You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

生产环境下Devise Token Auth确认链接返回500错误求助

生产环境下Devise Token Auth邮件确认端点返回500错误排查

问题概述

使用Devise和Devise Token Auth构建SPA认证功能,开发环境流程正常,但生产环境点击邮件确认链接时返回500内部服务器错误,导致账号确认失败,且无法跳转到预期前端路由https://my-service.net/account_confirmation_success=true。

生产环境部署与请求流程

  • 部署环境:AWS ECS Fargate
  • 请求链路:Route 53 → ALB → Nginx(反向代理)→ Rails API
  • 通信方式:Nginx与Rails容器部署在同一ECS任务中,通过Unix域套接字通信

异常流程

  1. 用户注册后收到确认邮件;
  2. 邮件包含确认链接:https://api.my-service.net/api/v1/auth/confirmation?config=default&confirmation_token=hogefugabar;
  3. 点击链接触发500错误,无法跳转至前端成功页面。

补充细节

  • api.my-service.net已在Route 53正确配置A记录指向ALB;
  • 开发环境确认流程完全正常;
  • 推测密码重置邮件可能存在相同问题(未验证);
  • Nginx反向代理对其他API请求工作正常,Rails应用可正常响应。

技术栈

  • Ruby 3.3.7
  • Rails 7.2.2.1(API模式)

相关配置代码

user.rb

devise :database_authenticatable, :registerable,
       :recoverable, :validatable, :confirmable
  # :lockable, :timeoutable, :trackable, :omniauthable, :rememberable

  include DeviseTokenAuth::Concerns::User

confirmation_instructions.html.erb

<p><%= @email %>, </p>

<p>Thank you for registering your account!</p>

<p>Please click the link below to complete your registration. </p><br>

<p>
  <%= link_to “Verify your account”, confirmation_url(@resource, {
    confirmation_token: @token,
    config: message[‘client-config’].to_s,
  }).html_safe %>
</p>

<p>The link is valid for 3 days. Please respond as soon as possible. </p><br>

devise_token_auth.rb

# DEFAULT_CONFIRM_SUCCESS_URL and DEFAULT_PASSWORD_RESET_URL are passed as environment variables in the ECS task definition.

config.default_confirm_success_url = ENV["DEFAULT_CONFIRM_SUCCESS_URL"] || "http://localhost:3000"

config.default_password_reset_url = ENV["DEFAULT_PASSWORD_RESET_URL"] || "http://localhost:3000/password-reset"

config.redirect_whitelist = [
    "https://www.my-service.net",
    "https://www.my-service.net/password-reset"
]

production.rb

config.action_mailer.default_url_options = { host: "https://api.my-service.net" }
config.hosts << "api.my-service.net"

cors.rb

Rails.application.config.middleware.insert_before 0, Rack::Cors do
  allow do
    origins "http://localhost:3000", "https://www.my-service.net", "https://api.my-service.net"

    resource "*",
      headers: :any,
      expose:  [
        "access-token", "expiry", "token-type", "uid", "client",
        "current-page", "page-items", "total-count", "total-pages"
      ],
      methods: [:get, :post, :put, :patch, :delete, :options, :head]
  end
end

nginx.conf

upstream api {
  server unix:///app/tmp/sockets/puma.sock;
}

server {
  listen 80;
  server_name localhost;

  access_log /var/log/nginx/access.log;
  error_log  /var/log/nginx/error.log;

  root /app/public;

  client_max_body_size 100m;

  keepalive_timeout 5;

  location = /healthcheck {
    access_log off;
    return 200 "OK";
    add_header Content-Type text/plain;
  }

  error_page 404             /404.html;
  error_page 502 503 504 505 /500.html;

  location = /404.html {
    internal;
  }

  location = /500.html {
    internal;
  }

  try_files $uri @api;

  location @api {
    proxy_pass             http://api;
    proxy_set_header       Host $host;
    proxy_set_header       X-Real-IP $remote_addr;
    proxy_set_header       X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_intercept_errors on;
  }
}

CloudWatch日志信息

"GET /api/v1/auth/confirmation?config=default&confirmation_token=ZhpLxqjmVbs4kgxS_QfH HTTP/1.1" 500 26 "-" "Mozilla/5.0
[error] 14#14: *99 open() "/app/public/404.html" failed (2: No such file or directory), client: 10.0.1.23, server: localhost, request: "GET /favicon.ico HTTP/1.1", upstream: "http://unix:///app/tmp/sockets/puma.sock/favicon.ico", host: "api.my-service.net", referrer: "https://api.my-service.net/api/v1/auth/confirmation?config=default&confirmation_token=ZhpLxqjmVbs4kgxS_QfH"

排查请求

目前已确认GET /api/v1/auth/confirmation请求已到达后端但执行失败,无法定位Devise Token Auth的confirmations_controller.rb返回500错误的原因。请提供该问题的排查指导或解决方案。

内容的提问来源于stack exchange,提问作者y4tk8

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 22:53:11