You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法通过Playwright-JavaScript生成Basic Auth的API访问令牌(返回401)

问题:Playwright-JavaScript调用Basic Auth令牌接口返回401,Postman请求正常

问题描述

无法通过Playwright-JavaScript生成带Basic Auth的API端点访问令牌,请求返回401状态码,但在Postman中相同参数的请求可正常返回200。

Postman 请求详情

TokenEndPoint - https://api.dev.aa.com//token
Authorization: username: 'fadsfadf353423',
               password: 'ZurbhG3kjZ'
Body: grant_type: 'client_credentials'

CURL 请求详情

curl --location --request POST 'https://api.dev.aa.com/edgemicro-auth/token' \
--header 'Authorization: Basic UkdZZUxSVUpobk5iRkR1QXJ4dzBnV1JNYXY3QmRxS==' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--header 'Cookie: _abck=D615B497E043C6F7E72E5F9AB4A34B5E~-1~YAAQDPs7FyzSrg+HAQAAwuC2NwmgIuawZv+zP3GhCafLPgqXpwKMPc9pjZ1IQ1kkIaWLFigGwzSfbIV6Y0cA/octAN264XvJR7IQHlVWNKSW64iR3bKb/4cTCCoKtNVyX3V7O+ekwHo/MhiK2Ie3vzGIw5qXpeqX7VQLSshZ4Tn+YvWCoARgFpSh0H6WhJQqPoKlvl3JJkMogFubx6csEfoHvShZaOdi2E0ddNxQOV2bmSnBtHuN5ntsIskySSqI1NvdXquXIZxyq+ghkDxgCWHaW9uFdLsZChBHZb7MhwSEfXvAeuBC4gSEhg5T8dHltZpYR+DvJQlZPdGh2fccOE8jb07ypbEU+FK5djoEk0qZJypQ6mJyGKqwYnBw6XvdRbBl~-1~-1~1675889701' \
--data-urlencode 'grant_type=client_credentials'

尝试的Playwright代码

import { expect, request, test } from "@playwright/test";
const apiUrlEndPoint = 'https://api.dev.aa.com/token'
test('authendPoin', async ({request}) => {
    const response = await request.post(apiUrlEndPoint, {
        headers: {
            //grant_type: 'client_credentials',
            grant_type: 'password',
            username: 'RGYeLRUJhnNbFDuArxw0gWRMav7BdqJu',
            password: 'ZurbhG3kjZviG4xV'
          }
        //data:processRefundBodyPayload
        //data: JSON.stringify(postBody),
    })
    expect(response.ok()).toBeTruthy
    console.log("===================Status Text==============")
    console.log(response.statusText())
    expect(response.status()).toBe(200)
})

问题排查与修正方案

核心问题点

  1. 接口地址不匹配:
    Postman和CURL的接口路径是/edgemicro-auth/token,但Playwright代码里用的是/token,缺少了关键路径段,导致请求到错误的端点。

  2. Basic Auth处理错误:
    Basic Auth的规范是将用户名:密码拼接成字符串后进行Base64编码,然后放在Authorization: Basic <编码值>的Header中。你当前直接把username和password作为Header字段传递,完全不符合认证要求。

  3. 请求参数位置错误:
    grant_type应该作为application/x-www-form-urlencoded类型的请求体参数,而不是放在Header里;同时你错误地将grant_type设置为password,和Postman中使用的client_credentials不一致。

修正后的Playwright代码

import { expect, test } from "@playwright/test";

// 修正接口地址,与Postman/CURL保持一致
const apiUrlEndPoint = 'https://api.dev.aa.com/edgemicro-auth/token';

test('authendPoin', async ({ request }) => {
    // 生成Basic Auth所需的Base64编码令牌
    const username = 'RGYeLRUJhnNbFDuArxw0gWRMav7BdqJu';
    const password = 'ZurbhG3kjZviG4xV';
    const basicAuthToken = Buffer.from(`${username}:${password}`).toString('base64');

    const response = await request.post(apiUrlEndPoint, {
        headers: {
            'Authorization': `Basic ${basicAuthToken}`,
            'Content-Type': 'application/x-www-form-urlencoded'
        },
        // 正确设置请求体参数
        form: {
            grant_type: 'client_credentials'
        }
    });

    console.log("===================Status Text==============");
    console.log(response.statusText());
    expect(response.ok()).toBeTruthy();
    expect(response.status()).toBe(200);
});

额外注意事项

  • 核对用户名和密码是否与Postman中使用的完全一致(你Playwright代码中的密码比Postman示例多了viG4xV,需确认正确性)。
  • 如果接口依赖CURL中的Cookie才能正常响应,可以在请求Headers中添加对应的Cookie字段。

内容的提问来源于stack exchange,提问作者MD Zaman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 11:14:53