You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Java 11 HttpClient设置会话cookie时认证失败如何解决

解决方法

核心问题原因

  • Java 11 HttpClient 内置的 CookieManager 默认使用 CookiePolicy.ACCEPT_ORIGINAL_SERVER 策略,对Cookie的域、路径匹配有严格的隐式校验,很容易出现配置了Cookie但实际未附加到请求的情况
  • 部分JDK版本对带前缀.的域配置处理存在兼容性问题,会导致Cookie匹配失败

方案1:直接手动设置Cookie头(最稳妥,无额外坑)

直接在构造HttpRequest时显式添加Cookie请求头,不需要引入CookieManager相关逻辑,修改后代码如下:

public static void main(String[] args) throws IOException, InterruptedException {
  String year = args[0];
  String day = args[1];
  String session = System.getenv("AOCSESSION");
  System.out.println(session);
  
  HttpRequest req = HttpRequest.newBuilder()
      .uri(URI.create("https://adventofcode.com/"+year+"/day/"+day+"/input"))
      .header("Cookie", "session=" + session) // 直接显式添加Cookie头
      .GET()
      .build();
  // 不需要额外配置CookieManager,使用默认客户端即可
  HttpClient client = HttpClient.newHttpClient();

  String body = client.send(req, HttpResponse.BodyHandlers.ofString()).body();
  System.out.println(body);
}

方案2:修复CookieManager配置(需要全局Cookie管理能力时使用)

如果你需要保留CookieManager做全局Cookie管理,修改两处配置即可:

  1. 给CookieManager设置宽松的Cookie接收策略
  2. 去掉Cookie域的前缀点,避免JDK版本兼容问题
    修改后代码如下:
public static void main(String[] args) throws IOException, InterruptedException {
  String year = args[0];
  String day = args[1];
  String session = System.getenv("AOCSESSION");
  System.out.println(session);
  
  HttpRequest req = HttpRequest.newBuilder()
      .uri(URI.create("https://adventofcode.com/"+year+"/day/"+day+"/input")).GET().build();
  // 初始化CookieManager时设置接受所有Cookie的策略
  CookieManager cookieManager = new CookieManager();
  cookieManager.setCookiePolicy(CookiePolicy.ACCEPT_ALL);
  HttpCookie cookie = new HttpCookie("session", session);
  cookie.setDomain("adventofcode.com"); // 不要加前缀点,避免兼容问题
  cookie.setPath("/");
  cookie.setSecure(true);
  cookieManager.getCookieStore().add(URI.create("https://adventofcode.com"), cookie);
  HttpClient client = HttpClient.newBuilder().cookieHandler(cookieManager).build();

  String body = client.send(req, HttpResponse.BodyHandlers.ofString()).body();
  System.out.println(body);
}

额外校验点

  • 确认环境变量AOCSESSION取值正确,没有多余的前后空格、换行符
  • 确认你使用的session值本身有效,可通过浏览器访问Advent of Code页面校验session未过期

内容的提问来源于stack exchange,提问作者Simon Baars

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 22:15:06