【问题标题】:tymon/jwt-auth for laravel 5.4 refresh tokentymon/jwt-auth 用于 laravel 5.4 刷新令牌
【发布时间】:2018-10-21 00:00:05
【问题描述】:

我最近使用 laravel 5.4,我想使用 tymon/jwt-auth 包通过发送访问令牌来保护我的 API,但是我的问题发生在令牌过期时我无法在过期之前刷新它,我预计令牌将是自动刷新


public function handle($request, Closure $next)
{
    try{
        $user = JWTAuth::parseToken()->authenticate();
    }catch (JWTException $e) {
        if($e instanceof \Tymon\JWTAuth\Exceptions\TokenExpiredException) {
            return response()->json(['token_expired'], $e->getStatusCode());
        }else if ($e instanceof \Tymon\JWTAuth\Exceptions\TokenInvalidException) {

            return response()->json(['token_invalid'], $e->getStatusCode());
        }else{
            return response()->json(['error'=>'Token is required']);
        }
    }
   return $next($request);
}

【问题讨论】:

    标签: laravel-5


    【解决方案1】:

    你只需要这个sn-p来做认证:

    $credentials = request(['email', 'password']);
    if (!$token = JWTAuth::attempt($credentials)) {
        return response()->json(['error' => 'Unauthorized'], 401);
    }
    

    确保在中间件中包含 jwt.auth 和 jwt.refresh,如下所示:

    Route::Group(['middleware' => [
        'jwt.auth',
        'jwt.refresh',
    ]], function() {
    //list your route here
    ....
    ....
    ....
    

    jwt.refresh 每次访问路由时都会刷新令牌。并且还在你的 .env 中添加了这个

    JWT_BLACKLIST_GRACE_PERIOD=60
    

    您可以将数字从 60 秒调整为任何其他值。此设置将设置令牌在再次刷新之前的有效期。

    【讨论】:

      猜你喜欢
      • 2017-06-10
      • 2018-11-28
      • 2021-07-10
      • 2017-07-29
      • 2020-07-04
      • 2020-12-05
      • 2018-04-01
      • 2021-09-08
      • 2015-05-19
      相关资源
      最近更新 更多