You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Rest Assured手动传Cookie仍报HTTP 401错误,求代码排查

Fixing Rest Assured 401 Error When Using Session Cookies

Hey there! I spot the issue right away — let's get your test working properly.

The Core Problem

You're using param("Cookie", "...") to pass your session cookies, but param() adds query parameters to the URL, not request headers. Postman correctly sends cookies in the Cookie request header, but your current code is appending the cookie string as a URL parameter (like .../articles?Cookie=...). The server never receives the valid session cookies it needs to authorize your request, hence the 401 Unauthorized error.

Correct Ways to Send Cookies in Rest Assured

There are a few clean, effective ways to send cookies with your request:

1. Add Cookies Individually (Most Readable)

Use the cookie() method for each cookie key-value pair:

import static io.restassured.RestAssured.given;
import static org.hamcrest.Matchers.equalTo;
import org.testng.annotations.Test;
import io.restassured.RestAssured;

public class getart {
    @Test
    public void Test1() {
        RestAssured.useRelaxedHTTPSValidation();
        // Don't forget to add the port if your server uses one (e.g., https://localhost:8443)
        RestAssured.baseURI="https://localhost";
        
        given()
            .cookie("JSESSIONID", "B1FAC334FF60F7182D4C552ABE01A700")
            .cookie("hi.session.co.entity", "1838-PROD1")
            .cookie("hi.session.id.identifier", "xHmvClBuIBcSKAEiVP~~AAAESADWaUjq")
            .cookie("hi.session.client.identifier", "1838Viewer")
        .when()
            .get("/hi-prod/3.1.12/al/api/articles")
        .then()
            .assertThat().statusCode(200)
            .body("status", equalTo("OK"))
            .log().body();
    }
}

2. Batch Cookies with a Map

If you have multiple cookies, use a Map and the cookies() method to add them all at once:

import static io.restassured.RestAssured.given;
import static org.hamcrest.Matchers.equalTo;
import java.util.HashMap;
import java.util.Map;
import org.testng.annotations.Test;
import io.restassured.RestAssured;

public class getart {
    @Test
    public void Test1() {
        RestAssured.useRelaxedHTTPSValidation();
        RestAssured.baseURI="https://localhost";
        
        Map<String, String> sessionCookies = new HashMap<>();
        sessionCookies.put("JSESSIONID", "B1FAC334FF60F7182D4C552ABE01A700");
        sessionCookies.put("hi.session.co.entity", "1838-PROD1");
        sessionCookies.put("hi.session.id.identifier", "xHmvClBuIBcSKAEiVP~~AAAESADWaUjq");
        sessionCookies.put("hi.session.client.identifier", "1838Viewer");
        
        given()
            .cookies(sessionCookies)
        .when()
            .get("/hi-prod/3.1.12/al/api/articles")
        .then()
            .assertThat().statusCode(200)
            .body("status", equalTo("OK"))
            .log().body();
    }
}

3. Directly Set the Cookie Header

If you prefer to use the full cookie string like you did in Postman, use the header() method to set the Cookie request header directly:

given()
    .header("Cookie", "JSESSIONID=B1FAC334FF60F7182D4C552ABE01A700; hi.session.co.entity=1838-PROD1; hi.session.id.identifier=xHmvClBuIBcSKAEiVP~~AAAESADWaUjq; hi.session.client.identifier=1838Viewer")
// ... rest of your request code

Additional Debug Tips

  • Check the Base URI: Make sure RestAssured.baseURI includes the correct port (if your server uses one). Postman might have this set automatically, but your code might not.
  • Log Request Details: Add .log().all() to the given() section to print the full request (headers, URL, etc.) and compare it directly to Postman's request. This helps spot any missing headers or differences:
    given()
        .log().all() // Prints all request details for debugging
        .cookies(sessionCookies)
    // ...
    
  • Verify Other Headers: Some servers require additional headers (like User-Agent or Accept) that Postman adds by default. If the above fixes don't work, check Postman's "Headers" tab and replicate any missing ones in your code with .header().

内容的提问来源于stack exchange,提问作者Madhusudhan R

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:44:58