【发布时间】:2018-06-06 15:41:08
【问题描述】:
我正在尝试使用 NodeJS 客户端从 Github 获取访问令牌。
const axios = require("axios");
var jwt = require("jsonwebtoken");
exports.openedPOST = function openedPOST(req, res) {
// generate jwt
const now = Math.round(Date.now() / 1000);
const payload = {
// issued at time
iat: now,
// expires in 10min
exp: now + 600,
// Github app id
iss: 6700
};
const token = jwt.sign(payload, cert, { algorithm: "RS256" });
console.log(token)
// auth to github
axios({
method: "get",
url: "https://api.github.com/app",
headers: {
Accept: "application/vnd.github.machine-man-preview+json",
Authorization: `Bearer ${token}`
}
})
.then(function(response) {
console.log(response.data);
})
.catch(function(error) {
console.warn("Unable to authenticate");
// The request was made and the server responded with a status code
// that falls out of the range of 2xx
if (error.response) {
console.warn(`Status ${error.response.status}`);
console.warn(`${error.response.data.message}`);
}
});
res.status(200).end();
但这只会产生:
{
"message": "A JSON web token could not be decoded",
"documentation_url": "https://developer.github.com/v3"
}
我已经在https://jwt.io 验证了令牌,并且有效负载符合预期。
【问题讨论】:
-
你解决了这个问题吗?
-
没有。不知道为什么会失败。
-
这可能没有任何区别,但我手动执行此操作,使用 Ruby 脚本生成令牌。我发现
iss: 6700会导致您收到消息,但"iss: 6700"允许令牌生成工作。抱歉,如果我跑题了,但是您是如何生成cert的?
标签: javascript node.js jwt github-api