You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

NextAuth出现JWEDecryptionFailed解密失败错误,求解决方法及原因

问题:NextAuth结合GitHub登录时出现JWEDecryptionFailed错误

相关代码与配置

[...nextauth]/route.js 文件

import { User } from "@/lib/models";
import { connectToDb } from "@/lib/utils";
import NextAuth from "next-auth";
import GitHubProvider from "next-auth/providers/github";

export const authOptions = {
    secret:process.env.AUTH_SECRET,
    providers:[
        GitHubProvider({
            clientId: process.env.GITHUB_ID,
            clientSecret: process.env.GITHUB_SECRET,
        }),
    ],
    callbacks:{
        async signIn({user, account, profile})
        {
            // console.log(user, account, profile);
            if (account.provider === "github")
            {
                connectToDb()
                try {
                    const user = await User.findOne({email:profile.email});

                    if (!user)
                    {
                        const newUser = new User({
                            username:profile.login,
                            email:profile.email,
                            image:profile.avatar_url,
                            password:"123456",
                        });

                        await newUser.save();
                    }
                } catch (error) {
                    console.log(error);
                    return false;
                }
                return true;
            }
        }
    },
};

export const handlers = NextAuth(authOptions);
export {handlers as GET, handlers as POST};

.env 文件

#TERMINAL INPUT >> openssl rand -base64 32

AUTH_SECRET = aISfOz91Gp66KGHMIUsDI63z+56dv7yjIr+vN96IkHE=
AUTH_URL = http://localhost:3000/api/auth

错误信息

[next-auth][error][JWT_SESSION_ERROR]
decryption operation failed {
  message: 'decryption operation failed',
  stack: 'JWEDecryptionFailed: decryption operation failed\n' +
    '    at gcmDecrypt (webpack-internal:///(rsc)/./node_modules/jose/dist/node/cjs/runtime/decrypt.js:68:15)\n' +
    '    at decrypt (webpack-internal:///(rsc)/./node_modules/jose/dist/node/cjs/runtime/decrypt.js:91:20)\n' +
    '    at flattenedDecrypt (webpack-internal:///(rsc)/./node_modules/jose/dist/node/cjs/jwe/flattened/decrypt.js:137:52)\n' +
    '    at async compactDecrypt (webpack-internal:///(rsc)/./node_modules/jose/dist/node/cjs/jwe/compact/decrypt.js:20:23)\n' +
    '    at async jwtDecrypt (webpack-internal:///(rsc)/./node_modules/jose/dist/node/cjs/jwt/decrypt.js:10:23)\n' +
    '    at async Object.decode (webpack-internal:///(rsc)/./node_modules/next-auth/jwt/index.js:44:25)\n' +
    '    at async Object.session (webpack-internal:///(rsc)/./node_modules/next-auth/core/routes/session.js:25:34)\n' +
    '    at async AuthHandler (webpack-internal:///(rsc)/./node_modules/next-auth/core/index.js:161:37)\n' +
    '    at async getServerSession (webpack-internal:///(rsc)/./node_modules/next-auth/next/index.js:126:21)\n' +
    '    at async RootLayout (webpack-internal:///(rsc)/./src/app/layout.js:31:21)',
  name: 'JWEDecryptionFailed'
}

使用最新版NextAuth包,已配置AUTH_SECRET并在authOptions中指定,但仍报错,求解决方法。


解决方法

1. 修正AUTH_SECRET格式

.env文件中等号两边的空格会导致读取的secret包含无效字符,直接修改为无空格的格式:

AUTH_SECRET=aISfOz91Gp66KGHMIUsDI63z+56dv7yjIr+vN96IkHE=
AUTH_URL=http://localhost:3000/api/auth

也可以重新生成兼容性更好的十六进制密钥,执行命令:openssl rand -hex 32,将结果替换现有AUTH_SECRET值。

2. 清除浏览器缓存与Cookie

之前可能存储了用旧密钥加密的JWT,清除浏览器中localhost:3000的所有Cookie,重启浏览器后重新测试登录流程。

3. 修复数据库连接的异步问题

connectToDb()是异步函数,未加await会导致数据库操作在连接建立前执行,可能引发异常影响会话生成,修改signIn回调:

async signIn({user, account, profile})
{
    if (account.provider === "github")
    {
        await connectToDb(); // 添加await确保连接完成
        try {
            const user = await User.findOne({email:profile.email});

            if (!user)
            {
                const newUser = new User({
                    username:profile.login,
                    email:profile.email,
                    image:profile.avatar_url,
                    password:"123456",
                });

                await newUser.save();
            }
        } catch (error) {
            console.log(error);
            return false;
        }
        return true;
    }
}

4. 显式声明Session策略

虽然默认是JWT策略,但显式声明可以避免潜在的配置歧义:

export const authOptions = {
    secret: process.env.AUTH_SECRET,
    session: {
        strategy: "jwt"
    },
    // 其他原有配置
};

内容的提问来源于stack exchange,提问作者Keat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 22:07:50