如何在路由之前使用身份验证中间件获取令牌。

huangapple go评论90阅读模式
英文:

how to use middleware of the auth before route to get token

问题

我该如何解决这个问题?我想在路由中获取令牌,然后路由发送响应。但在这个中间件中,我的代码在路由被调用后获取令牌。我如何访问中间件令牌以验证用户?

  1. var express = require("express");
  2. var request = require("request");
  3. var router = express.Router();
  4. var supertoken;
  5. tokenmiddleware = function(req, res, next) {
  6. console.log("这是身份验证中间件");
  7. try {
  8. var options = {
  9. method: "POST",
  10. url: "这里是我的身份验证服务器URL",
  11. headers: {
  12. json: true,
  13. Authorization: "", //
  14. "Content-Type": "application/x-www-form-urlencoded"
  15. }
  16. },
  17. form: {
  18. grant_type: "password",
  19. username: "用户名",
  20. password: "密码"
  21. };
  22. request(options, function(error, response, body1) {
  23. if (error) {
  24. throw new Error(error);
  25. } else {
  26. let info = JSON.parse(body1);
  27. //将body1解析为JSON,以便我们可以使用body1的属性。
  28. supertoken = info.access_token; //它提供了超级管理员的令牌。
  29. // console.log(supertoken)
  30. // console.log(process.env.ACCESS_TOKEN);
  31. //返回supertoken
  32. }
  33. });
  34. console.log("超级令牌");
  35. console.log(supertoken);
  36. next();
  37. } catch (error) {
  38. return res.status(401).json({ message: "身份验证失败。" });
  39. }
  40. }; //此中间件给了我一个令牌。
  41. router.post("/verifyUser", tokenmiddleware, (req, res) => {
  42. //这里我想要我的中间件令牌(但它在路由之后调用)
  43. //在这里我应用了验证用户的逻辑,但令牌不起作用(它说是未定义的)
  44. });

请注意,这是您提供的代码的中文翻译部分。

英文:

How can I solve this?
i want get token in router and then router send response.but in this middle ware my code get token after routes called.and how can i access middleware token for verify user

  1. var express = require("express");
  2. var request = require("request");
  3. var router = express.Router();
  4. var supertoken;
  5. tokenmiddleware = function(req, res, next) {
  6. console.log("this is auth middleware");
  7. try {
  8. var options = {
  9. method: "POST",
  10. url: "here is my auth server url",
  11. headers: {
  12. json: true,
  13. Authorization: "", //
  14. "Content-Type": "application/x-www-form-urlencoded"
  15. }
  16. },
  17. form: {
  18. grant_type: "password",
  19. username: "usrename",
  20. password: "password"
  21. };
  22. request(options, function(error, response, body1) {
  23. if (error) {
  24. throw new Error(error);
  25. } else {
  26. let info = JSON.parse(body1);
  27. //it parse the body1 into json so we can use property of body1.
  28. supertoken = info.access_token; //it gives the token of the super admin.
  29. // console.log(supertoken)
  30. // console.log(process.env.ACCESS_TOKEN);
  31. //return supertoken
  32. }
  33. });
  34. console.log("superrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr");
  35. console.log(supertoken);
  36. next();
  37. } catch (error) {
  38. return res.status(401).json({ message: "Auth Failed." });
  39. }
  40. }; //this middleware gave me a token.
  41. router.post("/verifyUser", tokenmiddleware, (req, res) => {
  42. //here i want my middleware token (but it calls after the route)
  43. //here i applied logic of verify user but token is not working.(it say's undefined)
  44. });

答案1

得分: 0

你的中间件包括一个异步操作的请求,并且你在请求回调之外调用了 next()。在你的中间件调用后,你在请求完成之前触发了 next(),只需将 next() 移动到请求回调内部。

  1. tokenmiddleware = function (req, res, next) {
  2. console.log('这是身份验证中间件');
  3. try {
  4. var options = {
  5. method: 'POST',
  6. url: '这里是我的身份验证服务器URL',
  7. headers: {
  8. json: true,
  9. Authorization: '', //
  10. 'Content-Type': 'application/x-www-form-urlencoded',
  11. },
  12. form: {
  13. grant_type: 'password',
  14. username: '用户名',
  15. password: '密码',
  16. },
  17. };
  18. request(options, function(error, response, body1) {
  19. if (error) {
  20. throw new Error(error);
  21. } else {
  22. let info = JSON.parse(body1);
  23. // 解析body1为JSON,以便我们可以使用body1的属性。
  24. supertoken = info.access_token; // 它提供了超级管理员的令牌。
  25. // console.log(supertoken)
  26. console.log('超级令牌');
  27. console.log(supertoken);
  28. req.userToken = info.access_token;
  29. next();
  30. }
  31. });
  32. } catch (error) {
  33. return res.status(401).json({ message: '身份验证失败。' });
  34. }
  35. };
  36. router.post("/verifyUser", tokenmiddleware, (req, res) => {
  37. console.log(req.userToken); // 应该是您的令牌
  38. });
英文:

Your middleware includes request which is an asynchronous operation. And you call next() outside of request callback. After your middleware called you fire next() before request is finished, just move next inside request callback

  1. tokenmiddleware = function (req, res, next) {
  2. console.log('this is auth middleware');
  3. try {
  4. var options = {
  5. method: 'POST',
  6. url: 'here is my auth server url',
  7. headers: {
  8. json: true,
  9. Authorization: '', //
  10. 'Content-Type': 'application/x-www-form-urlencoded',
  11. },
  12. form: {
  13. grant_type: 'password',
  14. username: 'usrename',
  15. password: 'password',
  16. },
  17. };
  18. request(options, function(error, response, body1) {
  19. if (error) {
  20. throw new Error(error);
  21. } else {
  22. let info = JSON.parse(body1);
  23. //it parse the body1 into json so we can use property of body1.
  24. supertoken = info.access_token; //it gives the token of the super admin.
  25. // console.log(supertoken)
  26. console.log('superrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr');
  27. console.log(supertoken);
  28. req.userToken = info.access_token;
  29. next();
  30. }
  31. });
  32. } catch (error) {
  33. return res.status(401).json({ message: 'Auth Failed.' });
  34. }
  35. };
  36. router.post("/verifyUser", tokenmiddleware, (req, res) => {
  37. console.log(req.userToken); // should be your token
  38. });

huangapple
  • 本文由 发表于 2020年1月3日 16:58:50
  • 转载请务必保留本文链接:https://go.coder-hub.com/59575632.html
匿名

发表评论

匿名网友

:?: :razz: :sad: :evil: :!: :smile: :oops: :grin: :eek: :shock: :???: :cool: :lol: :mad: :twisted: :roll: :wink: :idea: :arrow: :neutral: :cry: :mrgreen:

确定