You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Actix-Web JWT中间件失效求助:受保护端点无令牌仍可访问

问题分析与解决方案

你的JWT中间件未生效的核心原因是路由配置方式错误,Actix-web中单个路由的中间件需要通过web::resource来包裹,而非直接在web::get()后调用wrap。同时也需要验证verify_jwt函数的正确性。

1. 修正路由配置

将单个路由的中间件配置改为web::resource包裹的形式,确保中间件被正确应用到目标路由:

pub fn route(cfg: &mut web::ServiceConfig, state: web::Data<AppState>) {
    cfg.service(
        web::scope("/api/v1/customers")
            .route("/register", web::post().to(create_customer))
            .route("/login", web::post().to(signin_customer))
            // 改用resource包裹路由并添加中间件
            .service(
                web::resource("/block/{id}")
                    .wrap(JwtAuthMiddleware::new(state.clone()))
                    .route(web::get().to(block_customer_controller))
            )
    );
}

2. 验证verify_jwt函数的正确性

确保verify_jwt函数在以下场景下正确返回错误:

  • 请求中没有携带Authorization头
  • Authorization头格式不正确(比如缺少Bearer前缀)
  • JWT令牌签名无效、过期或格式错误

示例verify_jwt的正确实现框架(供参考):

use actix_web::HttpRequest;
use jsonwebtoken::{decode, Validation, DecodingKey};
use crate::AppState;

pub async fn verify_jwt(req: &HttpRequest, state: &web::Data<AppState>) -> Result<YourClaimsType, jsonwebtoken::errors::Error> {
    // 提取Authorization头
    let auth_header = req.headers().get("Authorization")
        .ok_or(jsonwebtoken::errors::ErrorKind::InvalidToken)?
        .to_str()?;
    
    // 验证Bearer前缀
    let token = auth_header.strip_prefix("Bearer ")
        .ok_or(jsonwebtoken::errors::ErrorKind::InvalidToken)?;
    
    // 解码并验证JWT
    decode::<YourClaimsType>(
        token,
        &DecodingKey::from_secret(state.jwt_secret.as_bytes()),
        &Validation::default()
    ).map(|data| data.claims)
}

3. 额外检查点

  • 确认AppState中已正确注入JWT密钥,且密钥与生成令牌时使用的一致
  • 测试时使用无令牌或无效令牌请求/api/v1/customers/block/{id},确认返回401 Unauthorized
  • 若使用Actix-web 4.x版本,确保中间件的Transform和Service实现符合版本要求(你的代码看起来是兼容4.x的)

内容的提问来源于stack exchange,提问作者EmmaWedi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 22:40:21