Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

AdkWebServer's root->dev-ui redirect breaks behind a path-stripping reverse proxy

Aperta
#1,457 2 commenti 0 reazioni 1 assegnatario Vedi su GitHub

@hemasekhar-p ci sta già lavorando.

Dal 26/8/2026.

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

needs review

Description

AdkWebServer.addViewControllers() redirects "/" to the root-relative path "/dev-ui":

https://github.com/google/adk-java/blob/e8b1c20d10680e7ed8e936ae1ac0ab768a0b8345/dev/src/main/java/com/google/adk/web/AdkWebServer.java#L151

registry.addRedirectViewController("/", "/dev-ui");

When this app is deployed behind a reverse proxy that strips a path prefix before forwarding the request (a common pattern for platform-managed multi-tenant gateways, e.g. Kubernetes Gateway API HTTPRoute with a URLRewrite/ReplacePrefixMatch filter), the browser follows this redirect to an unprefixed path the proxy has no route for, and the dev UI 404s.

Why this can't be fixed by the app alone with standard Spring mechanisms

Spring's own reverse-proxy support (server.forward-headers-strategy=framework, which installs ForwardedHeaderFilter) is specifically designed to solve exactly this class of problem via the X-Forwarded-Prefix header — but it only works for context-relative redirect targets (ones that do not start with /). I traced this through ForwardedHeaderExtractingResponse#sendRedirect:

path = (path.startsWith(FOLDER_SEPARATOR) ? path :
        StringUtils.applyRelativePath(this.request.getRequestURI(), path));

Root-relative targets (starting with /, as "/dev-ui" does) skip the applyRelativePath branch entirely — the one place X-Forwarded-Prefix awareness would apply — so the prefix is never spliced back in, no matter how the proxy is configured.

Proposed fix

Change the redirect target to be context-relative instead of root-relative:

registry.addRedirectViewController("/", "dev-ui");

I verified this doesn't change behavior for the common local/non-proxied case: RedirectView's contextRelative handling only prepends the context path when the target starts with / (so a context-relative target like "dev-ui" is passed through as-is), and the servlet container's own relative-URL resolution for sendRedirect still resolves "dev-ui" against the current request path "/" to "/dev-ui". It does additionally allow server.forward-headers-strategy=framework + an X-Forwarded-Prefix header to correctly restore a proxy's path prefix, fixing the reverse-proxy case with zero app-specific workaround code.

I've opened a PR with this one-line fix plus the corresponding test update: (link to follow)

Environment

  • adk-java: current main (verified against commit e8b1c20)
  • Encountered while deploying a Java ADK agent behind a Kubernetes Gateway API HTTPRoute that strips a per-app path prefix
Lingua principale
Java
Stelle
1.7k
Fork
421
Merge medio
3g 8h
PR unite (30g)
36

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di google/adk-java

Tutte le issue di google/adk-java

Issue simili

Altre issue su Java

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.