Facebook登录OAuth重定向URL异常:仅域名可用,子路径无法跳转
Hey Rolf, sorry to hear you've been stuck on this all day—let's walk through the key issues you're facing and break down actionable checks to get this working:
Core Problem Recap
From what you described:
- Using the full redirect URL
https://www.ruhrlink.de/von_eigene_termine/throws a "domain not in app settings" error, but shortening it tohttps://www.ruhrlink.de/works (though it lands on the homepage instead of your targetindex.php). - Both scenarios return URLs with
?code=xyzandFBRLH_stateparameters, but requesting an Access Token still fails—even though you've added both paths to Valid OAuth Redirect URLs.
Targeted Fixes to Try
1. Nail Down Valid OAuth Redirect URLs Formatting
Facebook’s URL matching is extremely strict—even tiny mismatches will block the redirect:
- Add the full target path: Instead of just
https://www.ruhrlink.de/von_eigene_termine/, add the exact endpoint you need to land on:https://www.ruhrlink.de/von_eigene_termine/index.php. Facebook requires the redirect URI to match the exact path used in your login request. - Check trailing slashes: If your code uses
https://www.ruhrlink.de/von_eigene_termine(no trailing slash) but you added the version with a slash in settings, that’ll cause a mismatch. Ensure they’re identical. - Avoid extra parameters: Don’t include
?code=orFBRLH_statein your Valid URLs—those are appended automatically after login.
2. Verify the Exact redirect_uri Sent to Facebook
Sometimes code typos or server rewrites can alter the redirect_uri parameter sent in the initial login request:
- Open your browser’s Network DevTools, trigger the login flow, and look for the request to Facebook’s OAuth endpoint. Check the
redirect_uriquery parameter—it must exactly match one of the URLs in your Valid list. - If it’s different (e.g., missing
index.php, or has a typo in the path), fix that in your code where you construct the login URL.
3. Diagnose the Access Token Error
Don’t ignore the specific error message when requesting the Access Token—it’s your biggest clue:
- If it says
invalid_redirect_uri: Yourredirect_uriused in the token request doesn’t match the one used to get the code, or isn’t in Valid URLs. Make sure both requests use the exact same URI. - If it says
authorization_code_is_invalid: The code might be expired (Facebook codes expire in 10 minutes), or you’re using a code obtained with the short URL to request a token with the long URL (codes are tied to the redirect URI used to generate them).
4. Check Your App’s Mode
If your Facebook app is still in Development Mode, only users added as "Test Users" or "App Roles" can successfully authenticate. If regular users are testing this, switch your app to Live Mode in the Facebook Developer Dashboard.
5. Rule Out Server Rewrite Issues
Your server’s rewrite rules (Apache mod_rewrite, Nginx rewrites) might be intercepting the redirect and sending users to the homepage:
- Manually visit
https://www.ruhrlink.de/von_eigene_termine/index.php?code=test&FBRLH_state=test—if you’re redirected to the homepage, your rewrite rules are blocking the path. Adjust them to allow requests with query parameters to reachindex.php.
内容的提问来源于stack exchange,提问作者Rolf Blenn

