You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

@nuxtjs/auth-next中refresh_token刷新接口调用异常求助

问题:@nuxtjs/auth-next 刷新接口使用access_token而非refresh_token

我正在使用@nuxtjs/auth-next模块,配置如下,但调用auth/refresh接口时,请求使用的是access_token。服务端获取到Authorization头后,解码JWT发现内容为access_token。我原本以为该模块会在access_token过期时,将refresh_token放入Authorization头并调用api/auth/refresh接口。烦请帮忙排查是否存在配置错误。

配置代码

auth: {
  redirect: {
    login:    '/login', 
    logout:   '/login',
    callback: '/login', 
    home:     '/'
  },
  strategies: {
    local: {
      scheme:     'refresh',
      autoLogout: true,
      token: {
        property: 'access_token',
        maxAge:   1800,
        global:   true,
        // type: 'Bearer'
      },
      refreshToken: {
        property: 'refresh_token',
        data:     'refresh_token',
        maxAge:   60 * 60 * 24 * 30
      },
      user: {
        property:   false,
        autoFetch:  true
      },
      endpoints: {
        login: {
          url:          '/auth/login',
          method:       'post',
          propertyName: 'access_token',
          headers: {
            "Content-Type": "application/x-www-form-urlencoded",
            "grant_type":   "password"
          },
        },
        refresh:  { url: '/auth/refresh', method: 'get'                       },
        logout:   { url: '/auth/logout',  method: 'post',                     },
        user:     { url: '/auth/me',      method: 'get', propertyName: false  }
      }
    },
}

/auth/login 响应

{
    "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl90eXBlIjoiYWNjZXNzX3Rva2VuIiwiZXhwIjoxNjc0NTI1OTA3LCJzdGFmZl9pZCI6ImFiY2RlMTIzIn0.68BPtgr93lwHgSfSQxieEJUJtGPe9bafQMpnbdHEqy0",
    "refresh_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl90eXBlIjoicmVmcmVzaF90b2tlbiIsImV4cCI6MTY3NzExNzg0Nywic3RhZmZfaWQiOiJhYmNkZTEyMyJ9.71B1iofZIsoaduUOH7ahuTi2gc2NCp5fpsRrsZaGPMg",
    "token_type": "bearer"
}

Cookies信息

NameValueExpires/Max-AgePriority
auth._token_expiration.local1674525907000SessionMedium
auth._refresh_token.localeyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl90eXBlIjoicmVmcmVzaF90b2tlbiIsImV4cCI6MTY3NzExNzg0Nywic3RhZmZfaWQiOiJhYmNkZTEyMyJ9.71B1iofZIsoaduUOH7ahuTi2gc2NCp5fpsRrsZaGPMgSessionMedium
auth._token.localBearer%20eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl90eXBlIjoiYWNjZXNzX3Rva2VuIiwiZXhwIjoxNjc0NTI1OTA3LCJzdGFmZl9pZCI6ImFiY2RlMTIzIn0.68BPtgr93lwHgSfSQxieEJUJtGPe9bafQMpnbdHEqy0SessionMedium
auth._refresh_token_expiration.local1677117847000SessionMedium
auth.strategylocalSessionMedium

已尝试的操作

  • 调整nuxt.config.js中的多项auth配置(例如设置autoLogout: false等),问题仍未解决
  • 手动调用this.$auth.refreshTokens(),Authorization头仍被设置为access_token
  • 确认token已成功接收并存入Cookie中

解决方案

1. 补全refreshToken的tokenType配置

当前注释了token.type,导致refresh scheme无法正确识别refresh token的认证类型,需要在refreshToken节点添加tokenType字段:

refreshToken: {
  property: 'refresh_token',
  data:     'refresh_token',
  maxAge:   60 * 60 * 24 * 30,
  tokenType: 'Bearer' // 明确指定refresh token的认证类型
}

2. 调整refresh接口的请求方式

GET方法不适合传递敏感的refresh token,建议将refresh接口改为POST,并确保后端能正确接收Authorization头中的refresh token:

refresh:  { url: '/auth/refresh', method: 'post' }

3. 验证access token是否真的过期

模块仅会在access token过期时自动触发刷新逻辑,手动调用refreshTokens()前,可先删除auth._token.local Cookie,强制模拟token过期场景测试。

4. 检查token.global配置的冲突

token.global: true会让所有请求都携带access token,可能覆盖refresh请求的头信息,可临时设置为false,仅在需要授权的接口手动添加token,排查是否存在冲突。

5. 清除缓存重启项目

删除.nuxt文件夹及node_modules/.cache目录,重新启动Nuxt项目,避免旧配置缓存导致的问题。


内容的提问来源于stack exchange,提问作者oosato

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 05:30:53