You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已注册用户存在于数据库,但Postman登录认证时无法找到用户求助

问题描述

我已注册一名用户,该用户确实存在于数据库中,但通过Postman使用邮箱和密码登录时,系统提示找不到该用户。以下是相关配置与代码:

安全配置(BookStoreSecurityConfig)

private final AuthenticationProvider authenticationProvider;
private final JWTTokenGeneratorFilter jwtTokenGeneratorFilter;

@Bean
SecurityFilterChain defaultSecurityFilterChain(HttpSecurity http) throws Exception{
    CsrfTokenRequestAttributeHandler requestAttributeHandler = new CsrfTokenRequestAttributeHandler();
    requestAttributeHandler.setCsrfRequestAttributeName("_csrf");
    http.csrf((csrf)->csrf.disable())
            .authorizeHttpRequests(requests -> requests.requestMatchers("/api/v1/auth/**")
                    .permitAll()
                    .anyRequest()
                    .authenticated()
            ).sessionManagement(session -> session
                    .sessionCreationPolicy(SessionCreationPolicy.STATELESS))
            .authenticationProvider(authenticationProvider)
            .addFilterBefore(jwtTokenGeneratorFilter, UsernamePasswordAuthenticationFilter.class)
            .addFilterAfter(new CsrfCookieFilter(),BasicAuthenticationFilter.class);
    return http.build();
}

应用配置

private final UsersRepository usersRepository;

@Bean
public PasswordEncoder passwordEncoder(){
    return new BCryptPasswordEncoder();
}

@Bean
public UserDetailsService userDetailsService(){
    return username -> usersRepository.findByEmail(username).orElseThrow(() -> new UsernameNotFoundException("not found"));
}

@Bean
public AuthenticationProvider authenticationProvider(){
    DaoAuthenticationProvider authProvider = new DaoAuthenticationProvider();
    authProvider.setUserDetailsService(userDetailsService());
    authProvider.setPasswordEncoder(passwordEncoder());
    return authProvider;
}

@Bean
public AuthenticationManager authenticationManager(AuthenticationConfiguration config) throws Exception{
    return config.getAuthenticationManager();
}

认证服务

@Override
public AuthenticationDtoResponse authenticate(AuthenticationDtoRequest request) {
    authenticationManager.authenticate((
            new UsernamePasswordAuthenticationToken(
                    request.getEmail(),
                    request.getPassword())
            )
    );
    var user = usersRepository.findByEmail(request.getEmail()).orElseThrow();
    var jwtToken = jwtService.generateToken(user);
    return AuthenticationDtoResponse.builder()
            .email(request.getEmail())
            .jwt(jwtToken)
            .build();
}

排查方向与解决方案

  1. 邮箱大小写不匹配
    数据库中存储的邮箱可能是大小写混合格式(如Test@example.com),但Postman请求时用了全小写/全大写。检查usersRepository.findByEmail是否支持大小写不敏感查询。

    • 解决:修改Repository查询方法,比如添加@Query("SELECT u FROM User u WHERE LOWER(u.email) = LOWER(:email)"),确保查询忽略大小写。
  2. 密码加密不一致
    注册用户时是否用了同一个BCryptPasswordEncoder实例加密密码?如果注册时未加密或用了其他加密方式,登录时密码验证失败,Spring Security会默认抛出UsernameNotFoundException(防止恶意枚举用户)。

    • 解决:检查注册逻辑,确保密码通过passwordEncoder().encode(rawPassword)加密后再存入数据库。
  3. UserDetails实体状态异常
    你的User实体若实现了UserDetails接口,需检查isAccountNonExpired、isAccountNonLocked、isCredentialsNonExpired、isEnabled这几个方法的返回值,若有返回false的情况,会导致认证失败,表现为“找不到用户”。

    • 解决:确保上述方法均返回true(除非有特定的账户状态管控逻辑)。
  4. 请求参数传递错误
    检查Postman请求中是否正确传递了email参数,比如参数名写错(如mail而非email)、参数值为空或拼写错误。

    • 解决:在认证服务的authenticate方法开头添加日志,打印request.getEmail()的值,确认接收到的邮箱与数据库中一致。
  5. Repository查询逻辑错误
    检查usersRepository.findByEmail方法的定义,是否正确映射了实体的email字段,比如字段名拼写错误、Repository接口方法定义不符合Spring Data规范。

    • 解决:查看Repository接口代码,必要时用@Column注解明确实体字段与数据库列的映射关系。
  6. 过滤器干扰认证流程
    你的JWTTokenGeneratorFilter或CsrfCookieFilter可能在认证前拦截了请求,导致参数解析异常。

    • 解决:暂时注释掉addFilterBefore和addFilterAfter的过滤器配置,测试基础认证是否正常,逐步排查过滤器的影响。

内容的提问来源于stack exchange,提问作者Kai7

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 11:57:50