【问题标题】:Auth0, error decoding access token with HS256 encrypt algorithmAuth0,使用 HS256 加密算法解码访问令牌时出错
【发布时间】:2019-12-25 18:36:18
【问题描述】:

我想创建一个函数,在 Python 中使用 Auth0 检查访问令牌是否有效。

现在,可以使用 HS256 或 RS256 算法对令牌进行加密。

下一个代码在 RS256 算法中运行良好,但在其他加密算法中返回 Exception: Expected a string value。为什么?

def is_valid_token(access_token, audience, algorithms):
    AUTH0_DOMAIN = 'dev-47ysz721.auth0.com'

    jsonurl = req.urlopen('https://' + AUTH0_DOMAIN + '/.well-known/jwks.json')
    jwks = json.loads(jsonurl.read())
    cert = '-----BEGIN CERTIFICATE-----\n' + jwks['keys'][0]['x5c'][0] + '\n-----END CERTIFICATE-----'
    certificate = load_pem_x509_certificate(cert.encode('utf-8'), default_backend())
    public_key = certificate.public_key()

    try:
        decoded = jwt.decode(access_token, public_key, audience=audience, algorithms=algorithms)
    except Exception as e:
        print 'Excepcion', e
        return None
    return decoded

编辑:

  • 参数access_token、audience和algorithms都是字符串,所以不存在问题。
  • 删除 try except 完整的回溯是下一个:

    Traceback:
    File "/home/vagrant/env/local/lib/python2.7/site-packages/django/core/handlers/base.py" in get_response
      111.                     response = wrapped_callback(request, *callback_args, **callback_kwargs)
    File "/home/vagrant/env/local/lib/python2.7/site-packages/django/views/decorators/csrf.py" in wrapped_view
      57.         return view_func(*args, **kwargs)
    File "/home/vagrant/env/local/lib/python2.7/site-packages/rest_framework/viewsets.py" in view
      87.             return self.dispatch(request, *args, **kwargs)
    File "/home/vagrant/env/local/lib/python2.7/site-packages/rest_framework/views.py" in dispatch
      466.             response = self.handle_exception(exc)
    File "/home/vagrant/env/local/lib/python2.7/site-packages/rest_framework/views.py" in dispatch
      463.             response = handler(request, *args, **kwargs)
    File "./apim/viewsets.py" in list
      144.             decoded = is_valid_token(access_token, account, audience, algorithms)
    File "./apim/viewsets.py" in is_valid_token
      50.     decoded = jwt.decode(access_token, public_key, audience=audience, algorithms=algorithms)
    File "/home/vagrant/env/local/lib/python2.7/site-packages/jwt/api_jwt.py" in decode
      92.             jwt, key=key, algorithms=algorithms, options=options, **kwargs
    File "/home/vagrant/env/local/lib/python2.7/site-packages/jwt/api_jws.py" in decode
      156.                                    key, algorithms)
    File "/home/vagrant/env/local/lib/python2.7/site-packages/jwt/api_jws.py" in _verify_signature
      220.             key = alg_obj.prepare_key(key)
    File "/home/vagrant/env/local/lib/python2.7/site-packages/jwt/algorithms.py" in prepare_key
      140.         key = force_bytes(key)
    File "/home/vagrant/env/local/lib/python2.7/site-packages/jwt/utils.py" in force_bytes
      30.         raise TypeError('Expected a string value')
    
    Exception Type: TypeError at /ventasapi/v1/HS.json/
    Exception Value: Expected a string value
    </textarea>
      <br><br>
      <input type="submit" value="Share this traceback on a public Web site">
      </div>
    </form>
    </div>
    

【问题讨论】:

  • 你能删除 try/except 块并包含生成的完整回溯吗?
  • @glibdud 添加了完整的回溯。

标签: python auth0


【解决方案1】:

我找到了一个解决方案,不太推荐,但工作正常。正在添加参数verify=False,代码的结果是:

if algorithms=='HS256':
        decoded = jwt.decode(access_token, public_key, audience=audience, algorithms=[algorithms], verify=False)
else:
        decoded = jwt.decode(access_token, public_key, audience=audience, algorithms=[algorithms])

见:verify

【讨论】:

    猜你喜欢
    • 2019-06-18
    • 1970-01-01
    • 2022-07-05
    • 2023-03-31
    • 2020-06-14
    • 2017-12-29
    • 1970-01-01
    • 2019-07-20
    • 2015-08-01
    相关资源
    最近更新 更多