You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

生产环境登录Token未定义致401未授权问题求助

生产环境认证Token丢失导致401错误的排查与解决

问题现象

  • 开发环境登录后Token有效,控制台可正常查看
  • 生产环境下isAuthenticated中间件中req.cookies.token始终为undefined
  • 生产构建版本请求接口返回401 (Unauthorized),开发环境无此问题

相关认证中间件代码

import jwt from "jsonwebtoken";

const isAuthenticated = async (req, res, next) => { 
  try { 
    // Retrieve the token from cookies 
    const token = req.cookies.token; 

    console.log("token from isAuth",token); // 生产环境此处输出undefined

    // Check if the token is missing
    if (!token) {
        return res.status(401).json({ message: "User not authenticated", success: false });
    }
    
    // Verify the token
    const decode = await jwt.verify(token, process.env.SECRET_KEY);
    
    // Check if the token could not be decoded
    if (!decode) {
        return res.status(403).json({ message: "Invalid token", success: false });
    }

    // Attach user ID to the request object for future middleware/controllers
    req.id = decode.userId;

    // Proceed to the next middleware
    next();

  } catch (error) {
    console.error("Authentication error:", error);

    // Send a 500 Internal Server Error response for any unexpected errors
    return res.status(500).json({ message: "Server error during authentication", success: false });
  }
};

排查与解决步骤

1. 检查Cookie的生产环境配置

后端设置Cookie时,生产环境需注意以下参数:

  • domain:必须设置为你的实际业务域名(如.example.com),不要用开发环境的localhost
  • secure:如果生产环境用HTTPS,必须设为true,否则浏览器不会在HTTPS请求中携带Cookie
  • sameSite:建议设为Lax或None(配合secure: true),避免跨域请求时Cookie被拦截

2. 确认前端请求携带Cookie

前端发送请求时必须配置携带Cookie:

  • Axios:添加withCredentials: true
  • Fetch:添加credentials: 'include'选项

3. 验证Cookie解析中间件是否正确挂载

确保cookie-parser在isAuthenticated之前被挂载,否则req.cookies为空:

const cookieParser = require('cookie-parser');
app.use(cookieParser());

4. 核对环境变量与Token签发逻辑

  • 检查生产环境的SECRET_KEY是否和开发环境一致,避免签发生成的Token无法被验证
  • 确认Token的过期时间配置合理,排除因Token提前过期导致的问题

5. 排查反向代理/CDN配置

如果用了Nginx等反向代理或CDN:

  • Nginx需配置proxy_set_header Cookie $http_cookie;,确保Cookie被正确传递到后端
  • 检查CDN是否缓存了静态资源,导致请求未携带最新的登录Cookie

内容的提问来源于stack exchange,提问作者Duraimurugan H

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 23:51:15