以Windows AD用户运行Node.js脚本请求Windows认证应用返回401问题
Hey there, the issue here is that the vanilla request library doesn't handle Windows Authentication (NTLM/Kerberos) out of the box. Even though you're running the script as your AD user in CMD, the request isn't automatically attaching your Windows credentials to the request—which is exactly why you're getting that 401 Unauthorized response.
Let me walk you through two solid solutions to fix this:
Solution 1: Use Automatic Windows Credentials (Recommended)
This approach uses the node-sspi library to automatically fetch and use your currently logged-in AD user's credentials—no need to manually enter or store your password, which is safer and more convenient for interactive use.
- First, install the required dependencies:
npm install request node-sspi
- Update your script to integrate SSPI authentication:
const request = require('request'); const { SSPIClient } = require('node-sspi'); console.log(process.env.USERDOMAIN); console.log(process.env.USERNAME); const sspiClient = new SSPIClient(); const requestOptions = { url: 'http://internalurl', headers: {} }; // Handle Windows authentication via SSPI sspiClient.authenticate(requestOptions, (authError) => { if (authError) { console.error('SSPI authentication failed:', authError); return; } // Send the authenticated request request(requestOptions, function (reqError, response, body) { if (reqError) { console.error('Request failed:', reqError); return; } if (response.statusCode === 200) { console.log('request successful!...'); } else { console.log(`Request failed with status code: ${response.statusCode}`); console.log('Response details:', body); } }); });
Solution 2: NTLM Authentication with Manual Password Input
If you need to specify credentials explicitly (for non-interactive scenarios, for example), use the request-ntlm library which adds NTLM support to the request framework.
- Install the dependency:
npm install request-ntlm
- Modify your script to include NTLM credentials:
const ntlm = require('request-ntlm'); const domain = process.env.USERDOMAIN; const username = process.env.USERNAME; const password = 'your-actual-ad-password'; // Replace with your AD password console.log(domain); console.log(username); ntlm.get({ url: 'http://internalurl', username: username, password: password, domain: domain }, function (reqError, response, body) { if (reqError) { console.error('Request error:', reqError); return; } if (response.statusCode === 200) { console.log('request successful!...'); } else { console.log(`Request failed with status code: ${response.statusCode}`); console.log('Response details:', body); } });
Extra Notes
- Security Tip: Avoid hardcoding passwords in your script—use environment variables or a secure secrets manager if you go with Solution 2.
- Verify that your web application is configured to accept NTLM or Kerberos authentication, and that your AD user has been granted access to the resource.
- If issues persist, check the web server's access logs to confirm whether the problem is missing credentials or actual permission restrictions.
内容的提问来源于stack exchange,提问作者Citizen SP

