You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot代码配置解决重定向时HTTPS转HTTP问题

Fixing HTTPS to HTTP Redirect Issue in Spring Boot with Code-Based Bean Config

Hey there! I totally get your frustration with the HTTPS → HTTP redirect problem when using redirect:/home in your @Controller—XML config can feel pretty outdated when you're comfortable with Java-based setups. Let's solve this using code-configured beans instead, no XML required.

Why This Happens

Most of the time, this issue pops up when your Spring Boot app is running behind a reverse proxy (like Nginx, Apache, or a cloud load balancer). The proxy handles the HTTPS termination, so your app only sees HTTP requests internally. When you return a redirect, Spring Boot doesn't realize the original request was over HTTPS, so it generates an HTTP URL.

Spring Boot provides a built-in filter that processes headers like X-Forwarded-Proto (sent by your proxy) to tell the app the original request scheme. This works across all embedded containers (Tomcat, Jetty, Undertow).

Create a configuration class to register the filter:

import org.springframework.boot.web.servlet.FilterRegistrationBean;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.filter.ForwardedHeaderFilter;

@Configuration
public class WebConfig {

    @Bean
    public FilterRegistrationBean<ForwardedHeaderFilter> forwardedHeaderFilter() {
        FilterRegistrationBean<ForwardedHeaderFilter> registrationBean = new FilterRegistrationBean<>();
        registrationBean.setFilter(new ForwardedHeaderFilter());
        // Set high priority to ensure this filter runs before others
        registrationBean.setOrder(0);
        return registrationBean;
    }
}

Important Note: Make sure your reverse proxy is configured to send the required headers. For example, in Nginx, add these lines to your location block:

proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Host $host;

This tells Spring Boot the original request used HTTPS.

Solution 2: Tomcat-Specific RemoteIpValve

If you're using Tomcat as your embedded container, you can configure a RemoteIpValve to achieve the same result. This valve parses the X-Forwarded-Proto header and updates the request's scheme to HTTPS.

Create a Tomcat configuration class:

import org.springframework.boot.web.embedded.tomcat.TomcatServletWebServerFactory;
import org.springframework.boot.web.server.WebServerFactoryCustomizer;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;

@Configuration
public class TomcatConfig {

    @Bean
    public WebServerFactoryCustomizer<TomcatServletWebServerFactory> tomcatRemoteIpValveCustomizer() {
        return factory -> {
            factory.addEngineValves(new org.apache.catalina.valves.RemoteIpValve());
        };
    }
}

Again, ensure your proxy sends the X-Forwarded-Proto header for this to work.

Testing the Fix

After adding either of these configurations, deploy your app and test the redirect:

  1. Access your endpoint over HTTPS.
  2. Check the redirect URL in your browser's network tab—it should now use HTTPS instead of HTTP.

内容的提问来源于stack exchange,提问作者Ayo K

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 06:16:18