【发布时间】:2020-05-27 17:02:45
【问题描述】:
我已经使用自定义服务在我的 lb4 应用程序中成功实现了 jwt auth,该服务实现了来自 @loopback/authentication-jwt 的 userservice。一切都可以正常进行身份验证。
但是当我去授权时,AuthorizationMetadata 只包含两个字段 - id 和 name。在发布令牌时,我使用了许多字段,其中之一是 role。
但是现在角色或电子邮件等所有其他字段都未定义。因此,每当我尝试访问受授权装饰器保护的控制器时,我都会收到 501 access denied.
我不明白为什么其他属性未定义。
提前谢谢你
定制服务
export class CustomUserService implements UserService<User, Credentials> {
// other code
convertToUserProfile(user: User): UserProfile {
let address = ''
if (user.address) {
address = user.address
}
const profile = {
[securityId]: user.id!.toString(),
name: user.name,
id: user.id,
email: user.email,
role: user.role,
address: user.address
}
console.log(profile)
return profile
}
}
登录控制器
import {authenticate, TokenService, UserService} from '@loopback/authentication';
export class UserController {
constructor(@inject(SecurityBindings.USER, {optional: true})
public users: UserProfile,){}
//@get login
async login(
@requestBody(CredentialsRequestBody) credentials: Credentials,
): Promise<{token: string}> {
// ensure the user exists, and the password is correct
const user = await this.userService.verifyCredentials(credentials);
// convert a User object into a UserProfile object (reduced set of properties)
const userProfile = this.userService.convertToUserProfile(user);
// create a JSON Web Token based on the user profile
const token = await this.jwtService.generateToken(userProfile);
return {token};
}
authorizer.ts
import {AuthorizationContext, AuthorizationDecision, AuthorizationMetadata} from '@loopback/authorization';
export async function basicAuthorization(
authorizationCtx: AuthorizationContext,
metadata: AuthorizationMetadata,
): Promise<AuthorizationDecision> {
// No access if authorization details are missing
let currentUser: UserProfile;
if (authorizationCtx.principals.length > 0) {
const user = _.pick(authorizationCtx.principals[0]
, [
'id',
'name',
'role',
'email',
'address'
]);
console.log(user) // contains only id and name
// other code
}
}
【问题讨论】:
标签: loopback4