Postman请求401未授权排查:JWT Token不含认证字符串
Alright, let's figure out why your /website/api/users/login endpoint is throwing a 401 Unauthorized error. I've gone through your error logs and Spring Security configuration, and here's the root cause and step-by-step fixes:
Root Cause
Looking at your setup closely:
- Your actual login endpoint is
/website/api/users/login, but in yourWebSecurityConfig'sconfigure(HttpSecurity)method, you've only added"/users/login"to the list of paths allowed for anonymous access. This path mismatch means the login endpoint isn't being excluded from JWT validation. - The
JwtRequestFilterruns on every request (including login) because the path wasn't properly whitelisted. Since a login request doesn't carry a JWT token yet, the filter throws the warningJWT Token does not contain auth stringand triggers yourMyAuthenticationEntryPointto return a 401. - Your
configure(WebSecurity)method ignores"/authenticate", which doesn't match your login path, so that configuration doesn't help here.
Fixes
Let's resolve this with these straightforward steps:
Correct the whitelisted paths in HttpSecurity
Update theantMatchersin yourconfigure(HttpSecurity)method to include the full path of your login endpoint (and other public user endpoints):@Override protected void configure(HttpSecurity httpSecurity) throws Exception { httpSecurity.cors(); httpSecurity.csrf().disable() .authorizeRequests() .antMatchers( "/website/api/users/login", "/website/api/users/addUser", "/website/api/users/addCustomer", "/", "/v2/**", "/swagger-ui.html", "/webjars/**", "/swagger-resources/**" ).permitAll() .anyRequest().authenticated() .and() .exceptionHandling().authenticationEntryPoint(jwtAuthenticationEntryPoint) .and() .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS); httpSecurity.addFilterBefore(jwtRequestFilter, UsernamePasswordAuthenticationFilter.class); }This ensures the login and user registration endpoints are accessible without a JWT token.
Add a safety check in JwtRequestFilter (optional but recommended)
Even with the HttpSecurity fix, adding a check in your filter to skip validation for the login path adds an extra layer of safety. Modify thedoFilterInternalmethod:@Override protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain chain) throws ServletException, IOException { String requestUri = request.getRequestURI(); // Skip JWT validation for login endpoint if ("/website/api/users/login".equals(requestUri)) { chain.doFilter(request, response); return; } // Your existing JWT validation logic here... }Update WebSecurity ignore list (optional)
If you want Spring Security to completely skip filtering for the login endpoint, update theconfigure(WebSecurity)method:@Override public void configure(WebSecurity web) throws Exception { web.ignoring().antMatchers("/authenticate", "/website/api/users/login"); }
Verification
After making these changes, restart your backend service. Now when you send a POST request to /website/api/users/login via Postman, the request will bypass JWT validation, reach your login handler, and you won't get the 401 error anymore.
内容的提问来源于stack exchange,提问作者Manoj Obbilisetty

