【问题标题】:Crypto Exception in ElixirElixir 中的加密异常
【发布时间】:2018-10-06 17:11:31
【问题描述】:

我已经配置了一个 elixir 应用并定义了管理路由。但是,我在尝试访问任何路由时遇到以下错误。

(exit) 引发异常: ** (ArgumentError) 参数错误 (加密) :crypto.hmac_nif(:sha256, {:system, "Zpumk6KLEY8Qx826qspHhYrpTpDswFzHL/64aJWqhPyYZQWbV3hWq+nUIPQRMwLn"}, >) (加密)crypto.erl:925::crypto.hmac/6 (plug) lib/plug/crypto/key_generator.ex:64: Plug.Crypto.KeyGenerator.generate/7 (plug) lib/plug/crypto/key_generator.ex:50: Plug.Crypto.KeyGenerator.with_cache/3 (plug) lib/plug/session/cookie.ex:88: Plug.Session.COOKIE.get/3 (plug) lib/plug/session.ex:75: Plug.Session.fetch_session/1 中的匿名 fn/5 (plug) lib/plug/debugger.ex:195: Plug.Debugger.maybe_fetch_session/1 (plug) lib/plug/debugger.ex:150: Plug.Debugger.render/6 (plug) lib/plug/debugger.ex:129: Plug.Debugger.catch/5 (my_app) lib/my_app_web/endpoint.ex:1: MyAppWeb.Endpoint.call/2 (plug) lib/plug/adapters/cowboy/handler.ex:15: Plug.Adapters.Cowboy.Handler.upgrade/4

这是 lib/my_app_web/endpoint.ex 的内容。

defmodule MyAppWeb.Endpoint do
  use Phoenix.Endpoint, otp_app: :my_app

  socket "/socket", MyAppWeb.UserSocket

  # Serve at "/" the static files from "priv/static" directory.
  #
  # You should set gzip to true if you are running phoenix.digest
  # when deploying your static files in production.
  plug Plug.Static,
    at: "/", from: :my_app, gzip: false,
    only: ~w(css fonts images js favicon.ico robots.txt)

  # Code reloading can be explicitly enabled under the
  # :code_reloader configuration of your endpoint.
  if code_reloading? do
    socket "/phoenix/live_reload/socket", Phoenix.LiveReloader.Socket
    plug Phoenix.LiveReloader
    plug Phoenix.CodeReloader
  end

  plug Plug.RequestId
  plug Plug.Logger

  plug Plug.Parsers,
    parsers: [:urlencoded, :multipart, :json, Absinthe.Plug.Parser],
    pass: ["*/*"],
    json_decoder: Poison

  plug Plug.MethodOverride
  plug Plug.Head

  # The session will be stored in the cookie and signed,
  # this means its contents can be read but not tampered with.
  # Set :encryption_salt if you would also like to encrypt it.
  plug Plug.Session,
    store: :cookie,
    key: "_my_app_key",
    signing_salt: "0FbVUD98"

  plug MyAppWeb.Router

  @doc """
  Callback invoked for dynamically configuring the endpoint.

  It receives the endpoint configuration and checks if
  configuration should be loaded from the system environment.
  """
  def init(_key, config) do
    if config[:load_from_system_env] do
      port = System.get_env("PORT") || raise "expected the PORT environment variable to be set"
      {:ok, Keyword.put(config, :http, [:inet6, port: port])}
    else
      {:ok, config}
    end
  end
end

有人帮忙吗?

【问题讨论】:

  • 请提供您的lib/my_app_web/endpoint.ex 的内容。
  • @YongHaoHu 添加endpoint.ex文件内容。
  • 您是否在连接中设置了 :secret_key_base 字段?见:hexdocs.pm/plug/Plug.Session.COOKIE.html
  • @YongHaoHu 我尝试在我的 endpoint.ex 中添加 put_secret_key_base。但是,没有用。出于某种原因,_my_app_key 没有生成并存储在 Cookie 中。你有什么想法吗?
  • 谢谢@YongHaoHu。 put_secret_key_base 工作。

标签: cryptography elixir plug


【解决方案1】:

(exit) an exception was raised: ** (ArgumentError) argument error (crypto) :crypto.hmac_nif(:sha256, {:system, "Zpumk6KLEY8Qx826qspHhYrpTpDswFzHL/64aJWqhPyYZQWbV3hWq+nUIPQRMwLn"}, <<48, 70, 98, 86, 85, 68, 57, 56, 0, 0, 0, 1>>) (crypto) crypto.erl:925: :crypto.hmac/6 (plug) lib/plug/crypto/key_generator.ex:64: Plug.Crypto.KeyGenerator.generate/7 (plug) lib/plug/crypto/key_generator.ex:50: Plug.Crypto.KeyGenerator.with_cache/3 (plug) lib/plug/session/cookie.ex:88: Plug.Session.COOKIE.get/3 lib/plug/adapters/cowboy/handler.ex:15: Plug.Adapters.Cowboy.Handler.upgrade/4

您的错误日志与Plug.Session.COOKIE 有关。

正如医生所说,

由于此商店使用加密功能,因此需要您在连接中设置 :secret_key_base 字段。这可以通过插头轻松实现:

您的代码中似乎没有这样做。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2016-10-08
    • 2015-01-28
    • 2013-03-20
    • 2010-12-10
    • 1970-01-01
    相关资源
    最近更新 更多