Symfony 5.4中使用LexikJWTAuthenticationBundle生成JWT令牌时遭遇无效凭证错误求助
Let's walk through the most common causes of this error and how to fix them, since you've already confirmed your credentials are correct:
1. Ensure Passwords Are Properly Hashed
The #1 culprit here is usually unhashed passwords in the database. Your User entity has a plainPassword field, but you need to make sure you're hashing it before saving the user to the database.
For example, when creating a user in a controller:
use Symfony\Component\PasswordHasher\Hasher\UserPasswordHasherInterface; use Doctrine\ORM\EntityManagerInterface; // Inside your controller action public function createUser(UserPasswordHasherInterface $passwordHasher, EntityManagerInterface $em) { $user = new User(); $user->setEmail('user@example.com'); $user->setPlainPassword('your-secure-password'); // Hash the plain password before storing it $hashedPassword = $passwordHasher->hashPassword($user, $user->getPlainPassword()); $user->setPassword($hashedPassword); $em->persist($user); $em->flush(); }
If you're using fixtures to load test users, do the same:
use Symfony\Component\PasswordHasher\Hasher\UserPasswordHasherInterface; use Doctrine\Persistence\ObjectManager; public function load(ObjectManager $manager, UserPasswordHasherInterface $passwordHasher) { $testUser = new User(); $testUser->setEmail('test@example.com'); $hashedPassword = $passwordHasher->hashPassword($testUser, 'test-password'); $testUser->setPassword($hashedPassword); $manager->persist($testUser); $manager->flush(); }
Double-check your database to confirm the password field contains a long hashed string (not plain text).
2. Fix JSON Login Field Mapping
Your security config comments out username_path and password_path, but since your User uses email as the user identifier, you need to explicitly map the request field to email—otherwise Symfony will look for a username field in your JSON payload, which doesn't exist.
Update your security.yaml under json_login:
json_login: check_path: /api/login_check success_handler: lexik_jwt_authentication.handler.authentication_success failure_handler: lexik_jwt_authentication.handler.authentication_failure username_path: email # Tell Symfony to use the "email" field from your JSON request password_path: password
Also, verify your Postman request:
- Set the request method to
POST - Set
Content-Typeheader toapplication/json - Send a JSON body like this:
{ "email": "user@example.com", "password": "your-secure-password" }
3. Fix Firewall Path Matching
Your login firewall uses pattern: ^/api/login, but your check_path is /api/login_check—this path doesn't match the pattern (since /login_check isn't a subpath of /login). This means the login firewall isn't handling the authentication request, leading to invalid credentials errors.
Adjust the firewall pattern to include /login_check:
firewalls: login: pattern: ^/api/login(.*) # Matches /api/login and /api/login_check stateless: true json_login: # ... your existing config api: # ... your existing config
Alternatively, you could change the check_path to /api/login/check to fit the original pattern, but updating the pattern is more flexible.
4. Clear Symfony Cache
Sometimes stale cache can cause config changes to not take effect. Run this command to clear it:
# For development environment php bin/console cache:clear # For production php bin/console cache:clear --env=prod
5. Verify User Entity Methods
Your User entity's getUserIdentifier() correctly returns the email, which is good. Just make sure there are no typos here—this method is what Symfony uses to look up the user.
6. Check User Status (If Applicable)
If you later add an isEnabled field to your User entity, ensure it's set to true for the user you're trying to authenticate. Your current entity doesn't have this field, so this step only applies if you extend it later.
内容的提问来源于stack exchange,提问作者Mohamed Farouk Ayadi

