Spring Authorization Server Redirects to HTTP when behind proxy

Viewed 74

I have a standalone spring authorization server at https://auth.foo.com with certificate configured in the spring boot application directly (no Proxy).

I have a client spring boot app using http 8080 behind a K8s Nginx Proxy. The certificate terminates on the proxy and then delivers http upstream to the spring boot app. https://client.foo.com

I have enabled the following in the client application.yaml

server:
  port: 8080
  forward-headers-strategy: native
  tomcat:
    use-relative-redirects: true
    remoteip:
      remote-ip-header: x-forwarded-for
      protocol-header: x-forwarded-proto

When navigating to the https://client.foo.com app, the relative redirects work fine, all links redirect to https.

However on successful login via https://auth.foo.com, the auth server redirects to https://client.foo.com/login/oauth2/code/foo-client-oidc?code=XXX then the client responds with a 302 but the Location header is insecure http://client.foo.com

Is there a way to force the redirect to use https in Spring Authorisation Server

Thanks in advance

0 Answers
Related