You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Symfony 5中无法创建JWT的技术问题求助

Symfony 5 JWT创建失败排查(500错误:Unable to create a signed JWT from the given configuration)

问题描述

在Symfony 5项目中配置JWT认证时,触发500内部服务器错误,报错信息为:

Unable to create a signed JWT from the given configuration.

已按官方文档步骤配置,但问题未解决。

相关代码与配置

控制器方法

#[Route('api/login', name: 'api_login')]
public function loginUser(Request $request,
                          JWTTokenManagerInterface $tokenManager
                         ): JsonResponse
{
    $credentials = json_decode($request->getContent(), true);

    if (!isset($credentials['username'], $credentials['password']) || !$credentials)
    {
        return new JsonResponse('Missing credentials', Response::HTTP_UNAUTHORIZED);
    }

    $username = $credentials['username'];
    $password = $credentials['password'];

    $user = $this->repository->findOneBy(['username' => $username]);

    if (!$user instanceof UserInterface || !$this->passwordHasher->isPasswordValid($user, $password))
    {
        return new JsonResponse('Invalid credentials', Response::HTTP_UNAUTHORIZED);
    }

    $token = $tokenManager->create($user);

    return new JsonResponse($user->getUserIdentifier() . $token);
}

Route.yaml

login:
    path: /api/login

security.yaml

security:
    password_hashers:
        Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface: 'auto'
    providers:
        app_user_provider:
            entity:
                class: App\Entity\User
                property: username
    firewalls:
        login:
            pattern: ^/api/login
            stateless: true
            json_login:
                check_path: /api/login
                success_handler: lexik_jwt_authentication.handler.authentication_success
                failure_handler: lexik_jwt_authentication.handler.authentication_failure
        api:
            pattern: ^/api
            stateless: true
            jwt: ~
        dev:
            pattern: ^/(_(profiler|wdt)|css|images|js)/
            security: false
        main:
            lazy: true
            provider: app_user_provider

    access_control:
         - { path: ^/api/register, roles: PUBLIC_ACCESS }
         - { path: ^/api/login, roles: PUBLIC_ACCESS }
         - { path: ^/api, roles: IS_AUTHENTICATED_FULLY }

when@test:
    security:
        password_hashers:
            Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface:
                algorithm: auto
                cost: 4 
                time_cost: 3 
                memory_cost: 10 

.env

JWT_SECRET_KEY=%kernel.project_dir%/config/jwt/private.pem
JWT_PUBLIC_KEY=%kernel.project_dir%/config/jwt/public.pem
JWT_PASSPHRASE=9c32a9b40d2606c7aed87e3eb8642bd7

lexik_jwt_authentication.yaml

lexik_jwt_authentication:
    secret_key: '%env(resolve:JWT_SECRET_KEY)%'
    public_key: '%env(resolve:JWT_PUBLIC_KEY)%'
    pass_phrase: '%env(JWT_PASSPHRASE)%'
    token_ttl: 3600

排查与解决方案

1. 验证密钥文件的存在与权限

  • 确认config/jwt目录下存在private.pem和public.pem文件,若未生成,执行以下命令:
    openssl genrsa -out config/jwt/private.pem -aes256 4096
    openssl rsa -pubout -in config/jwt/private.pem -out config/jwt/public.pem
    
  • 确保Web服务器对密钥文件有读取权限,执行:
    chmod 644 config/jwt/*.pem
    
    Linux系统下还需确认文件所属用户组与Web服务器一致(如www-data)。

2. 核对密钥路径与环境变量

  • 检查.env中的路径是否正确,执行命令查看解析后的实际路径:
    php bin/console debug:container --env-vars
    
    确认JWT_SECRET_KEY和JWT_PUBLIC_KEY指向的文件真实存在。

3. 确认密码短语一致性

  • 确保.env中的JWT_PASSPHRASE与生成私钥时设置的密码完全一致,注意大小写、特殊字符无差异。

4. 修复控制器与Security配置的冲突

  • 当前security.yaml中已配置json_login并关联Lexik的处理器,Symfony会自动处理登录并生成JWT,无需在控制器中手动调用$tokenManager->create($user),两者冲突会导致错误。
  • 解决方案:删除自定义的loginUser控制器方法,依赖security的json_login自动处理登录请求;若需自定义逻辑,需移除security.yaml中login防火墙的json_login配置,避免重复处理。

5. 检查Bundle依赖与缓存

  • 确认LexikJWTAuthenticationBundle版本兼容Symfony 5,执行:
    composer show lexik/jwt-authentication-bundle
    
  • 清除项目缓存,避免旧配置干扰:
    php bin/console cache:clear --env=dev
    # 生产环境执行
    php bin/console cache:clear --env=prod
    

内容的提问来源于stack exchange,提问作者Jaanioo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 01:48:28