【发布时间】:2018-12-12 11:36:24
【问题描述】:
当我尝试访问 /oauth/applications
我得到了 404
我看不到路线:
铁路路线 | grep oauth
我想要一个 200 并访问该页面。
我的配置:
# frozen_string_literal: true
Doorkeeper.configure do
# Change the ORM that doorkeeper will use (needs plugins)
orm :active_record
# This block will be called to check whether the resource owner is authenticated or not.
resource_owner_authenticator do
User.find_by(id: session[:current_user_id]) || redirect_to(new_user_session_url)
end
# In this flow, a token is requested in exchange for the resource owner credentials (username and password)
resource_owner_from_credentials do |_routes|
user = User.where(login: params[:username]).first
if user.valid_password?(params[:password])
user
end
end
# Access token expiration time (default 2 hours).
# If you want to disable expiration, set this to nil.
access_token_expires_in 1.day
# implicit and password grant flows have risks that you should understand
# before enabling:
# http://tools.ietf.org/html/rfc6819#section-4.4.2
# http://tools.ietf.org/html/rfc6819#section-4.4.3
#
grant_flows %w(password authorization_code client_credentials)
# grant_flows %w[password]
# Under some circumstances you might want to have applications auto-approved,
# so that the user skips the authorization step.
# For example if dealing with a trusted application.
# skip_authorization do |resource_owner, client|
# client.superapp? or resource_owner.admin?
# end
skip_authorization do
true
end
admin_authenticator do |routes|
User.find_by(id: session[:admin_id], roles: '{100}') || redirect_to(routes.new_user_session_url)
end
# default_scopes :read, :write
# optional_scopes :create, :update
# WWW-Authenticate Realm (default "Doorkeeper").
# realm "Doorkeeper"
end
在我的 router.rb 文件中:
use_doorkeeper do
# No need to register client application
skip_controllers :applications, :authorized_applications
end
【问题讨论】:
标签: ruby-on-rails oauth-2.0 doorkeeper