You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

NextAuth首次登录提示‘State cookie was missing.’,二次尝试成功求助

Google OAuth登录首次失败(State cookie缺失)二次成功问题排查求助

问题概述

点击Google OAuth登录按钮,到最后一步时出现错误,但点击错误提示中的按钮使用同一邮箱再次尝试时,登录成功,Cookie正常存储,功能恢复正常。我为这个问题折腾了近3天,几近崩溃。

服务器错误日志

[next-auth][error][OAUTH_CALLBACK_ERROR]
https://next-auth.js.org/errors#oauth_callback_error State cookie was missing. {
  error: Error [OAuthCallbackError]: State cookie was missing.
      at Object.use (/app/.next/server/app/api/auth/[...nextauth]/route.js:4:46997)
      at l (/app/.next/server/app/api/auth/[...nextauth]/route.js:4:43337)
      at async Object.c (/app/.next/server/app/api/auth/[...nextauth]/route.js:28:782)
      at async g (/app/.next/server/app/api/auth/[...nextauth]/route.js:4:26220)
      at async a (/app/.next/server/app/api/auth/[...nextauth]/route.js:28:19771)
      at async e.length.t (/app/.next/server/app/api/auth/[...nextauth]/route.js:28:21261)
      at async te.do (/app/node_modules/next/dist/compiled/next-server/app-route.runtime.prod.js:18:17826)
      at async te.handle (/app/node_modules/next/dist/compiled/next-server/app-route.runtime.prod.js:18:22492)
      at async doRender (/app/node_modules/next/dist/server/base-server.js:1455:42) {
    code: undefined
  },
  providerId: 'google',
  message: 'State cookie was missing.'
}

登录错误截图

依赖版本

next-auth@4.24.10
next@15.0.3

环境与配置说明

  • 仅生产环境出现该问题,本地开发环境正常;
  • 架构:HTTPS协议的www.example.com通过AWS ALB转发到HTTP协议的localhost:3000 NextJS服务;
  • AWS ALB已正确转发X-Forwarded-For请求头,尝试过Preserve和Append模式;
  • NextAuth的authOptions中已设置secure和trustedHost;
  • 首次登录时State已存入Cookie,但未作为参数传递到服务器,首次失败、二次成功的原因不明。

已尝试的解决方案

  • 确认环境变量配置正确(如NEXTAUTH_URL=https://www.example.com);
  • 移除代码中所有重定向逻辑。

authOptions代码

export const authOptions: NextAuthOptions = {
  providers: [
    GoogleProvider({
      clientId: process.env.GOOGLE_CLIENT_ID!,
      clientSecret: process.env.GOOGLE_CLIENT_SECRET!,
      authorization: {
        params: {
          scope: "openid email profile",
          access_type: 'offline',
          prompt: 'consent',
        },
      },
    }),
  ],
  debug: true,
  trustHost: true,
  session: {
    strategy: 'jwt',
    maxAge: 60 * 60 * 24 * 30, // 30 days
  },
  jwt: {
    maxAge: 60 * 60 * 24 * 30, // 30 days
  },
  secret: process.env.NEXTAUTH_SECRET,
  callbacks: {
    async jwt({ token, account, user }) {
      if (account) {
        token.accessToken = account.access_token;
        token.idToken = account.id_token;
        token.refreshToken = account.refresh_token;
        token.email = user?.email;
        if (account.expires_at) {
          token.accessTokenExpires = account.expires_at * 1000; // Convert to milliseconds
        } else {
          token.accessTokenExpires = Date.now() + 60 * 60 * 1000; // Default to 1 hour if expires_at is missing
        }

        trackEvent("Logging in", { email: token.email });
      }

      if (token.accessTokenExpires && Date.now() < (token.accessTokenExpires as number)) {
        return token; // Token is still valid
      }

      return await refreshAccessToken(token);
    },
    async session({ session, token }) {
      if (session.user) {
        session.accessToken = token.accessToken as string;
        session.user.email = token.email as string;
        session.idToken = token.idToken as string;
      }

      if (token.error === "RefreshAccessTokenError") {
        signOut({ callbackUrl: "/" });
      }

      return session;
    },
  },
};

求助

请问有没有架构或代码层面的其他建议?我已使用ChatGPT o1系列工具排查2天仍未解决,因首次失败、二次成功的特殊性特此单独提问,感谢解答!

内容的提问来源于stack exchange,提问作者Ankur Toshniwal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 19:41:06