刷新JWT Angular身份验证

我是纳尔逊

因此,我正在遵循以下Egghead.io指南:https ://egghead.io/lessons/angularjs-finalizing-jwt-authentication-with-angularjs

我正在尝试合并一个MongoDB来检索我的用户。到目前为止,我可以进行所有工作,除了最后一部分,他指出/ me路由应该只返回req.user,并且刷新后应该可以。我不明白 我得到的是从服务器返回的空白用户。

我的服务器代码是这样设置的:

var jwtSecret = 'fjkdlsajfoew239053/3uk';

app.use(cors());
app.use(bodyParser.json());
app.use(expressJwt({ secret: jwtSecret }).unless({ path: [ '/login' ]}));
app.use(compression());
app.use(express.static(__dirname + '/client'));
app.get('/', function(req, res){
  res.render(__dirname + '/client/bundle.js');
});

app.get('/me', function (req, res) {
  res.send(req.user);
});

... setup for user schema and other boring stuff ...

  function authenticate(req, res, next) {
    var body = req.body;
    if (!body.username || !body.password) {
      res.status(400).end('Must provide username or password');
    }

    //do salting, hashing, etc here yo
    User.findOne({ username: body.username }, function(err, user){
      if (user === null || body.password !== user.password) {
        res.status(401).end('Username or password incorrect');
      }else{
        req.user = user;
        next();
      }
    });
  }

  // ROUTES
  app.post('/login', authenticate, function (req, res, next) {
    var token = jwt.sign({
      username: req.user.username
    }, jwtSecret);
    res.send({
      token: token,
      user: req.user
    });
  });

app.listen(process.env.PORT || 5000);

而我处理基本身份验证的控制器(客户端)是:

module.exports = function($scope, $state, $modal, UserFactory) {
  var vm = this;

  $scope.$state = $state;
  $scope.sign_in = false;

  $scope.open =  function () {
    var $modalInstance = $modal.open({
      templateUrl: 'suggestion-modal.html',
      controller: 'modalCtrl'
    });
  };

  // initialization
  UserFactory.getUser().then(function success(response) {
    vm.user = response.data;
  });

  function login(username, password) {
    UserFactory.login(username, password).then(function success(response) {
      vm.user = response.data.user;
    }, handleError);
  }

  function logout() {
    UserFactory.logout();
    vm.user = null;
  }

  function handleError(response) {
    alert('Error: ' + response.data);
  }

  vm.login = login;
  vm.logout = logout;
};

有人可以抓住我在这里没有看到的错误吗?基本上,我登录时在客户端上有一个JWT,但是在客户端控制器上的初始化无法识别出我已经登录(这没有将用户对象设置为任何对象)。有点奇怪

我是纳尔逊

因此,我的解决方案最终考虑到了Kent的帮助和一些头脑风暴。它看起来像下面的样子。请注意,显然,Express中的中间件排序很重要,因为更改Express-jwt的加载时间后,是否在客户端的初始目录加载时检查身份验证标头有很大的不同(如果它们是有角度的,则不会加载,整个应用程序坏了)。干杯!

'use strict';
var faker = require('faker');
var cors = require('cors');
var bodyParser = require('body-parser');
var jwt = require('jsonwebtoken');
var expressJwt = require('express-jwt');
var compression = require('compression');
var express = require('express');
var bcrypt = require('bcrypt');
var connectLiveReload = require('connect-livereload');
var jwt = require('jsonwebtoken');
var app = express();

var jwtSecret = 'fjkdlsajfoew239053/3uk';

app.use(cors());
app.use(bodyParser.json());
app.use(compression());
app.use(express.static(__dirname + '/client'));
// app.get('/', function(req, res){
//   res.render(__dirname + '/client/bundle.js');
// });
app.use(expressJwt({ secret: jwtSecret }).unless({ path: ['/login']}));

app.get('/me', function (req, res) {
  res.send(req.user);
});


...schema stuff...

  // UTIL FUNCTIONS

  function authenticate(req, res, next) {
    var body = req.body;
    if (!body.username || !body.password) {
      res.status(400).end('Must provide username or password');
    }

    //do salting, hashing, etc here yo
    User.findOne({ username: body.username }, function(err, user){
      if (user === null || body.password !== user.password) {
        res.status(401).end('Username or password incorrect');
      }else{
        req.user = user;
        next();
      }
    });
  }

  // ROUTES
  app.post('/login', authenticate, function (req, res, next) {
    var token = jwt.sign({
      username: req.body.username
    }, jwtSecret);
    res.send({
      token: token,
      user: req.user
    });
  });

// app.use(connectLiveReload()); figure out whats wrong with this later and get livereload working

app.listen(process.env.PORT || 5000);

本文收集自互联网,转载请注明来源。

如有侵权,请联系 [email protected] 删除。

编辑于
0

我来说两句

0 条评论
登录 后参与评论

相关文章