You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RestAssured中重定向请求未携带Cookie的问题求助

RestAssured重定向请求携带Cookie问题解决

问题描述

在RestAssured中发送GET请求时,服务端返回302重定向,响应头包含Set-Cookie字段,但自动跟随的重定向请求未携带这些Cookie,导致返回400认证错误。该场景在Postman中可正常运行,但RestAssured中失效。

原代码示例

given()
        .spec(requestSpecWithToken)
        .redirects().follow(true)
        .config(RestAssured.config().httpClient(httpClientConfig().reuseHttpClientInstance()))
        .when()
        .get(myEndpoint)
        .then()
        .statusCode(200); // ← 因无Cookie返回400错误

已尝试移除reuseHttpClientInstance()配置,问题仍未解决。

HTTP流程示例

Source Request: GET https://example1.com/url-with-redirect
Source Response: 302
Set-Cookie: CookieName1=CookieValue1; Path=/; SameSite=None; Secure
Set-Cookie: CookieName2=CookieValue2; Path=/
location: https://example2.org/target

Redirected Request: GET https://example2.org/target
Redirected Request Cookies: -
Redirected Response: 400

补充日志信息

Request method: GET
Request URI:    https://example1.com/url-with-redirect
Proxy:          <none>
Request params: <none>
Query params:   <none>
Form params:    <none>
Path params:    <none>
Headers:        Authorization=Bearer [..]
                Accept=*/*
                Connection=keep-alive 
Cookies:        <none>
Multiparts:     <none>
Body:           <none>
[Fatal Error] :1:1: Content is not allowed in prolog.
[Fatal Error] :1:1: Content is not allowed in prolog.
HTTP/1.1 400 Authentication information is not given in the correct format.
Content-Length: 297
Content-Type: application/xml
Server: Microsoft-HTTPAPI/2.0
x-ms-request-id: [..]
Date: Tue, 20 Dec 2022 19:16:27 GMT

<?xml version="1.0" encoding="utf-8"?><Error><Code>InvalidAuthenticationInfo</Code><Message>Authentication information is not given in the correct format.
RequestId:[..]
Time:2022-12-20T19:16:27.9906229Z</Message></Error>

解决方法

1. 显式配置Cookie存储

RestAssured默认Cookie管理在跨域重定向时可能无法正确传递Cookie,需要手动配置CookieStore来保存并携带Cookie:

// 创建Cookie存储实例
CookieStore cookieStore = new BasicCookieStore();

// 配置RestAssured使用该存储
RestAssuredConfig config = RestAssured.config()
        .httpClient(httpClientConfig()
                .setCookieStore(cookieStore));

// 发送请求时应用配置
given()
        .spec(requestSpecWithToken)
        .redirects().follow(true)
        .config(config)
        .when()
        .get(myEndpoint)
        .then()
        .statusCode(200);

2. 适配SameSite Cookie属性

如果Cookie包含SameSite=None; Secure,需确保RestAssured使用支持该属性的Cookie规范,旧版本HttpClient可能不兼容:

RestAssuredConfig config = RestAssured.config()
        .httpClient(httpClientConfig()
                .setCookieSpec(CookieSpecs.STANDARD)); // 启用标准Cookie规范,支持SameSite

3. 手动处理重定向(备选方案)

若自动跟随仍有问题,可禁用自动重定向,手动提取Cookie和目标地址后发送请求:

// 第一步:发送初始请求,不跟随重定向
Response initialResponse = given()
        .spec(requestSpecWithToken)
        .redirects().follow(false)
        .when()
        .get(myEndpoint);

// 提取响应中的所有Cookie
List<Cookie> cookies = new ArrayList<>(initialResponse.getDetailedCookies().values());

// 获取重定向目标地址
String redirectUrl = initialResponse.getHeader("Location");

// 第二步:携带Cookie发送重定向请求
given()
        .cookies(cookies)
        .when()
        .get(redirectUrl)
        .then()
        .statusCode(200);

4. 检查请求规范的Cookie设置

确认requestSpecWithToken中没有清除Cookie的操作,比如避免使用cookies().clear()这类会清空Cookie的配置。


内容的提问来源于stack exchange,提问作者Varro

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 13:10:44