【问题标题】:Symfony 4 - JWT not found with LexikJWTAuthenticationBundleSymfony 4 - 在 LexikJWTAuthenticationBundle 中找不到 JWT
【发布时间】:2020-11-30 08:16:49
【问题描述】:

下午好,

我尝试在我的项目中使用 LexikJWTAuthenticationBundle,但我遇到了未生成令牌的问题。我已经在 var/jwt 目录中设置了私钥和公钥。

当我尝试使用登录路由时,API 会返回此响应:

{
    "code": 401,
    "message": "JWT Token not found"
}

Apache 虚拟主机:

<VirtualHost *:80>
    ServerName ypostirixi
    DocumentRoot "/var/www/ypostirixi/public"

    RewriteEngine On
    RewriteCond %{HTTP:Authorization} ^(.*)
    RewriteRule .* - [e=HTTP_AUTHORIZATION:%1]
</VirtualHost>

公共目录中的.htaccess文件:

<IfModule mod_rewrite.c>
    RewriteEngine On

    RewriteCond %{HTTP:Authorization} ^(.*)
    RewriteRule .* - [e=HTTP_AUTHORIZATION:%1]

    # Send would-be 404 requests to Craft
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteRule (.+) index.php?p=$1 [QSA,L]
</IfModule>

security.yaml 安全性:

encoders:
    App\Entity\User:
        algorithm: bcrypt
providers:
    doctrine_provider:
        entity:
            class: App\Entity\User
            property: email

firewalls:
    dev:
        pattern: ^/(_(profiler|wdt)|css|images|js)/
        security: false
    api_doc:
        pattern:  ^/api/doc
        security: false
    api:
        pattern:   ^/api
        stateless: true
        guard:
            authenticators:
                - lexik_jwt_authentication.jwt_token_authenticator
    main:
        pattern:   ^/
        stateless: true
        guard:
            authenticators:
                - lexik_jwt_authentication.jwt_token_authenticator
        provider: doctrine_provider

access_control:
    - { path: ^/api/login, roles: IS_AUTHENTICATED_ANONYMOUSLY }
    - { path: ^/api,       roles: IS_AUTHENTICATED_FULLY }

我希望成功使用登录路由并在其他路由上生成有效令牌。

【问题讨论】:

    标签: php symfony jwt lexikjwtauthbundle nelmioapidocbundle


    【解决方案1】:

    感谢您的帮助。

    我发现了有关此升级的问题,但我有解决方案。

    在 lexik_jwt_authentication.yaml 文件中:

    lexik_jwt_authentication:
        secret_key: '%env(resolve:JWT_SECRET_KEY)%'
        public_key: '%env(resolve:JWT_PUBLIC_KEY)%'
        pass_phrase: '%env(JWT_PASSPHRASE)%'
        token_ttl: '%env(JWT_TTL)%'
        token_extractors:
            authorization_header:
                enabled: true
                prefix:  '%env(JWT_TOKEN_PREFIX)%'
                name:    Authorization
        user_identity_field: email
    

    【讨论】:

      【解决方案2】:
      • 可能您忘记在防火墙或登录参数(电子邮件作为用户名)中配置登录防火墙..

      检查一下

      1 config/packages/security.yaml

          firewalls:
              login:
                  pattern:  ^/api/login
                  stateless: true
                  anonymous: true
                  form_login:
                      check_path:               /api/login_check
                      username_parameter: email
                      password_parameter: password
                      success_handler:          lexik_jwt_authentication.handler.authentication_success
                      failure_handler:          lexik_jwt_authentication.handler.authentication_failure
                      require_previous_session: false
      
              api:
                  pattern:   ^/api
                  stateless: true
                  guard:
                     authenticators:
                         - lexik_jwt_authentication.jwt_token_authenticator
              access_control:
                  - { path: ^/api/login$, role: IS_AUTHENTICATED_ANONYMOUSLY }
                  - { path: ^/api/, role: IS_AUTHENTICATED_FULLY }
      

      2 config/routes.yaml

      api_login_check:
          path: /api/login_check
      

      3 用 curl 测试一下

      X POST -H "Content-Type: application/json" http://localhost/api/login_check -d '{"email":"user@example.com","password":"pass"}'
      

      注意:如果不适合您,可能是您跳过了配置步骤或未正确配置捆绑包,您必须在文档中查看 https://github.com/lexik/LexikJWTAuthenticationBundle/blob/master/Resources/doc/index.md#installation

      【讨论】:

        【解决方案3】:

        您不允许匿名访问任何防火墙。您应该在主防火墙中添加匿名选项。

            main:
                pattern:   ^/
                stateless: true
                anonymous: true
                guard:
                    authenticators:
                        - lexik_jwt_authentication.jwt_token_authenticator
                provider: doctrine_provider
        

        【讨论】:

          猜你喜欢
          • 2019-01-27
          • 2019-09-23
          • 1970-01-01
          • 1970-01-01
          • 2018-08-09
          • 1970-01-01
          • 1970-01-01
          • 2018-08-05
          • 1970-01-01
          相关资源
          最近更新 更多