Grails 2.2.5搭配Shiro插件(v1.2.1):非标准端口引发问题
Hey there, let’s walk through the most likely causes and fixes for the odd behavior you’re seeing after switching your Nginx proxy to listen on 8070 (HTTP) and 8443 (HTTPS) instead of the standard 80/443 ports. Since your app worked fine for years before this change, the issues are almost certainly tied to how the new ports interact with Shiro’s session/cookie handling and reverse proxy headers.
Top Areas to Investigate
1. Shiro Cookie Configuration Mismatch
Shiro relies heavily on cookies for session management and remember-me functionality. If your Shiro config hardcodes the old 80/443 ports for cookies, the browser won’t send those cookies to the new ports, leading to unexpected auth failures or session drops.
Check your Shiro configuration (usually in grails-app/conf/ShiroConfig.groovy) for cookie settings like:
securityManager { rememberMeManager.cookie.port = 443 // Hardcoded old port? sessionManager.sessionIdCookie.port = 80 // Same issue here }
Remove the hardcoded port property entirely (let the browser use the request port automatically) or update it to match 8070/8443. Also verify cookieDomain and cookiePath don’t have any port-specific restrictions.
2. Nginx Reverse Proxy Header Issues
Nginx needs to pass accurate request metadata to your Grails app so Shiro can correctly resolve the real request protocol and port. If these headers are missing or incorrect, Shiro might generate URLs with the old ports, or reject requests because it thinks they’re coming from an untrusted source.
Update your Nginx location block for the Grails app to include these headers:
location / { proxy_pass http://your-grails-app-ip:8080; // Adjust to your app's internal port proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Port $server_port; proxy_set_header Host $host:$server_port; // Critical for port-aware apps }
Also, make sure your Grails Config.groovy has the updated serverURL matching the new ports:
grails.serverURL = "https://your-domain.com:8443"
3. Hardcoded Port Rules in Shiro Filters
Double-check your ShiroFilters.groovy for any filter chains that explicitly reference the old 80/443 ports. For example:
"/admin/**" = "authc, port[443]" // This would block access on 8443
Replace hardcoded ports with dynamic values or remove the port constraint if it’s no longer necessary.
4. Stale Browser Cookies
Users’ browsers might still have cached cookies tied to the old 80/443 ports. These won’t be sent when accessing the app on 8070/8443, leading to session issues. Advise testing with an incognito window first, or update your Shiro cookie configuration to use a new name (e.g., change rememberMeCookie.name from rememberMe to rememberMeNew) to force browsers to fetch fresh cookies.
5. Apache/Nginx Port Routing Conflicts
Even though you’ve assigned separate ports, confirm that incoming requests are actually reaching Nginx on 8070/8443 and not being intercepted by Apache. Run a test with curl to verify:
curl -v https://your-domain.com:8443/health-check // Replace with a test endpoint
Check the response headers to ensure the Server header reflects Nginx, and that the app returns the expected response.
Next Steps
Start with the Nginx header fixes and Grails serverURL update—those are the most common offenders when port changes break Shiro-based auth. If you see specific error messages (like "Session expired" or "Unauthorized" when you should have access), share those details and we can drill deeper.
内容的提问来源于stack exchange,提问作者John Moore

