2017-08-04 75 views
1

在这背后的故事,我一直在努力从文档的说明:https://laravel.com/docs/5.4/passportLaravel 5.4 401 /未经认证使用护照和多种令牌类型

  1. Laravel 5.4
  2. “laravel /护照“:”^ 3.0“来自作曲家
  3. 本地Mac osx运行Mamp pro,Php 7.0.15

我打电话在路由示例用户路由/ api.php

Route::get('/user', function() { 
    return 'testing'; 
})->middleware('auth:api'); 

邮差卷曲头(从邮差代码出口拉动):

CURLOPT_HTTPHEADER => array(
    "accept: application/json", 
    "authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImp0aSI6ImM3ZmI2ZmNmMWFkOGQ0NjFkNTdhMWU2NjFiYjhhOThmOTJhOTBkMDFkNDkwZDFjNDRkNDg5MTdlYjJiZWYyMDlkNjNmOTQwMjIxNTljZWI5In0.eyJhdWQiOiIxIiwianRpIjoiYzdmYjZmY2YxYWQ4ZDQ2MWQ1N2ExZTY2MWJiOGE5OGY5MmE5MGQwMWQ0OTBkMWM0NGQ0ODkxN2ViMmJlZjIwOWQ2M2Y5NDAyMjE1OWNlYjkiLCJpYXQiOjE1MDE3OTQ2NjIsIm5iZiI6MTUwMTc5NDY2MiwiZXhwIjoxNTMzMzMwNjYyLCJzdWIiOiIxIiwic2NvcGVzIjpbImFwaS1hY2Nlc3MiXX0.CPGM4PIKJBeiJvokuDzShz_1CnqHlnFIML-tWoBCn5GcijMXmQkWOHzTI8QwTws2h719TGA4hemXDljjqoZB0LiztAx2JZ3OhjNS-MhrMNujnTJUbvkXAVfcRdybhlDEWof_iboLICQTYNTslX1iw-2DCyFMh8gB4INAKUhpvzA955ALB-ZunKrjSNKdRkgtZRe0t6VyJf9LwzgjIAfSKoi_qRis36KD7hcf0Id_iWZkhvS-ZfuM5eUpzUooUe0rb4rkYYEYndlHlY7-uuZPlzmPMpaJTR4AW1CLkaK5Ic7fde1x1kk2duW_Znd9ki2YBP0kw7ifAmg2DaM5r2-0kEx_1iFuCIxE8QJns1aIm3XjWoOApovt7V6-s3yJZK3xlIDCjFI-C59RHiVSabh-hKdX4elvSL9taSQyuramPZPpsne9SUh4KCWul0iHoNjFdFJEut_TUBWyUPtD3J7gg6P97uRS_THDAUHMo2UYVhlnu9PV8SvbvjGj3OeaaH7ZbzWQCYKbqsLZAZ2mnJlFhTMghbaC2s_MND1zlRm7w9btmihxVW714NUbH8UAwSvrtIYYQ0itevZ59TLiAXprjmjkhiFkrhdX4bUje4uNEbLYawkZI-1o82IExW9D8kCYpOWOZdWTCLgmaE2wXcf-DTCV-9vDWRAdX1YmP4JbRsc", 
    "cache-control: no-cache", 
    "content-type: multipart/form-data; boundary=----WebKitFormBoundary7MA4YWxkTrZu0gW", 
    "postman-token: 2ec7a2c8-3489-812d-4638-ebb7dc62aeb1" 
), 

我有使用所生成的1个个人访问令牌Vue组件

我检查了我设置了1年的令牌过期并且反映在数据库中。

我AuthServiceProvider.php

Passport::routes(); 

     // TODO MAKE THEM LAST A LONG TIME 
     Passport::tokensExpireIn(Carbon::now()->addYears(20));//You can also use addDays(10) 
     Passport::refreshTokensExpireIn(Carbon::now()->addYears(20));//You can also use addDays(10) 
     Passport::pruneRevokedTokens(); //basic garbage collector 

     Passport::tokensCan([ 
      'api-access' => 'Access Complete API', 
     ]); 

我RouteServiceProvider.php(mapApiRoutes是所谓的地图功能)

protected function mapApiRoutes() 
    { 
     Route::group([ 
      'namespace' => $this->namespace, 
      'prefix' => 'api', 
     ], function ($router) { 
      require base_path('routes/api.php'); 
     }); 
    } 

我Kernel.php路线中间件

protected $routeMiddleware = [ 
    'auth' => \Illuminate\Auth\Middleware\Authenticate::class, 
    'auth.basic' => \Illuminate\Auth\Middleware\AuthenticateWithBasicAuth::class, 
    'bindings' => \Illuminate\Routing\Middleware\SubstituteBindings::class, 
    'can' => \Illuminate\Auth\Middleware\Authorize::class, 
    'guest' => \App\Http\Middleware\RedirectIfAuthenticated::class, 
    'throttle' => \Illuminate\Routing\Middleware\ThrottleRequests::class, 
]; 

- 编辑 - 更多研究后

我正在使用邮递员来测试我的api认证,并且每次尝试时都会得到一个401。我尝试过Personal Access Client和Password Grant Client,两者都有相同的问题。看了他们两个后,我意识到两者都使用Authorization Bearer [token]格式。

因此,我开始在Passport源中的各种文件中注销。

在TokenGuard.php

public function user(Request $request) { 

    Log::info('TokenGuard: '. $request); 

    if ($request->bearerToken()) { 
     return $this->authenticateViaBearerToken($request); 
    } elseif ($request->cookie(Passport::cookie())) { 
     return $this->authenticateViaCookie($request); 
    } 
} 

日志看起来像这样:

[2017-08-10 20:50:20] local.INFO: TokenGuard 93: GET /api/user HTTP/1.1 
Accept:   application/json 
Accept-Encoding: gzip, deflate 
Cache-Control: no-cache 
Connection:  keep-alive 
Content-Type: application/json 
Host:   url.com:8888 
Postman-Token: 66707fe5-8f6e-4920-948b-2804a76d4a65 
User-Agent:  PostmanRuntime/6.2.5 


[2017-08-10 20:50:20] local.INFO: TokenGuard 93: GET /api/user HTTP/1.1 
Accept:   application/json 
Accept-Encoding: gzip, deflate 
Cache-Control: no-cache 
Connection:  keep-alive 
Content-Type: application/json 
Host:   url.com:8888 
Postman-Token: 66707fe5-8f6e-4920-948b-2804a76d4a65 
User-Agent:  PostmanRuntime/6.2.5 

事情缺少的是该请求的承载[令牌]部分。 TokenGuard代码块正在运行一个if/else。这是我认为失败正在发生的地方。

它不应该记录下来吗?由于无记名令牌缺失,所以If/Else失败,然后返回401是有意义的。

为什么我的令牌被剥离出请求。

+0

你如何让你的令牌中的JavaScript?上面的代码示例中的令牌似乎太长,您确定您没有复制粘贴加密的cookie吗? – Kyslik

+0

当您创建个人访问令牌时,Vue组件将弹出一个包含该令牌的模式。我复制它,然后使用它。我已经尝试了这三个不同的时间,以确保我没有搞砸了。 –

+0

你唯一的选择是自己调试它,使用'\ Log :: info ...'语句修改相关文件(甚至是Laravel核心文件),并看看你陷入了什么困境。玩的开心! – Kyslik

回答

3

给你的.htaccess文件添加项目的公共目录下:

RewriteEngine on 
RewriteCond %{HTTP:Authorization} ^(.*) 
RewriteRule .* - [e=HTTP_AUTHORIZATION:%1]