{"record":{"id":"d39c63d085409c92","repo":"spring-projects/spring-security","slug":"unable-to-redirect-to-https-as-no-port-mapping-fou","errorCode":null,"errorMessage":"Unable to redirect to HTTPS as no port mapping found for HTTP port %s","messagePattern":"Unable to redirect to HTTPS as no port mapping found for HTTP port (.+?)","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"web/src/main/java/org/springframework/security/web/authentication/LoginUrlAuthenticationEntryPoint.java","lineNumber":199,"sourceCode":"\t\tString loginForm = determineUrlToUseForThisRequest(request, response, authException);\n\t\tif (UrlUtils.isAbsoluteUrl(loginForm)) {\n\t\t\treturn loginForm;\n\t\t}\n\t\tif (requiresRewrite(request)) {\n\t\t\treturn httpsUri(request, loginForm);\n\t\t}\n\t\treturn this.favorRelativeUris ? loginForm : absoluteUri(request, loginForm).getUrl();\n\t}\n\n\tprivate boolean requiresRewrite(HttpServletRequest request) {\n\t\treturn this.forceHttps && \"http\".equals(request.getScheme());\n\t}\n\n\tprivate String httpsUri(HttpServletRequest request, String path) {\n\t\tint serverPort = getServerPort(request);\n\t\tInteger httpsPort = this.portMapper.lookupHttpsPort(serverPort);\n\t\tif (httpsPort == null) {\n\t\t\tlogger.warn(LogMessage.format(\"Unable to redirect to HTTPS as no port mapping found for HTTP port %s\",\n\t\t\t\t\tserverPort));\n\t\t\treturn this.favorRelativeUris ? path : absoluteUri(request, path).getUrl();\n\t\t}\n\t\tRedirectUrlBuilder builder = absoluteUri(request, path);\n\t\tbuilder.setScheme(\"https\");\n\t\tbuilder.setPort(httpsPort);\n\t\treturn builder.getUrl();\n\t}\n\n\tprivate RedirectUrlBuilder absoluteUri(HttpServletRequest request, String path) {\n\t\tRedirectUrlBuilder urlBuilder = new RedirectUrlBuilder();\n\t\turlBuilder.setScheme(request.getScheme());\n\t\turlBuilder.setServerName(request.getServerName());\n\t\turlBuilder.setPort(getServerPort(request));\n\t\turlBuilder.setContextPath(request.getContextPath());\n\t\turlBuilder.setPathInfo(path);\n\t\treturn urlBuilder;\n\t}","sourceCodeStart":181,"sourceCodeEnd":217,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/web/src/main/java/org/springframework/security/web/authentication/LoginUrlAuthenticationEntryPoint.java#L181-L217","documentation":"LoginUrlAuthenticationEntryPoint.httpsUri() is asked to build an HTTPS redirect URL for the login page but PortMapper has no mapping for the current HTTP port. The entry point logs a warning and falls back to a non-HTTPS URL (or relative path), so the redirect will not be secure.","triggerScenarios":"HTTP request on a port not listed in the configured PortMapper (default: 80->443, 8080->8443, etc.) while the entry point requires secure redirect (portResolver/portMapper configured or requiresChannel http() in use).","commonSituations":"App behind a proxy serving on a custom port like 9000 or 8081; running on a nonstandard local dev port; missing setPortMapper()/setPortResolver() customization.","solutions":["Configure a PortMapper with a mapping for your HTTP port, e.g. new PortMapperImpl(Map.of(9000, 9443)) via LoginUrlAuthenticationEntryPoint.setPortMapper()","Serve the app on a standard port (8080/80) that has a default HTTPS mapping","Force HTTPS externally (proxy/LB) and make the request already secure so the HTTPS redirect path is not needed"],"exampleFix":"// before\nLoginUrlAuthenticationEntryPoint entryPoint = new LoginUrlAuthenticationEntryPoint(\"/login\");\n// after\nentryPoint.setPortMapper(new PortMapperImpl(Map.of(9000, 9443)));","handlingStrategy":"fallback","validationCode":"int port = request.getLocalPort();\nif (portMapper.lookupHttpsPort(port) == null) {\n    logger.warn(\"No HTTPS mapping for port \" + port + \"; HTTPS redirect will be skipped\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Customize LoginUrlAuthenticationEntryPoint.setPortMapper() for every nonstandard port you serve on","Prefer standard 8080->8443 / 80->443 port pairs in dev and prod","Terminate TLS at a proxy and use ForwardedHeaderFilter so requests are already secure"],"tags":["https","redirect","port-mapping","spring-security"],"backgroundTag":"invalid-config-value","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}