Axios POST请求返回401错误但Postman可正常调用(Spring Boot+Security)
问题场景
使用Spring Boot + Spring Boot Security构建API,前端通过Axios调用接口。所有接口在Postman测试均正常,但前端调用登录接口(POST /api/v1/auth/signin,用于生成JWT)时返回401错误,该接口已配置为无需授权。
已排查的方向:
- 排除Auth Token传递错误:该接口不需要Token,Postman请求可正常通过
- 尝试解决CORS问题:在Controller添加
@CrossOrigin注解,也试过从SecurityFilterChain中移除.cors()配置,但问题依旧
SecurityFilterChain 配置
@Configuration @EnableWebSecurity @EnableGlobalMethodSecurity(prePostEnabled = true) public class WebSecurityConfig { @Autowired private AuthEntryPointJwt authorizationHandler; @Autowired UserDetailsServiceImpl userDetailsService; @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http.cors().and().csrf().disable().exceptionHandling().authenticationEntryPoint(authorizationHandler).and() .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS).and().authorizeRequests() .antMatchers("/api/v1/auth/**").permitAll() .antMatchers("/api/v1/reviews/**").permitAll() .antMatchers("/api/v1/test/**").permitAll().anyRequest().authenticated(); http.addFilterBefore(authenticationJwtTokenFilter(), UsernamePasswordAuthenticationFilter.class); return http.build(); } @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } @Bean public AuthTokenFilter authenticationJwtTokenFilter() { return new AuthTokenFilter(); } @Bean public AuthenticationManager authenticationManager(AuthenticationConfiguration authenticationConfiguration) throws Exception { return authenticationConfiguration.getAuthenticationManager(); } }
AuthController 代码
@CrossOrigin(origins = "http://localhost:5173", maxAge = 3600) @RestController @RequestMapping("/api/v1/auth") public class AuthController { @Autowired AuthenticationManager authenticationManager; @Autowired UserRepository userRepository; @Autowired PasswordEncoder encoder; @Autowired JwtUtils jwtUtils; @PostMapping("/signin") public ResponseEntity<?> authenticateUser(@RequestBody LoginRequest loginRequest) { Authentication authentication = authenticationManager.authenticate( new UsernamePasswordAuthenticationToken(loginRequest.getUsername(), loginRequest.getPassword()) ); SecurityContextHolder.getContext().setAuthentication(authentication); String jwt = jwtUtils.generateJwtToken(authentication); UserDetailsImpl userDetails = (UserDetailsImpl) authentication.getPrincipal(); return ResponseEntity.ok(new JwtResponse(jwt, userDetails.getId(), userDetails.getUsername(), userDetails.getEmail())); } }
前端AuthService代码
import axios from "axios"; const API_URL = "http://localhost:8080/api/v1/auth/"; export default class AuthService { login(username, password) { console.log(API_URL + "signin"); console.log(username, password); return axios .post(API_URL + "signin", { username, password }) .then((response) => { if (response.data.accessToken) { localStorage.setItem("user", JSON.stringify(response.data)); } return response.data; }); } logout() { localStorage.removeItem("user"); } register(username, email, password) { return axios.post(API_URL + "signup", { username, email, password, }); } }
请求对比
- Postman请求:可正常返回JWT,无401错误
- Axios请求:返回401 Unauthorized
浏览器网络面板请求详情
基本信息
Request URL: http://localhost:8080/api/v1/auth/signin Request Method: POST Status Code: 401 Remote Address: [::1]:8080 Referrer Policy: strict-origin-when-cross-origin
响应头
HTTP/1.1 401 Vary: Origin Vary: Access-Control-Request-Method Vary: Access-Control-Request-Headers Access-Control-Allow-Origin: http://localhost:5173 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: 0 X-Frame-Options: DENY Content-Length: 0 Date: Tue, 27 Jun 2023 20:38:38 GMT Keep-Alive: timeout=60 Connection: keep-alive
请求头
POST /api/v1/auth/signin HTTP/1.1 Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Accept-Language: en-GB,en-US;q=0.9,en;q=0.8 Connection: keep-alive Content-Length: 49 Content-Type: application/json Host: localhost:8080 Origin: http://localhost:5173 Referer: http://localhost:5173/ Sec-Fetch-Dest: empty Sec-Fetch-Mode: cors Sec-Fetch-Site: same-site User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 sec-ch-ua: "Not.A/Brand";v="8", "Chromium";v="114", "Google Chrome";v="114" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows"
内容的提问来源于stack exchange,提问作者hirw
相关产品推荐
相关产品推荐

