Laravel 5.6配置JWT.auth:实现Token通过Header传递验证
Hey there, let's troubleshoot why your JWT token works when sent in the raw JSON body but not in the request header. This is a common issue with JWT authentication, and we'll go through the most likely fixes step by step.
1. Check Your Postman Header Format First
The #1 culprit here is usually an incorrectly formatted Authorization header. JWT standards expect the header to follow this structure:
- Header Key:
Authorization - Header Value:
Bearer YOUR_JWT_TOKEN(make sure there's a space betweenBearerand your token string)
If you're just pasting the token directly without the Bearer prefix, the jwt.auth middleware won't recognize it as a valid token source. Test this first—update your Postman header and resend the request.
2. Verify JWT Package Configuration
Assuming you're using the popular tymondesigns/jwt-auth package for Laravel, check your configuration to ensure it's set up to read tokens from the header:
- Open
config/jwt.php(runphp artisan vendor:publish --provider="Tymon\JWTAuth\Providers\LaravelServiceProvider"if you don't see this file) - Look for the
token_getterclosure. It should prioritize the header's Bearer token before falling back to request parameters:'token_getter' => function ($request) { // First try to get token from Authorization header (Bearer format) $token = $request->bearerToken(); // If not found, check for a "token" parameter in body/query if (empty($token)) { $token = $request->get('token'); } return $token; },
If this closure was modified to skip the header check, that's why your body token works but the header doesn't. Restore the default logic to allow both sources.
3. Confirm Your Authentication Middleware Logic
If you're using a custom middleware instead of the default jwt.auth, make sure it's correctly parsing the token from the header. Here's a standard implementation to reference:
public function handle($request, Closure $next) { try { // This method automatically looks for the Bearer token in the Authorization header $user = JWTAuth::parseToken()->authenticate(); } catch (\Exception $e) { if ($e instanceof \Tymon\JWTAuth\Exceptions\TokenInvalidException){ return response()->json(['status' => 'Token is Invalid']); }else if ($e instanceof \Tymon\JWTAuth\Exceptions\TokenExpiredException){ return response()->json(['status' => 'Token is Expired']); }else{ return response()->json(['status' => 'Authorization Token not found']); } } return $next($request); }
The parseToken() method is key here—it handles extracting the token from the correct header format.
4. Check for Server/Proxy Header Blocking
If you're testing on a live server (not local), your web server or reverse proxy might be stripping the Authorization header. For example, in Nginx, you need to explicitly pass the header to your Laravel app:
Add this line to your Nginx location block:
proxy_set_header Authorization $http_authorization;
This ensures the Authorization header isn't lost when the request is forwarded to your application.
内容的提问来源于stack exchange,提问作者Ahmed Guesmi

