使用Rest Assured手动传Cookie仍报HTTP 401错误,求代码排查
Hey there! I spot the issue right away — let's get your test working properly.
The Core Problem
You're using param("Cookie", "...") to pass your session cookies, but param() adds query parameters to the URL, not request headers. Postman correctly sends cookies in the Cookie request header, but your current code is appending the cookie string as a URL parameter (like .../articles?Cookie=...). The server never receives the valid session cookies it needs to authorize your request, hence the 401 Unauthorized error.
Correct Ways to Send Cookies in Rest Assured
There are a few clean, effective ways to send cookies with your request:
1. Add Cookies Individually (Most Readable)
Use the cookie() method for each cookie key-value pair:
import static io.restassured.RestAssured.given; import static org.hamcrest.Matchers.equalTo; import org.testng.annotations.Test; import io.restassured.RestAssured; public class getart { @Test public void Test1() { RestAssured.useRelaxedHTTPSValidation(); // Don't forget to add the port if your server uses one (e.g., https://localhost:8443) RestAssured.baseURI="https://localhost"; given() .cookie("JSESSIONID", "B1FAC334FF60F7182D4C552ABE01A700") .cookie("hi.session.co.entity", "1838-PROD1") .cookie("hi.session.id.identifier", "xHmvClBuIBcSKAEiVP~~AAAESADWaUjq") .cookie("hi.session.client.identifier", "1838Viewer") .when() .get("/hi-prod/3.1.12/al/api/articles") .then() .assertThat().statusCode(200) .body("status", equalTo("OK")) .log().body(); } }
2. Batch Cookies with a Map
If you have multiple cookies, use a Map and the cookies() method to add them all at once:
import static io.restassured.RestAssured.given; import static org.hamcrest.Matchers.equalTo; import java.util.HashMap; import java.util.Map; import org.testng.annotations.Test; import io.restassured.RestAssured; public class getart { @Test public void Test1() { RestAssured.useRelaxedHTTPSValidation(); RestAssured.baseURI="https://localhost"; Map<String, String> sessionCookies = new HashMap<>(); sessionCookies.put("JSESSIONID", "B1FAC334FF60F7182D4C552ABE01A700"); sessionCookies.put("hi.session.co.entity", "1838-PROD1"); sessionCookies.put("hi.session.id.identifier", "xHmvClBuIBcSKAEiVP~~AAAESADWaUjq"); sessionCookies.put("hi.session.client.identifier", "1838Viewer"); given() .cookies(sessionCookies) .when() .get("/hi-prod/3.1.12/al/api/articles") .then() .assertThat().statusCode(200) .body("status", equalTo("OK")) .log().body(); } }
3. Directly Set the Cookie Header
If you prefer to use the full cookie string like you did in Postman, use the header() method to set the Cookie request header directly:
given() .header("Cookie", "JSESSIONID=B1FAC334FF60F7182D4C552ABE01A700; hi.session.co.entity=1838-PROD1; hi.session.id.identifier=xHmvClBuIBcSKAEiVP~~AAAESADWaUjq; hi.session.client.identifier=1838Viewer") // ... rest of your request code
Additional Debug Tips
- Check the Base URI: Make sure
RestAssured.baseURIincludes the correct port (if your server uses one). Postman might have this set automatically, but your code might not. - Log Request Details: Add
.log().all()to thegiven()section to print the full request (headers, URL, etc.) and compare it directly to Postman's request. This helps spot any missing headers or differences:given() .log().all() // Prints all request details for debugging .cookies(sessionCookies) // ... - Verify Other Headers: Some servers require additional headers (like
User-AgentorAccept) that Postman adds by default. If the above fixes don't work, check Postman's "Headers" tab and replicate any missing ones in your code with.header().
内容的提问来源于stack exchange,提问作者Madhusudhan R

