【问题标题】:Devise user authentication in grape在葡萄中设计用户身份验证
【发布时间】:2015-08-25 21:54:25
【问题描述】:

我有一个包含所有前端部分、管理和注册/登录/注销(设计)的 Rails 应用程序。

我还有一部分是用 javascript React 编写的更动态的地图。它在同一应用程序中分别在控制器/视图上运行。

我使用 Grape 创建了一个 api 来向 React 公开数据。

我的问题是如何知道用户在不使用令牌的情况下登录。

哪条路?我可以使用存储在浏览器中的 cookie 和会话吗?会怎样?

我可以通过以下方式获取用户 ID:

user_id = env['rack.session']['warden.user.user.key'].first.first

这样可以吗?

User.find(user_id)

安全吗?

【问题讨论】:

    标签: ruby-on-rails devise grape grape-api


    【解决方案1】:

    我的一个应用程序使用了如下设计身份验证:

    api.rb

    #require 'grape'
    module Base
      class API < Grape::API
        prefix 'api'
        version 'v1', :using => :header, :vendor => 'vendor'
        format :json
    
        helpers do
          def current_user
            user = User.where(authentication_token: params[:auth_token], is_approved: true).first
            if user
              @current_user = user
            else
              false
            end
          end
    
          def authenticate!
            error!('401 Unauthorized', 401) unless current_user
          end
    
        end
    
    
        # load the rest of the API
        mount V1::Registration
        mount V1::Sessions
    
      end
    end
    

    sessions.rb

    module V1
      class Sessions < Grape::API
        version 'v1', using: :path
        format :json
        prefix :api
    
        resource :sessions do
    
          ##<$ User Sign In API $>##
          desc 'Authenticate user and return user object / access token'
    
          params do
            requires :email, type: String, desc: 'User email'
            requires :password, type: String, desc: 'User Password'
          end
    
          post do
            email = params[:email]
            password = params[:password]
    
            if email.nil? or password.nil?
              error!({error_code: 404, error_message: 'Invalid Email or Password.'}, 401)
              return
            end
    
            user = User.where(email: email.downcase).first
            if user.nil?
              error!({error_code: 404, error_message: 'Invalid Email or Password.'}, 401)
              return
            end
    
            if !user.valid_password?(password)
              error!({error_code: 404, error_message: 'Invalid Email or Password.'}, 401)
              return
            else
              user.ensure_authentication_token
              user.save
              {status: 'ok', auth_token: user.authentication_token}
            end
          end
    
          desc 'Destroy the access token'
          params do
            requires :auth_token, type: String, desc: 'User Access Token'
          end
          delete ':auth_token' do
            auth_token = params[:auth_token]
            user = User.where(authentication_token: auth_token).first
            if user.nil?
              error!({error_code: 404, error_message: 'Invalid access token.'}, 401)
              return
            else
              user.reset_authentication_token
              {status: 'ok'}
            end
          end
    
        end
      end
    end
    

    【讨论】:

    • “我的问题是如何知道用户在不使用令牌的情况下登录了。”谢谢。
    • 首先当你使用 REST 时,你不能使用 session。因为它是无国籍的。要检查用户登录,您需要在每个请求中传递 auth_token。从 API 方面,您需要检查 auth_token 是否存在。
    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2017-02-16
    • 1970-01-01
    • 2016-02-21
    相关资源
    最近更新 更多