You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Next.js v13.4.1与next-auth 4.22.1中API路由获取session失败求助

在Next.js v13.4.1 + next-auth 4.22.1的API路由中无法获取Session的解决方案

问题背景

前端通过useSession可以正常获取登录用户的Session,但在API路由中尝试多种方式均无法获取Session:

  • 使用getServerSession返回null
  • 使用getToken+adapter.getSessionAndUser返回null
  • API请求的req.cookies为空,请求头中无相关Cookie信息

现有配置与代码

前端Session使用(正常工作)

import { signOut, useSession } from 'next-auth/react';
// ...
const { data: session } = useSession();
// 登录后可正常使用session

[...nextauth].js配置

export const authOptions = {
   debug: true,
   session: {
     strategy: "jwt"
   },
   providers: [
     TwitterProvider({
        clientId: process.env.TWITTER_CLIENT_ID,
        clientSecret: process.env.TWITTER_CLIENT_SECRET,
        version: "2.0", // opt-in to Twitter OAuth 2.0
     })
   ],
   adapter: DynamoDBAdapter(
     client, {tableName: "leaderboard-auth"}
   )
}

API路由尝试的方法

  1. getServerSession方式
import { getServerSession } from "next-auth/next"
import { authOptions } from '../auth/[...nextauth]'

export default async function handler(req, res) {
   const session = await getServerSession(req, res, authOptions)
   console.log(session ); // 始终为null
}
  1. getToken+适配器方式
import { authOptions } from '../auth/[...nextauth]'
import { getToken } from "next-auth/jwt"

export default async function handler(req, res) {
   const token = await getToken({req});
   const session = await authOptions.adapter.getSessionAndUser(token)
   console.log(session ); // 始终为null
}
  1. 检查请求Cookie
export default async function handler(req, res) {
   console.log('cookies', req.cookies); // 结果始终为{}
   console.log('headers', req.rawHeaders ); // 无相关cookies
}

解决方案

1. 确保API请求携带Credentials

前端调用API时,必须显式设置携带Cookie,否则浏览器不会自动传递:

  • 使用fetch时:
fetch('/api/your-route', {
  method: 'GET',
  credentials: 'include' // 关键:带上Cookie
})
  • 使用axios时:
axios.get('/api/your-route', {
  withCredentials: true // 关键:带上Cookie
})

2. 配置NEXTAUTH_SECRET环境变量

next-auth的JWT加密/解密、Cookie签名都依赖NEXTAUTH_SECRET,必须在.env文件中添加:

NEXTAUTH_SECRET=your-random-secret-key

可以用openssl rand -hex 32生成一个安全的密钥

3. 检查authOptions的Session配置与适配器兼容性

  • 当session.strategy: "jwt"时,实际上不需要数据库适配器(除非你需要将Session持久化到DB)。如果同时使用JWT策略和适配器,请确保适配器配置正确,且数据库中存在对应的Session记录。
  • 若要使用数据库Session策略,需将session.strategy改为"database",并确保适配器正常工作(你已确认DynamoDB适配器工作,此步可跳过)。

4. 验证Cookie的SameSite与Domain设置

在authOptions中显式配置Cookie参数,确保在开发环境下正常传递:

export const authOptions = {
  // ... 其他配置
  cookies: {
    sessionToken: {
      name: `next-auth.session-token`,
      options: {
        httpOnly: true,
        sameSite: 'lax', // 开发环境建议用'lax',生产可根据需求调整
        path: '/',
        domain: process.env.NODE_ENV === 'production' ? '.your-domain.com' : undefined,
        secure: process.env.NODE_ENV === 'production'
      }
    }
  }
}

5. 确保getServerSession的参数正确传递

在API路由中,确保authOptions被正确导入,且req和res参数完整传递:

import { getServerSession } from "next-auth/next";
import { authOptions } from "../auth/[...nextauth]";

export default async function handler(req, res) {
  // 确认authOptions的secret已正确设置
  if (!authOptions.secret) {
    throw new Error("NEXTAUTH_SECRET is not set");
  }
  
  const session = await getServerSession(req, res, authOptions);
  if (!session) {
    return res.status(401).json({ message: "未授权" });
  }
  
  res.status(200).json({ session });
}

内容的提问来源于stack exchange,提问作者user2517028

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 18:53:10