【发布时间】:2020-03-13 13:57:10
【问题描述】:
我使用前端和后端 API 服务器来实现 Ruby/Sinatra Web 应用程序。表单将发布到前端 app.rb 中的 '/login' 路由:
post '/login' do
uri = URI.join("http://#{settings.api}:#{settings.api_port}",
"/user/", "validate")
response = Net::HTTP.post_form(
uri, 'email' => params[:email],
'password' => params[:password])
h = response.code == "200" || response.code == "401" ?
JSON.parse(response.body) : {}
if h["status"] == "success"
# Save the user id inside the browser cookie.
# This is how we keep the user
# logged in when they navigate around our website.
session[:user_id] = h["user_id"]
puts session[:user_id]
redirect '/home'
else
# If user's login doesn't work, send them back to the login form.
flash[:notice] = "Login failed due to #{h["status"]}"
redirect '/login'
end
end
post 请求及其参数通过 HTTP 发送到后端服务器。后端 API 服务器将以 JSON 响应,其中包含一个状态字段以提示用户是否已成功通过身份验证。
我在浏览器中显示“连接不安全”的以下消息。 enter image description here。我必须在前端 app.rb 中包含额外的安全配置吗?
【问题讨论】:
-
该网站可以在这里访问:link。图片没有显示不安全的提示信息。
-
请不要使用图片来提供代码、数据或调试信息。 “Discourage screenshots of code and/or errors”。请参阅“How to Ask”、“Stack Overflow question checklist”和“MCVE”及其所有链接页面。
-
该消息不是因为您使用的是纯 HTTP 吗?接收应用程序是否完全位于不同的网络上?
标签: ruby http security sinatra