic even when users connect via HTTPS. GAE adds the X-Forwarded-Proto header set to https to indicate the original request protocol, but Express doesn’t trust this header by default. As a result, any code generating your redirect URI uses http:// instead of https://, causing the mismatch with your OAuth client’s authorized HTTPS URI.
Solution 1: Configure Express to Trust the GAE Proxy
First, tell Express to trust the proxy headers sent by GAE. This makes Express use the X-Forwarded-Proto header to determine the correct protocol:
// Add this at the top of your Express app setup app.set('trust proxy', true);
With this setting, req.protocol will automatically return https for HTTPS requests, so any dynamic redirect URI generation (like in Passport.js) will use the correct protocol.
Solution 2: Manually Override the Protocol (If Needed)
If for some reason the trust proxy setting doesn’t work, add a middleware to force req.protocol to https when the X-Forwarded-Proto header is present:
app.use((req, res, next) => { if (req.headers['x-forwarded-proto'] === 'https') { req.protocol = 'https'; } next(); });
Solution 3: Ensure Your OAuth Callback URI Uses HTTPS
Double-check your Google Cloud Console OAuth 2.0 Client ID settings:
- Go to APIs & Services > Credentials
- Find your client ID, edit it
- Add/verify the HTTPS version of your callback URI:
https://www.example.com/api/auth/google/callback - Remove any old HTTP URIs if they’re no longer needed
For Passport.js Users (Common for Google Login)
If you’re using Passport.js for authentication, make sure your Google Strategy uses the dynamic protocol to generate the callback URL:
const GoogleStrategy = require('passport-google-oauth20').Strategy; passport.use(new GoogleStrategy({ clientID: process.env.GOOGLE_CLIENT_ID, clientSecret: process.env.GOOGLE_CLIENT_SECRET, // Dynamically generate the callback URL using the correct protocol callbackURL: (req) => `${req.protocol}://${req.get('host')}/api/auth/google/callback` }, (accessToken, refreshToken, profile, done) => { // Your user authentication logic here }));
Final Checks
- Deploy your updated Express app to GAE
- Test the Google login flow over HTTPS—you should no longer see the
redirect_uri_mismatcherror - Verify that the redirect URI in the OAuth request (check browser dev tools > Network tab) matches the authorized HTTPS URI in your Google Cloud Console
内容的提问来源于stack exchange,提问作者npr

