You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Postman请求401未授权排查:JWT Token不含认证字符串

Alright, let's figure out why your /website/api/users/login endpoint is throwing a 401 Unauthorized error. I've gone through your error logs and Spring Security configuration, and here's the root cause and step-by-step fixes:

Root Cause

Looking at your setup closely:

  • Your actual login endpoint is /website/api/users/login, but in your WebSecurityConfig's configure(HttpSecurity) method, you've only added "/users/login" to the list of paths allowed for anonymous access. This path mismatch means the login endpoint isn't being excluded from JWT validation.
  • The JwtRequestFilter runs on every request (including login) because the path wasn't properly whitelisted. Since a login request doesn't carry a JWT token yet, the filter throws the warning JWT Token does not contain auth string and triggers your MyAuthenticationEntryPoint to return a 401.
  • Your configure(WebSecurity) method ignores "/authenticate", which doesn't match your login path, so that configuration doesn't help here.

Fixes

Let's resolve this with these straightforward steps:

  1. Correct the whitelisted paths in HttpSecurity
    Update the antMatchers in your configure(HttpSecurity) method to include the full path of your login endpoint (and other public user endpoints):

    @Override
    protected void configure(HttpSecurity httpSecurity) throws Exception {
        httpSecurity.cors();
        httpSecurity.csrf().disable()
            .authorizeRequests()
                .antMatchers(
                    "/website/api/users/login",
                    "/website/api/users/addUser",
                    "/website/api/users/addCustomer",
                    "/",
                    "/v2/**",
                    "/swagger-ui.html",
                    "/webjars/**",
                    "/swagger-resources/**"
                ).permitAll()
                .anyRequest().authenticated()
            .and()
                .exceptionHandling().authenticationEntryPoint(jwtAuthenticationEntryPoint)
            .and()
                .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS);
    
        httpSecurity.addFilterBefore(jwtRequestFilter, UsernamePasswordAuthenticationFilter.class);
    }
    

    This ensures the login and user registration endpoints are accessible without a JWT token.

  2. Add a safety check in JwtRequestFilter (optional but recommended)
    Even with the HttpSecurity fix, adding a check in your filter to skip validation for the login path adds an extra layer of safety. Modify the doFilterInternal method:

    @Override
    protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain chain) throws ServletException, IOException {
        String requestUri = request.getRequestURI();
        // Skip JWT validation for login endpoint
        if ("/website/api/users/login".equals(requestUri)) {
            chain.doFilter(request, response);
            return;
        }
        // Your existing JWT validation logic here...
    }
    
  3. Update WebSecurity ignore list (optional)
    If you want Spring Security to completely skip filtering for the login endpoint, update the configure(WebSecurity) method:

    @Override
    public void configure(WebSecurity web) throws Exception {
        web.ignoring().antMatchers("/authenticate", "/website/api/users/login");
    }
    

Verification

After making these changes, restart your backend service. Now when you send a POST request to /website/api/users/login via Postman, the request will bypass JWT validation, reach your login handler, and you won't get the 401 error anymore.

内容的提问来源于stack exchange,提问作者Manoj Obbilisetty

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 16:37:36