You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Backstage插件默认安全模型禁用及Guest用户Token获取问题求助

解决Backstage插件"Illegal token"认证错误的方案

1. 调整路由注册顺序

Backstage的认证策略按注册先后顺序生效,若先挂载路由再添加认证策略,策略不会对已挂载的路由生效。必须先调用addAuthPolicy,再绑定插件路由:

// 正确顺序:先添加认证策略
httpRouter.addAuthPolicy({
  path: '/api/newplugin-backend/applications',
  allow: 'unauthenticated',
});

// 再挂载插件路由
httpRouter.use(await createRouter({
  httpAuth,
  userInfo,
  logger,
}));

2. 确保路径匹配准确

如果接口包含子路径(比如/api/newplugin-backend/applications/123),需要用通配符*匹配所有子路径,否则策略仅匹配精确路径:

httpRouter.addAuthPolicy({
  path: '/api/newplugin-backend/applications/*',
  allow: 'unauthenticated',
});

同时检查路径大小写、是否包含多余斜杠,确保和请求URL完全匹配。

3. 修正插件内部的认证调用

如果createRouter内部主动调用了httpAuth.credentials(),即使外部设置了unauthenticated策略,内部的强制认证逻辑仍会触发错误。需在调用时显式允许匿名访问:

// 插件内部获取凭证时添加允许匿名参数
const credentials = await httpAuth.credentials({ allow: 'unauthenticated' });

4. 检查模块注册方式的正确性

如果插件通过createBackendModule注册,确保认证策略在模块的registerInit阶段添加,而非路由内部:

export default createBackendModule({
  pluginId: 'newplugin-backend',
  moduleId: 'default',
  register(reg) {
    reg.registerInit({
      deps: { 
        httpRouter: coreServices.httpRouter,
        httpAuth: coreServices.httpAuth,
        userInfo: coreServices.userInfo,
        logger: coreServices.logger
      },
      async init({ httpRouter, httpAuth, userInfo, logger }) {
        // 先添加认证策略
        httpRouter.addAuthPolicy({
          path: '/api/newplugin-backend/applications/*',
          allow: 'unauthenticated',
        });
        // 再挂载路由
        httpRouter.use(await createRouter({
          httpAuth,
          userInfo,
          logger,
        }));
      },
    });
  },
});

5. 清除请求中的无效Token

若测试时浏览器缓存了过期或无效的Authorization token,即使设置了匿名访问,Backstage仍会尝试解析并报错。可通过以下方式解决:

  • 使用无痕窗口测试接口
  • 手动移除请求头中的Authorization字段

内容的提问来源于stack exchange,提问作者rewa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 08:15:56