spring-projects/spring-security · warning

Unable to redirect to HTTPS as no port mapping found for…

Error message

Unable to redirect to HTTPS as no port mapping found for HTTP port %s

What it means

LoginUrlAuthenticationEntryPoint.httpsUri() is asked to build an HTTPS redirect URL for the login page but PortMapper has no mapping for the current HTTP port. The entry point logs a warning and falls back to a non-HTTPS URL (or relative path), so the redirect will not be secure.

Solutions

  1. Configure a PortMapper with a mapping for your HTTP port, e.g. new PortMapperImpl(Map.of(9000, 9443)) via LoginUrlAuthenticationEntryPoint.setPortMapper()
  2. Serve the app on a standard port (8080/80) that has a default HTTPS mapping
  3. Force HTTPS externally (proxy/LB) and make the request already secure so the HTTPS redirect path is not needed

Example fix

// before
LoginUrlAuthenticationEntryPoint entryPoint = new LoginUrlAuthenticationEntryPoint("/login");
// after
entryPoint.setPortMapper(new PortMapperImpl(Map.of(9000, 9443)));
Defensive patterns

Strategy: fallback

Validate before calling

int port = request.getLocalPort();
if (portMapper.lookupHttpsPort(port) == null) {
    logger.warn("No HTTPS mapping for port " + port + "; HTTPS redirect will be skipped");
}

Prevention

When it happens

Trigger: HTTP request on a port not listed in the configured PortMapper (default: 80->443, 8080->8443, etc.) while the entry point requires secure redirect (portResolver/portMapper configured or requiresChannel http() in use).

Common situations: App behind a proxy serving on a custom port like 9000 or 8081; running on a nonstandard local dev port; missing setPortMapper()/setPortResolver() customization.

Understand the failure class

Background: "Invalid value" and "allowed values are" config errors: what your library rejected and how to fix it — this error's family across 41 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/d39c63d085409c92. Report an issue: GitHub.

Appendix: source

Thrown at web/src/main/java/org/springframework/security/web/authentication/LoginUrlAuthenticationEntryPoint.java:199

		String loginForm = determineUrlToUseForThisRequest(request, response, authException);
		if (UrlUtils.isAbsoluteUrl(loginForm)) {
			return loginForm;
		}
		if (requiresRewrite(request)) {
			return httpsUri(request, loginForm);
		}
		return this.favorRelativeUris ? loginForm : absoluteUri(request, loginForm).getUrl();
	}

	private boolean requiresRewrite(HttpServletRequest request) {
		return this.forceHttps && "http".equals(request.getScheme());
	}

	private String httpsUri(HttpServletRequest request, String path) {
		int serverPort = getServerPort(request);
		Integer httpsPort = this.portMapper.lookupHttpsPort(serverPort);
		if (httpsPort == null) {
			logger.warn(LogMessage.format("Unable to redirect to HTTPS as no port mapping found for HTTP port %s",
					serverPort));
			return this.favorRelativeUris ? path : absoluteUri(request, path).getUrl();
		}
		RedirectUrlBuilder builder = absoluteUri(request, path);
		builder.setScheme("https");
		builder.setPort(httpsPort);
		return builder.getUrl();
	}

	private RedirectUrlBuilder absoluteUri(HttpServletRequest request, String path) {
		RedirectUrlBuilder urlBuilder = new RedirectUrlBuilder();
		urlBuilder.setScheme(request.getScheme());
		urlBuilder.setServerName(request.getServerName());
		urlBuilder.setPort(getServerPort(request));
		urlBuilder.setContextPath(request.getContextPath());
		urlBuilder.setPathInfo(path);
		return urlBuilder;
	}

View on GitHub (pinned to 96852e8860)