【问题标题】:passportjs facebook pass request to callbackpassportjs facebook 传递请求回调
【发布时间】:2015-01-07 19:59:02
【问题描述】:

我一定在这里忽略了一些东西。我正在使用 passportjs 的 Facebook 策略来验证用户身份。这是通过 2 个请求/[路由处理程序] 完成的:

//one to initiate the the auth:
init: function (req, res, next) {
    passport.authenticate('facebook', {
        callbackURL: URL + '/facebook/callback',
        state: req.body //attempting to put some state
    })(req, res, next)
}

//one callback
callback: function (req, res, next) {
    passport.authenticate('facebook', {
        callbackURL: URL + '/facebook/callback'
    },
    function (err, profile, accessToken, refreshToken) {
        if (err) return next(err)
        res.send(passedReqBody)
    })(req, res, next)
}

//the verify callback doesn't do much.
//Application logic is done in route callback handlers
passport.use(new FacebookStrategy({
    clientID: config.facebook.id,
    clientSecret: config.facebook.secret
},
//When setting passReqToCallback to true, it is set as the first argument
//to the verify callback. As in:
//function (req, accessToken, refreshToken, params, profile, done) {
//But this is the 'callback' request object. I want the 'init' request object.
function (accessToken, refreshToken, params, profile, done) {
    //params.state is undefined
    return done(null, profile, accessToken, refreshToken);
}));

我的问题是我希望第一个函数的 POST 请求主体在回调路由处理程序中公开。

OAuth2Strategy 构造函数“passReqToCallback”有一个选项可用,它将最新请求发送回验证回调,这对我没有用(我想要第一个 request.body)

接下来看起来可行的方法是使用“状态”选项,如https://github.com/jaredhanson/passport-oauth/blob/master/lib/passport-oauth/strategies/oauth2.js#L169

但这些值在 getOAuthAccessToken 回调 https://github.com/jaredhanson/passport-oauth/blob/master/lib/passport-oauth/strategies/oauth2.js#L124 中不可用

我当前的选择是在 OAuth2Strategy.prototype.authenticate() 函数中添加一个额外的变量,该变量在第一个函数中设置,并原封不动地传回回调函数,但我无法想象这是要走的路。

【问题讨论】:

    标签: node.js facebook authentication passport.js


    【解决方案1】:

    根据您的描述,最佳方法可能取决于您的应用程序,但这里是您的 initcallback 中间件的快速修改:

    init: function (req, res, next) {
        // SAVE BODY IN SESSION
        req.session.initBody = req.body;
    
        passport.authenticate('facebook', {
            callbackURL: URL + '/facebook/callback',
            state: req.body //attempting to put some state
        })(req, res, next)
    }
    
    //one callback
    callback: function (req, res, next) {
        passport.authenticate('facebook', {
            callbackURL: URL + '/facebook/callback'
        },
        function (err, profile, accessToken, refreshToken) {
            if (err) return next(err)
            // RESTORE BODY FROM SESSION
            res.send(req.session.initBody);
            delete req.session.initBody;
        })(req, res, next)
    }
    

    请注意,原始请求正文被持久化到会话中,然后在回调时恢复。如果您希望数据在请求/响应周期中存活,这是一种技术。不过,我要提醒的是,GET 回调中的变异状态可能是不可取的,所以如果您根据原始正文修改任何内容,请小心。

    【讨论】:

    • 你的救命恩人 :))
    猜你喜欢
    • 2014-06-05
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2022-08-19
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多