go
auth_error
ai_generated
true
rpc 错误:code = PermissionDenied desc = 缺少或无效的授权元数据
rpc error: code = PermissionDenied desc = missing or invalid authorization metadata
ID: go/grpc-permission-denied-metadata
80%修复率
88%置信度
0证据数
2025-01-20首次发现
版本兼容性
| 版本 | 状态 | 引入 | 弃用 | 备注 |
|---|---|---|---|---|
| google.golang.org/grpc v1.55+ | active | — | — | — |
根因分析
服务器端认证拦截器拒绝了请求,因为授权元数据(bearer token、API key)缺失或验证失败。
English
The server-side auth interceptor rejected the request because the authorization metadata (bearer token, API key) was missing or failed validation.
解决方案
-
95% 成功率
md := metadata.Pairs("authorization", "Bearer "+token) ctx = metadata.NewOutgoingContext(ctx, md) resp, err := client.Get(ctx, req) -
93% 成功率
func authUnary(token string) grpc.UnaryClientInterceptor { return func(ctx context.Context, method string, req, reply any, cc *grpc.ClientConn, inv grpc.UnaryInvoker, opts ...grpc.CallOption) error { ctx = metadata.AppendToOutgoingContext(ctx, "authorization", "Bearer "+token) return inv(ctx, method, req, reply, cc, opts...) } } conn, _ := grpc.NewClient(addr, grpc.WithUnaryInterceptor(authUnary(token)))
无效尝试
常见但无效的做法:
-
98% 失败
gRPC method names are fixed; query strings are not transmitted. Token never reaches the server.
-
85% 失败
Leaks the token into logs and business payloads; bypasses standard interceptor checks.