@nuxtjs/auth-next中refresh_token刷新接口调用异常求助
问题:@nuxtjs/auth-next 刷新接口使用access_token而非refresh_token
我正在使用@nuxtjs/auth-next模块,配置如下,但调用auth/refresh接口时,请求使用的是access_token。服务端获取到Authorization头后,解码JWT发现内容为access_token。我原本以为该模块会在access_token过期时,将refresh_token放入Authorization头并调用api/auth/refresh接口。烦请帮忙排查是否存在配置错误。
配置代码
auth: { redirect: { login: '/login', logout: '/login', callback: '/login', home: '/' }, strategies: { local: { scheme: 'refresh', autoLogout: true, token: { property: 'access_token', maxAge: 1800, global: true, // type: 'Bearer' }, refreshToken: { property: 'refresh_token', data: 'refresh_token', maxAge: 60 * 60 * 24 * 30 }, user: { property: false, autoFetch: true }, endpoints: { login: { url: '/auth/login', method: 'post', propertyName: 'access_token', headers: { "Content-Type": "application/x-www-form-urlencoded", "grant_type": "password" }, }, refresh: { url: '/auth/refresh', method: 'get' }, logout: { url: '/auth/logout', method: 'post', }, user: { url: '/auth/me', method: 'get', propertyName: false } } }, }
/auth/login 响应
{ "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl90eXBlIjoiYWNjZXNzX3Rva2VuIiwiZXhwIjoxNjc0NTI1OTA3LCJzdGFmZl9pZCI6ImFiY2RlMTIzIn0.68BPtgr93lwHgSfSQxieEJUJtGPe9bafQMpnbdHEqy0", "refresh_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl90eXBlIjoicmVmcmVzaF90b2tlbiIsImV4cCI6MTY3NzExNzg0Nywic3RhZmZfaWQiOiJhYmNkZTEyMyJ9.71B1iofZIsoaduUOH7ahuTi2gc2NCp5fpsRrsZaGPMg", "token_type": "bearer" }
Cookies信息
| Name | Value | Expires/Max-Age | Priority |
|---|---|---|---|
| auth._token_expiration.local | 1674525907000 | Session | Medium |
| auth._refresh_token.local | eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl90eXBlIjoicmVmcmVzaF90b2tlbiIsImV4cCI6MTY3NzExNzg0Nywic3RhZmZfaWQiOiJhYmNkZTEyMyJ9.71B1iofZIsoaduUOH7ahuTi2gc2NCp5fpsRrsZaGPMg | Session | Medium |
| auth._token.local | Bearer%20eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl90eXBlIjoiYWNjZXNzX3Rva2VuIiwiZXhwIjoxNjc0NTI1OTA3LCJzdGFmZl9pZCI6ImFiY2RlMTIzIn0.68BPtgr93lwHgSfSQxieEJUJtGPe9bafQMpnbdHEqy0 | Session | Medium |
| auth._refresh_token_expiration.local | 1677117847000 | Session | Medium |
| auth.strategy | local | Session | Medium |
已尝试的操作
- 调整nuxt.config.js中的多项auth配置(例如设置
autoLogout: false等),问题仍未解决 - 手动调用
this.$auth.refreshTokens(),Authorization头仍被设置为access_token - 确认token已成功接收并存入Cookie中
解决方案
1. 补全refreshToken的tokenType配置
当前注释了token.type,导致refresh scheme无法正确识别refresh token的认证类型,需要在refreshToken节点添加tokenType字段:
refreshToken: { property: 'refresh_token', data: 'refresh_token', maxAge: 60 * 60 * 24 * 30, tokenType: 'Bearer' // 明确指定refresh token的认证类型 }
2. 调整refresh接口的请求方式
GET方法不适合传递敏感的refresh token,建议将refresh接口改为POST,并确保后端能正确接收Authorization头中的refresh token:
refresh: { url: '/auth/refresh', method: 'post' }
3. 验证access token是否真的过期
模块仅会在access token过期时自动触发刷新逻辑,手动调用refreshTokens()前,可先删除auth._token.local Cookie,强制模拟token过期场景测试。
4. 检查token.global配置的冲突
token.global: true会让所有请求都携带access token,可能覆盖refresh请求的头信息,可临时设置为false,仅在需要授权的接口手动添加token,排查是否存在冲突。
5. 清除缓存重启项目
删除.nuxt文件夹及node_modules/.cache目录,重新启动Nuxt项目,避免旧配置缓存导致的问题。
内容的提问来源于stack exchange,提问作者oosato
相关产品推荐
相关产品推荐

