NextAuth出现JWEDecryptionFailed解密失败错误,求解决方法及原因
问题:NextAuth结合GitHub登录时出现JWEDecryptionFailed错误
相关代码与配置
[...nextauth]/route.js 文件
import { User } from "@/lib/models"; import { connectToDb } from "@/lib/utils"; import NextAuth from "next-auth"; import GitHubProvider from "next-auth/providers/github"; export const authOptions = { secret:process.env.AUTH_SECRET, providers:[ GitHubProvider({ clientId: process.env.GITHUB_ID, clientSecret: process.env.GITHUB_SECRET, }), ], callbacks:{ async signIn({user, account, profile}) { // console.log(user, account, profile); if (account.provider === "github") { connectToDb() try { const user = await User.findOne({email:profile.email}); if (!user) { const newUser = new User({ username:profile.login, email:profile.email, image:profile.avatar_url, password:"123456", }); await newUser.save(); } } catch (error) { console.log(error); return false; } return true; } } }, }; export const handlers = NextAuth(authOptions); export {handlers as GET, handlers as POST};
.env 文件
#TERMINAL INPUT >> openssl rand -base64 32 AUTH_SECRET = aISfOz91Gp66KGHMIUsDI63z+56dv7yjIr+vN96IkHE= AUTH_URL = http://localhost:3000/api/auth
错误信息
[next-auth][error][JWT_SESSION_ERROR] decryption operation failed { message: 'decryption operation failed', stack: 'JWEDecryptionFailed: decryption operation failed\n' + ' at gcmDecrypt (webpack-internal:///(rsc)/./node_modules/jose/dist/node/cjs/runtime/decrypt.js:68:15)\n' + ' at decrypt (webpack-internal:///(rsc)/./node_modules/jose/dist/node/cjs/runtime/decrypt.js:91:20)\n' + ' at flattenedDecrypt (webpack-internal:///(rsc)/./node_modules/jose/dist/node/cjs/jwe/flattened/decrypt.js:137:52)\n' + ' at async compactDecrypt (webpack-internal:///(rsc)/./node_modules/jose/dist/node/cjs/jwe/compact/decrypt.js:20:23)\n' + ' at async jwtDecrypt (webpack-internal:///(rsc)/./node_modules/jose/dist/node/cjs/jwt/decrypt.js:10:23)\n' + ' at async Object.decode (webpack-internal:///(rsc)/./node_modules/next-auth/jwt/index.js:44:25)\n' + ' at async Object.session (webpack-internal:///(rsc)/./node_modules/next-auth/core/routes/session.js:25:34)\n' + ' at async AuthHandler (webpack-internal:///(rsc)/./node_modules/next-auth/core/index.js:161:37)\n' + ' at async getServerSession (webpack-internal:///(rsc)/./node_modules/next-auth/next/index.js:126:21)\n' + ' at async RootLayout (webpack-internal:///(rsc)/./src/app/layout.js:31:21)', name: 'JWEDecryptionFailed' }
使用最新版NextAuth包,已配置AUTH_SECRET并在authOptions中指定,但仍报错,求解决方法。
解决方法
1. 修正AUTH_SECRET格式
.env文件中等号两边的空格会导致读取的secret包含无效字符,直接修改为无空格的格式:
AUTH_SECRET=aISfOz91Gp66KGHMIUsDI63z+56dv7yjIr+vN96IkHE= AUTH_URL=http://localhost:3000/api/auth
也可以重新生成兼容性更好的十六进制密钥,执行命令:openssl rand -hex 32,将结果替换现有AUTH_SECRET值。
2. 清除浏览器缓存与Cookie
之前可能存储了用旧密钥加密的JWT,清除浏览器中localhost:3000的所有Cookie,重启浏览器后重新测试登录流程。
3. 修复数据库连接的异步问题
connectToDb()是异步函数,未加await会导致数据库操作在连接建立前执行,可能引发异常影响会话生成,修改signIn回调:
async signIn({user, account, profile}) { if (account.provider === "github") { await connectToDb(); // 添加await确保连接完成 try { const user = await User.findOne({email:profile.email}); if (!user) { const newUser = new User({ username:profile.login, email:profile.email, image:profile.avatar_url, password:"123456", }); await newUser.save(); } } catch (error) { console.log(error); return false; } return true; } }
4. 显式声明Session策略
虽然默认是JWT策略,但显式声明可以避免潜在的配置歧义:
export const authOptions = { secret: process.env.AUTH_SECRET, session: { strategy: "jwt" }, // 其他原有配置 };
内容的提问来源于stack exchange,提问作者Keat
相关产品推荐
相关产品推荐

