使用fastapi-users集成Google OAuth2访问受保护路由遇401未授权
排查Google OAuth2 + FastAPI-Users 401未授权问题
以下是几个关键排查方向:
1. 检查JWT配置一致性
生成和验证令牌的JWT密钥、算法必须完全一致。检查代码中:
- 创建
JWTStrategy时的secret参数 - 算法(默认是HS256)是否和令牌解码时使用的一致
如果密钥不匹配,令牌会直接验证失败返回401。
2. 确认受保护路由的依赖项
确保受保护路由使用了正确的CurrentUser依赖,示例代码:
from fastapi import Depends from fastapi_users import FastAPIUsers from your_app_module import fastapi_users, User @app.get("/authenticated-route") async def authenticated_route(user: User = Depends(fastapi_users.current_user())): return {"message": f"Hello {user.email}"}
默认情况下current_user()要求用户处于激活状态,若需允许未激活用户访问,可改为current_user(active=False)。
3. 验证令牌受众(Audience)
你的令牌中aud字段为["fastapi-users:auth"],需确保JWT策略配置了完全匹配的受众:
from fastapi_users.authentication import JWTStrategy def get_jwt_strategy() -> JWTStrategy: return JWTStrategy( secret=SECRET_KEY, lifetime_seconds=3600, audience=["fastapi-users:auth"], # 必须与令牌中的aud字段一致 )
受众不匹配会导致令牌验证失败。
4. 检查用户激活状态
FastAPI-Users默认要求用户处于激活状态才能访问受保护路由,OAuth注册的用户可能默认未激活:
- 查看数据库中用户的
is_active字段是否为True - 可在OAuth回调逻辑中自动激活用户,示例:
# 重写OAuth回调方法自动激活用户 @fastapi_users.oauth_router.post("/callback") async def oauth_callback(request: Request, db: AsyncSession = Depends(get_db)): user = await super().oauth_callback(request, db) if not user.is_active: user.is_active = True await user.save() return user
5. 检查Authorization头格式
确保请求头格式完全正确:
- 头名称为
Authorization(注意大小写) - 值为
Bearer+ 令牌,中间有且仅有一个空格,例如:Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
可通过curl命令快速验证:
curl -H "Authorization: Bearer YOUR_ACCESS_TOKEN" http://127.0.0.1:8000/authenticated-route
内容的提问来源于stack exchange,提问作者user8724769
相关产品推荐
相关产品推荐

