You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google App Engine Node.js应用HTTPS下Google登录redirect_uri_mismatch问题

Fixing Google Login redirect_uri_mismatch on GAE Node.js (Express) with HTTPS

I’ve run into this exact issue before with Google App Engine and Express—here’s how to fix it step by step:

The Root Cause

Google App Engine handles SSL termination at its load balancer, so your Express app actually receives HTTP traffic even when users connect via HTTPS. GAE adds the X-Forwarded-Proto header set to https to indicate the original request protocol, but Express doesn’t trust this header by default. As a result, any code generating your redirect URI uses http:// instead of https://, causing the mismatch with your OAuth client’s authorized HTTPS URI.

Solution 1: Configure Express to Trust the GAE Proxy

First, tell Express to trust the proxy headers sent by GAE. This makes Express use the X-Forwarded-Proto header to determine the correct protocol:

// Add this at the top of your Express app setup
app.set('trust proxy', true);

With this setting, req.protocol will automatically return https for HTTPS requests, so any dynamic redirect URI generation (like in Passport.js) will use the correct protocol.

Solution 2: Manually Override the Protocol (If Needed)

If for some reason the trust proxy setting doesn’t work, add a middleware to force req.protocol to https when the X-Forwarded-Proto header is present:

app.use((req, res, next) => {
  if (req.headers['x-forwarded-proto'] === 'https') {
    req.protocol = 'https';
  }
  next();
});

Solution 3: Ensure Your OAuth Callback URI Uses HTTPS

Double-check your Google Cloud Console OAuth 2.0 Client ID settings:

  • Go to APIs & Services > Credentials
  • Find your client ID, edit it
  • Add/verify the HTTPS version of your callback URI: https://www.example.com/api/auth/google/callback
  • Remove any old HTTP URIs if they’re no longer needed

For Passport.js Users (Common for Google Login)

If you’re using Passport.js for authentication, make sure your Google Strategy uses the dynamic protocol to generate the callback URL:

const GoogleStrategy = require('passport-google-oauth20').Strategy;

passport.use(new GoogleStrategy({
    clientID: process.env.GOOGLE_CLIENT_ID,
    clientSecret: process.env.GOOGLE_CLIENT_SECRET,
    // Dynamically generate the callback URL using the correct protocol
    callbackURL: (req) => `${req.protocol}://${req.get('host')}/api/auth/google/callback`
}, (accessToken, refreshToken, profile, done) => {
    // Your user authentication logic here
}));

Final Checks

  1. Deploy your updated Express app to GAE
  2. Test the Google login flow over HTTPS—you should no longer see the redirect_uri_mismatch error
  3. Verify that the redirect URI in the OAuth request (check browser dev tools > Network tab) matches the authorized HTTPS URI in your Google Cloud Console

内容的提问来源于stack exchange,提问作者npr

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:46:04