Java中携带Access Token发送HTTP GET请求报错求助
问题:发送携带Access Token的HTTP GET请求时抛出参数异常
依赖库
import java.io.IOException; import java.net.HttpURLConnection; import java.net.URL; import java.security.cert.X509Certificate; import java.util.ArrayList; import java.util.List; import javax.net.ssl.SSLContext; import org.apache.commons.io.IOUtils; import org.apache.http.Consts; import org.apache.http.HttpResponse; import org.apache.http.NameValuePair; import org.apache.http.client.entity.UrlEncodedFormEntity; import org.apache.http.client.methods.CloseableHttpResponse; import org.apache.http.client.methods.HttpGet; import org.apache.http.client.methods.HttpPost; import org.apache.http.conn.ssl.SSLConnectionSocketFactory; import org.apache.http.impl.client.CloseableHttpClient; import org.apache.http.impl.client.HttpClients; import org.apache.http.message.BasicNameValuePair; import org.apache.http.ssl.TrustStrategy; import org.json.JSONObject;
现有代码
// My site is set as insecure, so I set the following setting TrustStrategy acceptingTrustStrategy = (X509Certificate[] chain, String authType) -> true; SSLContext sslContext = org.apache.http.ssl.SSLContexts.custom() .loadTrustMaterial(null, acceptingTrustStrategy) .build(); SSLConnectionSocketFactory csf = new SSLConnectionSocketFactory(sslContext); CloseableHttpClient httpClient = HttpClients.custom() .setSSLSocketFactory(csf) .build(); HttpGet request = new HttpGet("https://xxxxxxxxxxxxxxxxx"); request.addHeader("Authorization", "Bearer " + access_token); CloseableHttpResponse response = httpClient.execute(request);
报错信息
java.lang.IllegalArgumentException: method GET must not have a request body.
解决方案
错误原因
HTTP规范明确要求GET请求不能携带请求体,Apache HttpClient会严格执行这个校验。你的代码看似没有显式设置请求体,但大概率是存在遗留逻辑(比如复制POST请求代码时未清理设置请求实体的代码),或是依赖的HttpClient版本存在隐式配置问题。
修正步骤
- 清理请求体相关代码:确保从未对
HttpGet对象调用setEntity()这类添加请求体的方法,这是POST请求专属操作。 - 简化客户端配置:如果不需要复杂自定义,可尝试用默认方式创建HttpClient,避免隐式配置引发问题。
- 确认请求头合法性:你设置的
Authorization头是正确的,无需额外添加会触发请求体的配置。
修正后的完整代码示例
import java.io.IOException; import java.security.cert.X509Certificate; import javax.net.ssl.SSLContext; import org.apache.http.client.methods.CloseableHttpResponse; import org.apache.http.client.methods.HttpGet; import org.apache.http.conn.ssl.SSLConnectionSocketFactory; import org.apache.http.impl.client.CloseableHttpClient; import org.apache.http.impl.client.HttpClients; import org.apache.http.ssl.TrustStrategy; public class GetRequestWithToken { public static void main(String[] args) throws IOException { String access_token = "your_valid_token_here"; String targetUrl = "https://xxxxxxxxxxxxxxxxx"; // 跳过SSL证书校验(仅测试环境使用) TrustStrategy acceptingTrustStrategy = (X509Certificate[] chain, String authType) -> true; SSLContext sslContext = org.apache.http.ssl.SSLContexts.custom() .loadTrustMaterial(null, acceptingTrustStrategy) .build(); SSLConnectionSocketFactory csf = new SSLConnectionSocketFactory(sslContext); // 创建HttpClient try (CloseableHttpClient httpClient = HttpClients.custom() .setSSLSocketFactory(csf) .build()) { // 创建GET请求并设置Authorization头 HttpGet request = new HttpGet(targetUrl); request.addHeader("Authorization", "Bearer " + access_token); // 执行请求并处理响应 try (CloseableHttpResponse response = httpClient.execute(request)) { // 此处可添加响应处理逻辑,比如读取响应体 System.out.println("Response Status: " + response.getStatusLine()); } } } }
额外注意
- 跳过SSL证书校验仅适合测试环境,生产环境必须配置合法的证书信任策略。
- 严格遵循HTTP规范,GET请求绝不携带请求体,可避免各类兼容性问题。
内容的提问来源于stack exchange,提问作者ציפי גולדברג
相关产品推荐
相关产品推荐

