Swift 3中发送Authorization Headers失败:服务器未接收到该请求头
Hey there, let's work through why your server isn't receiving the Authorization header. I've dealt with this exact issue a few times, so here are the most likely fixes to test out:
1. Check CORS Configuration (If It's a Cross-Origin Request)
If your frontend is making requests from a different domain, browsers will block custom headers like Authorization unless your server explicitly allows them. You need to set the right CORS headers:
- Add
Access-Control-Allow-Headers: Authorizationto your server's response headers - Make sure you also include other required CORS headers like
Access-Control-Allow-Origin
Here's an example for Node.js/Express:
app.use((req, res, next) => { // Replace * with your frontend's actual domain for production res.header('Access-Control-Allow-Origin', '*'); res.header( 'Access-Control-Allow-Headers', 'Origin, X-Requested-With, Content-Type, Authorization' ); res.header('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS'); // Handle preflight OPTIONS requests if (req.method === 'OPTIONS') { return res.sendStatus(200); } next(); });
2. Ensure You're Using the Correct Authorization Scheme
JWT tokens almost always require the Bearer prefix in the header. Your request should look like this:
Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9...
If you're just sending the token without Bearer , most server-side auth middleware won't recognize it. Double-check your client-side code:
// Example with fetch API fetch('/your-protected-endpoint', { method: 'GET', headers: { 'Authorization': `Bearer ${yourToken}` // *Don't forget the Bearer prefix!* } });
3. Verify Server-Side Middleware Order & Setup
If you're using auth middleware (like Passport.js or a custom JWT verifier), make sure:
- The middleware is loaded before your protected routes
- You're correctly extracting the token from the header
Here's a simple custom JWT verification middleware to test with:
const jwt = require('jsonwebtoken'); const verifyToken = (req, res, next) => { // Extract token from Authorization header (split "Bearer" and the token string) const authHeader = req.headers['authorization']; const token = authHeader && authHeader.split(' ')[1]; if (!token) { return res.sendStatus(401); // No token provided } jwt.verify(token, process.env.JWT_SECRET, (err, user) => { if (err) return res.sendStatus(403); // Invalid token req.user = user; next(); }); }; // Apply the middleware to your protected routes app.get('/protected', verifyToken, (req, res) => { res.send('You have access to this protected content!'); });
4. Check for Proxy/Reverse Proxy Interference
If your server sits behind a proxy (like Nginx), the proxy might be stripping the Authorization header by default. You need to configure it to pass the header through:
For Nginx, add this to your location block:
location / { proxy_pass http://your-server-ip:port; proxy_set_header Authorization $http_authorization; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; }
5. Validate the Request with Browser Dev Tools
Before diving deeper into server code, confirm the header is actually being sent:
- Open your browser's DevTools (F12)
- Go to the Network tab
- Make the request that should include the Authorization header
- Click on the request, then check the Headers section
- Look for the
Authorizationfield in the Request Headers
If it's not there, the issue is on the client side—double-check your request setup.
内容的提问来源于stack exchange,提问作者Russel Ramirez

