Spring Boot代码配置解决重定向时HTTPS转HTTP问题
Hey there! I totally get your frustration with the HTTPS → HTTP redirect problem when using redirect:/home in your @Controller—XML config can feel pretty outdated when you're comfortable with Java-based setups. Let's solve this using code-configured beans instead, no XML required.
Why This Happens
Most of the time, this issue pops up when your Spring Boot app is running behind a reverse proxy (like Nginx, Apache, or a cloud load balancer). The proxy handles the HTTPS termination, so your app only sees HTTP requests internally. When you return a redirect, Spring Boot doesn't realize the original request was over HTTPS, so it generates an HTTP URL.
Solution 1: Use ForwardedHeaderFilter (Recommended)
Spring Boot provides a built-in filter that processes headers like X-Forwarded-Proto (sent by your proxy) to tell the app the original request scheme. This works across all embedded containers (Tomcat, Jetty, Undertow).
Create a configuration class to register the filter:
import org.springframework.boot.web.servlet.FilterRegistrationBean; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.web.filter.ForwardedHeaderFilter; @Configuration public class WebConfig { @Bean public FilterRegistrationBean<ForwardedHeaderFilter> forwardedHeaderFilter() { FilterRegistrationBean<ForwardedHeaderFilter> registrationBean = new FilterRegistrationBean<>(); registrationBean.setFilter(new ForwardedHeaderFilter()); // Set high priority to ensure this filter runs before others registrationBean.setOrder(0); return registrationBean; } }
Important Note: Make sure your reverse proxy is configured to send the required headers. For example, in Nginx, add these lines to your location block:
proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header X-Forwarded-Host $host;
This tells Spring Boot the original request used HTTPS.
Solution 2: Tomcat-Specific RemoteIpValve
If you're using Tomcat as your embedded container, you can configure a RemoteIpValve to achieve the same result. This valve parses the X-Forwarded-Proto header and updates the request's scheme to HTTPS.
Create a Tomcat configuration class:
import org.springframework.boot.web.embedded.tomcat.TomcatServletWebServerFactory; import org.springframework.boot.web.server.WebServerFactoryCustomizer; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; @Configuration public class TomcatConfig { @Bean public WebServerFactoryCustomizer<TomcatServletWebServerFactory> tomcatRemoteIpValveCustomizer() { return factory -> { factory.addEngineValves(new org.apache.catalina.valves.RemoteIpValve()); }; } }
Again, ensure your proxy sends the X-Forwarded-Proto header for this to work.
Testing the Fix
After adding either of these configurations, deploy your app and test the redirect:
- Access your endpoint over HTTPS.
- Check the redirect URL in your browser's network tab—it should now use HTTPS instead of HTTP.
内容的提问来源于stack exchange,提问作者Ayo K

