RestAssured中重定向请求未携带Cookie的问题求助
问题描述
在RestAssured中发送GET请求时,服务端返回302重定向,响应头包含Set-Cookie字段,但自动跟随的重定向请求未携带这些Cookie,导致返回400认证错误。该场景在Postman中可正常运行,但RestAssured中失效。
原代码示例
given() .spec(requestSpecWithToken) .redirects().follow(true) .config(RestAssured.config().httpClient(httpClientConfig().reuseHttpClientInstance())) .when() .get(myEndpoint) .then() .statusCode(200); // ← 因无Cookie返回400错误
已尝试移除reuseHttpClientInstance()配置,问题仍未解决。
HTTP流程示例
Source Request: GET https://example1.com/url-with-redirect Source Response: 302 Set-Cookie: CookieName1=CookieValue1; Path=/; SameSite=None; Secure Set-Cookie: CookieName2=CookieValue2; Path=/ location: https://example2.org/target Redirected Request: GET https://example2.org/target Redirected Request Cookies: - Redirected Response: 400
补充日志信息
Request method: GET Request URI: https://example1.com/url-with-redirect Proxy: <none> Request params: <none> Query params: <none> Form params: <none> Path params: <none> Headers: Authorization=Bearer [..] Accept=*/* Connection=keep-alive Cookies: <none> Multiparts: <none> Body: <none> [Fatal Error] :1:1: Content is not allowed in prolog. [Fatal Error] :1:1: Content is not allowed in prolog. HTTP/1.1 400 Authentication information is not given in the correct format. Content-Length: 297 Content-Type: application/xml Server: Microsoft-HTTPAPI/2.0 x-ms-request-id: [..] Date: Tue, 20 Dec 2022 19:16:27 GMT <?xml version="1.0" encoding="utf-8"?><Error><Code>InvalidAuthenticationInfo</Code><Message>Authentication information is not given in the correct format. RequestId:[..] Time:2022-12-20T19:16:27.9906229Z</Message></Error>
解决方法
1. 显式配置Cookie存储
RestAssured默认Cookie管理在跨域重定向时可能无法正确传递Cookie,需要手动配置CookieStore来保存并携带Cookie:
// 创建Cookie存储实例 CookieStore cookieStore = new BasicCookieStore(); // 配置RestAssured使用该存储 RestAssuredConfig config = RestAssured.config() .httpClient(httpClientConfig() .setCookieStore(cookieStore)); // 发送请求时应用配置 given() .spec(requestSpecWithToken) .redirects().follow(true) .config(config) .when() .get(myEndpoint) .then() .statusCode(200);
2. 适配SameSite Cookie属性
如果Cookie包含SameSite=None; Secure,需确保RestAssured使用支持该属性的Cookie规范,旧版本HttpClient可能不兼容:
RestAssuredConfig config = RestAssured.config() .httpClient(httpClientConfig() .setCookieSpec(CookieSpecs.STANDARD)); // 启用标准Cookie规范,支持SameSite
3. 手动处理重定向(备选方案)
若自动跟随仍有问题,可禁用自动重定向,手动提取Cookie和目标地址后发送请求:
// 第一步:发送初始请求,不跟随重定向 Response initialResponse = given() .spec(requestSpecWithToken) .redirects().follow(false) .when() .get(myEndpoint); // 提取响应中的所有Cookie List<Cookie> cookies = new ArrayList<>(initialResponse.getDetailedCookies().values()); // 获取重定向目标地址 String redirectUrl = initialResponse.getHeader("Location"); // 第二步:携带Cookie发送重定向请求 given() .cookies(cookies) .when() .get(redirectUrl) .then() .statusCode(200);
4. 检查请求规范的Cookie设置
确认requestSpecWithToken中没有清除Cookie的操作,比如避免使用cookies().clear()这类会清空Cookie的配置。
内容的提问来源于stack exchange,提问作者Varro
相关产品推荐
相关产品推荐

