Spring Boot+Scala应用HTTPS下Google登录静默跳转/login?error问题
Scala + Spring Boot Google登录HTTPS环境重定向错误排查与解决
问题核心现象
- 本地HTTP环境下Google登录流程正常
- 通过ngrok部署的HTTPS环境中,Google登录后会静默重定向至
https://9ec1-122-169-40-86.ngrok-free.app/login?error,无前端详细错误提示 - 错误日志明确抛出
OAuth2AuthenticationException: [invalid_redirect_uri_parameter]
已完成排查
- Google开发者控制台已注册正确的重定向URI
- 已引入OAuth2客户端所需依赖
application.properties中spring.security.oauth2.client相关配置正确login/oauth2/code/google端点可正常访问- 开启Spring Security调试日志,仅捕获到重定向至错误页的记录,无更多细节
关键错误日志
org.springframework.security.oauth2.core.OAuth2AuthenticationException: [invalid_redirect_uri_parameter] at org.springframework.security.oauth2.client.authentication.OAuth2LoginAuthenticationProvider.authenticate(OAuth2LoginAuthenticationProvider.java:110) ~[spring-security-oauth2-client-5.1.5.RELEASE.jar:5.1.5.RELEASE] at org.springframework.security.authentication.ProviderManager.authenticate(ProviderManager.java:175) ~[spring-security-core-5.1.5.RELEASE.jar:5.1.5.RELEASE] at org.springframework.security.oauth2.client.web.OAuth2LoginAuthenticationFilter.attemptAuthentication(OAuth2LoginAuthenticationFilter.java:186) ~[spring-security-oauth2-client-5.1.5.RELEASE.jar:5.1.5.RELEASE]
org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java.a.SimpleUrlAuthenticationFailureHandler : Redirecting to /login?error 2025-07-03 18:56:55.845 DEBUG 49291 --- [nio-8080-exec-3] o.s.s.web.DefaultRedirectStrategy : Redirecting to '/login?error' 2025-07-03 18:56:56.015 DEBUG 49291 --- [nio-8080-exec-4] o.s.s.web.util.matcher.OrRequestMatcher : No matches found 80-exec-4] o.s.security.web.FilterChainProxy : /login?error at position 9 of 13 in additional filter chain; firing Filter: 'RememberMeAuthenticationFilter' 2025-07-03 18:56:56.016 DEBUG 49291 --- [nio-8080-exec-4] o.s.security.web.FilterChainProxy : /login?error at position 10 of 13 in additional filter chain; firing Filter: 'AnonymousAuthenticationFilter' 2025-07-03 18:56:56.016 DEBUG 49291 --- [nio-8080-exec-4] o.s.s.w.a.AnonymousAuthenticationFilter : Populated SecurityContextHolder with anonymous token: s.s.w.c.SecurityContextPersistenceFilter : SecurityContextHolder now cleared, as request processing completed
针对性解决方案
1. 验证重定向URI的HTTPS格式
Google OAuth2对重定向URI的协议严格校验,确保在Google开发者控制台中注册的URI是完整HTTPS格式,例如:https://9ec1-122-169-40-86.ngrok-free.app/login/oauth2/code/google
- 不要遗漏
https://前缀 - 确认ngrok域名与注册的完全一致(包括随机生成的前缀)
2. 强制Spring Boot识别HTTPS代理头
ngrok作为反向代理,会向后端传递X-Forwarded-Proto等头信息,但旧版Spring Security(如你使用的5.1.5.RELEASE)默认不会识别这些头。需要在配置中开启代理支持:
方式一:修改application.properties
server.use-forward-headers=true server.tomcat.remote-ip-header=x-forwarded-for server.tomcat.protocol-header=x-forwarded-proto
方式二:配置SecurityFilterChain(Scala代码)
import org.springframework.security.config.annotation.web.builders.HttpSecurity import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity import org.springframework.security.web.SecurityFilterChain @EnableWebSecurity class SecurityConfig { def filterChain(http: HttpSecurity): SecurityFilterChain = { http .oauth2Login() .and() .authorizeRequests() .anyRequest() .authenticated() .and() .requiresChannel() .requestMatchers("/login/oauth2/code/google") .requiresSecure() // 确保回调端点强制使用HTTPS .and() .forwardedHeaders() // 启用转发头识别 .build() } }
3. 检查OAuth2客户端配置的回调URI
确保application.properties中的回调URI与Google控制台完全匹配:
spring.security.oauth2.client.registration.google.redirect-uri=https://9ec1-122-169-40-86.ngrok-free.app/login/oauth2/code/google
- 避免使用相对路径(如
/login/oauth2/code/google),在代理环境下可能导致Spring生成错误的绝对URI
4. 清除OAuth2客户端缓存
Google开发者控制台修改重定向URI后,可能存在缓存问题:
- 重启Spring Boot应用
- 在Google开发者控制台中重新生成客户端密钥,更新至
application.properties
5. 升级Spring Security版本
你当前使用的Spring Security 5.1.5.RELEASE版本较旧,对HTTPS代理场景的支持不完善。建议升级至5.3.x及以上版本,能更好地处理反向代理环境下的URI解析问题。
内容的提问来源于stack exchange,提问作者Prathamesh Khadake
相关产品推荐
相关产品推荐

