You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

认证过程中lang参数丢失问题及现有配置可行性咨询

解决认证过程中lang参数丢失的方案

不用重写大量AbstractAuthenticationFilterConfigurer相关代码,有几个轻量级的方案可以保留lang参数:

1. 扩展LoginUrlAuthenticationEntryPoint直接处理参数

这个方法最直接,只需要继承原类,重写构建跳转URL的方法,把lang参数拼接进去,不管是重定向还是转发场景都能覆盖:

public class LangPreservingLoginEntryPoint extends LoginUrlAuthenticationEntryPoint {

    public LangPreservingLoginEntryPoint(String loginFormUrl) {
        super(loginFormUrl);
    }

    // 处理重定向场景的URL拼接
    @Override
    protected String buildRedirectUrlToLoginPage(HttpServletRequest request, HttpServletResponse response, AuthenticationException authException) {
        String baseUrl = super.buildRedirectUrlToLoginPage(request, response, authException);
        return appendLangParameter(request, baseUrl);
    }

    // 处理服务器转发场景的URL拼接
    @Override
    protected String determineUrlToUseForThisRequest(HttpServletRequest request, HttpServletResponse response, AuthenticationException authException) {
        String baseUrl = super.determineUrlToUseForThisRequest(request, response, authException);
        return appendLangParameter(request, baseUrl);
    }

    // 通用的参数拼接逻辑
    private String appendLangParameter(HttpServletRequest request, String url) {
        String lang = request.getParameter("lang");
        if (lang == null || lang.isBlank()) {
            return url;
        }
        String separator = url.contains("?") ? "&" : "?";
        return url + separator + "lang=" + lang;
    }
}

然后在你的Security配置里替换默认的EntryPoint就行:

@Configuration
public class CustomSecurityConfig extends WebSecurityConfigurerAdapter {

    @Autowired
    private OAuth2SsoProperties sso;

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        // 保留你原有的其他配置...
        
        // 替换成我们自定义的EntryPoint
        RequestMatcher preferredMatcher = new AntPathRequestMatcher("/**"); // 根据你的实际需求调整匹配规则
        http.exceptionHandling()
            .defaultAuthenticationEntryPointFor(
                new LangPreservingLoginEntryPoint(sso.getLoginPath()),
                preferredMatcher
            );
    }
}

2. 自定义RedirectStrategy(仅重定向场景)

如果你只需要处理重定向的情况,可以单独自定义重定向策略,给所有重定向请求带上lang参数:

public class LangPreservingRedirectStrategy extends DefaultRedirectStrategy {

    @Override
    public void sendRedirect(HttpServletRequest request, HttpServletResponse response, String url) throws IOException {
        String lang = request.getParameter("lang");
        if (lang != null && !lang.isBlank()) {
            String separator = url.contains("?") ? "&" : "?";
            url = url + separator + "lang=" + lang;
        }
        super.sendRedirect(request, response, url);
    }
}

然后把这个策略设置到LoginUrlAuthenticationEntryPoint上:

LangPreservingLoginEntryPoint entryPoint = new LangPreservingLoginEntryPoint(sso.getLoginPath());
entryPoint.setRedirectStrategy(new LangPreservingRedirectStrategy());
// 后续配置和方案1一致

为什么这些方案更优?

这些方法都不需要修改AbstractAuthenticationFilterConfigurer的核心逻辑,只是对Spring Security的扩展点进行定制,符合开闭原则,也避免了重写大量代码带来的维护成本。

内容的提问来源于stack exchange,提问作者xiao luo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 04:15:05