【问题标题】:Laravel Passport - Authenticating web app against api with Custom UserProviderLaravel Passport - 使用自定义 UserProvider 针对 api 对 Web 应用程序进行身份验证
【发布时间】:2018-03-14 05:01:39
【问题描述】:

我真的是新构建 laravel 应用程序,我有一个安静的 laravel API 和一个 Web 应用程序,我希望客户端 Web 应用程序对 API 进行身份验证并将用户存储在会话中,我已经注册了一个新的 UserProvider 和像下面这样在配置的身份验证上设置它

服务提供者

public function boot()
{
    $this->registerPolicies();

    Auth::provider('apiAuthServiceProvider', function ($app, $config) {
        return new UserProvider(new ApiUserService());
    });
}

配置/认证

'providers' => [
    'users' => [
        'driver' => 'apiAuthServiceProvider',
    ],
],

用户提供者类

    <?php

namespace App\Providers;

use Illuminate\Support\ServiceProvider;
use Illuminate\Contracts\Auth\UserProvider as IlluminateUserProvider;

    class UserProvider implements IlluminateUserProvider
    {
        private $userService;

        public function __construct($userService)
        {
            $this->userService = $userService;
        }

        /**
         * @param  mixed  $identifier
         * @return \Illuminate\Contracts\Auth\Authenticatable|null
         */
        public function retrieveById($identifier)
        {
            // Get and return a user by their unique identifier
        }

        /**
         * @param  mixed   $identifier
         * @param  string  $token
         * @return \Illuminate\Contracts\Auth\Authenticatable|null
         */
        public function retrieveByToken($identifier, $token)
        {
            // Get and return a user by their unique identifier and "remember me" token
        }

        /**
         * @param  \Illuminate\Contracts\Auth\Authenticatable  $user
         * @param  string  $token
         * @return void
         */
        public function updateRememberToken(Authenticatable $user, $token)
        {
            // Save the given "remember me" token for the given user
        }

        /**
         * Retrieve a user by the given credentials.
         *
         * @param  array  $credentials
         * @return \Illuminate\Contracts\Auth\Authenticatable|null
         */
        public function retrieveByCredentials(array $credentials)
        {
            // Get and return a user by looking up the given credentials
        }

        /**
         * Validate a user against the given credentials.
         *
         * @param  \Illuminate\Contracts\Auth\Authenticatable  $user
         * @param  array  $credentials
         * @return bool
         */
        public function validateCredentials(Authenticatable $user, array $credentials)
        {
            // Check that given credentials belong to the given user
        }
    }

Custom UserProvider注入一个UserService类,负责向API发出请求并返回用户...

我很迷茫,我应该从“UserProvider”接口覆盖哪些 UserProvider 方法? “retrieveById”、“retrieveByToken”、“updateRememberToken”、“retrieveByCredentials”和“validateCredentials”?还是我应该覆盖所有这些?考虑到客户端 Web 应用程序将有一个登录表单,并且用户将验证发送电子邮件和密码(grant_type = 密码),我也对令牌感到困惑,我应该如何在会话中存储令牌和刷新令牌?是否可以将会话超时设置为与令牌到期时间相同?我将在哪里调用retrieveByCredentials 的UserProvider 来传递身份验证参数?提前谢谢....

【问题讨论】:

  • 我已经发布了关于需要覆盖的功能的部分答案。您能否澄清一下您需要使用护照的自定义用户提供程序的场景?默认用户提供程序是否正常工作?您所说的令牌是护照令牌,还是您的意思是 PHPSESSID 之类的?

标签: laravel oauth-2.0 restful-authentication laravel-passport


【解决方案1】:

您应该只覆盖您需要的函数。大多数标准 功能应该已经在您继承的用户提供程序中定义。我只从Illuminate\Auth\EloquentUserProvider(这里是 Laravel 5.4)继承了我的自定义用户提供程序,所以请仔细检查你继承的类是如何工作的。例如,如果您需要使用不同于默认 id 字段的 ID 检索用户,则应覆盖 retrieveById。

【讨论】:

    猜你喜欢
    • 2016-08-08
    • 1970-01-01
    • 2015-04-25
    • 2016-07-28
    • 1970-01-01
    • 2014-04-26
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多