You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Swift 3中发送Authorization Headers失败:服务器未接收到该请求头

Troubleshooting Missing Authorization Header on Your Server

Hey there, let's work through why your server isn't receiving the Authorization header. I've dealt with this exact issue a few times, so here are the most likely fixes to test out:

1. Check CORS Configuration (If It's a Cross-Origin Request)

If your frontend is making requests from a different domain, browsers will block custom headers like Authorization unless your server explicitly allows them. You need to set the right CORS headers:

  • Add Access-Control-Allow-Headers: Authorization to your server's response headers
  • Make sure you also include other required CORS headers like Access-Control-Allow-Origin

Here's an example for Node.js/Express:

app.use((req, res, next) => {
  // Replace * with your frontend's actual domain for production
  res.header('Access-Control-Allow-Origin', '*');
  res.header(
    'Access-Control-Allow-Headers',
    'Origin, X-Requested-With, Content-Type, Authorization'
  );
  res.header('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS');
  
  // Handle preflight OPTIONS requests
  if (req.method === 'OPTIONS') {
    return res.sendStatus(200);
  }
  next();
});

2. Ensure You're Using the Correct Authorization Scheme

JWT tokens almost always require the Bearer prefix in the header. Your request should look like this:

Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9...

If you're just sending the token without Bearer , most server-side auth middleware won't recognize it. Double-check your client-side code:

// Example with fetch API
fetch('/your-protected-endpoint', {
  method: 'GET',
  headers: {
    'Authorization': `Bearer ${yourToken}` // *Don't forget the Bearer prefix!*
  }
});

3. Verify Server-Side Middleware Order & Setup

If you're using auth middleware (like Passport.js or a custom JWT verifier), make sure:

  • The middleware is loaded before your protected routes
  • You're correctly extracting the token from the header

Here's a simple custom JWT verification middleware to test with:

const jwt = require('jsonwebtoken');

const verifyToken = (req, res, next) => {
  // Extract token from Authorization header (split "Bearer" and the token string)
  const authHeader = req.headers['authorization'];
  const token = authHeader && authHeader.split(' ')[1];

  if (!token) {
    return res.sendStatus(401); // No token provided
  }

  jwt.verify(token, process.env.JWT_SECRET, (err, user) => {
    if (err) return res.sendStatus(403); // Invalid token
    req.user = user;
    next();
  });
};

// Apply the middleware to your protected routes
app.get('/protected', verifyToken, (req, res) => {
  res.send('You have access to this protected content!');
});

4. Check for Proxy/Reverse Proxy Interference

If your server sits behind a proxy (like Nginx), the proxy might be stripping the Authorization header by default. You need to configure it to pass the header through:

For Nginx, add this to your location block:

location / {
  proxy_pass http://your-server-ip:port;
  proxy_set_header Authorization $http_authorization;
  proxy_set_header Host $host;
  proxy_set_header X-Real-IP $remote_addr;
}

5. Validate the Request with Browser Dev Tools

Before diving deeper into server code, confirm the header is actually being sent:

  1. Open your browser's DevTools (F12)
  2. Go to the Network tab
  3. Make the request that should include the Authorization header
  4. Click on the request, then check the Headers section
  5. Look for the Authorization field in the Request Headers

If it's not there, the issue is on the client side—double-check your request setup.


内容的提问来源于stack exchange,提问作者Russel Ramirez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:35:19