【问题标题】:How to create a secure connection in form fields with Sinatra如何使用 Sinatra 在表单域中创建安全连接
【发布时间】:2020-03-13 13:57:10
【问题描述】:

我使用前端和后端 API 服务器来实现 Ruby/Sinatra Web 应用程序。表单将发布到前端 app.rb 中的 '/login' 路由:

post '/login' do
  uri = URI.join("http://#{settings.api}:#{settings.api_port}",
                 "/user/", "validate")
  response = Net::HTTP.post_form(
    uri, 'email' => params[:email], 
    'password' => params[:password])
  h = response.code == "200" || response.code == "401" ? 
      JSON.parse(response.body) : {}
  if h["status"] == "success"
    # Save the user id inside the browser cookie. 
    # This is how we keep the user 
    # logged in when they navigate around our website.
    session[:user_id] = h["user_id"]
    puts session[:user_id]
    redirect '/home'
  else
  # If user's login doesn't work, send them back to the login form.
    flash[:notice] = "Login failed due to #{h["status"]}"
    redirect '/login'
  end
end

post 请求及其参数通过 HTTP 发送到后端服务器。后端 API 服务器将以 JSON 响应,其中包含一个状态字段以提示用户是否已成功通过身份验证。

我在浏览器中显示“连接不安全”的以下消息。 enter image description here。我必须在前端 app.rb 中包含额外的安全配置吗?

【问题讨论】:

标签: ruby http security sinatra


【解决方案1】:

您可以尝试在 app.rb 文件中添加以下配置:

configure :development, :test do
  set :force_ssl, true
end

configure :production do
  set :force_ssl, true
end

请参阅“Forcing SSL in a Sinatra App”,了解在 Sinatra 应用程序中强制使用 SSL 以及它对您的情况有何帮助。

【讨论】:

猜你喜欢
  • 2011-05-13
  • 2014-09-21
  • 2017-02-27
  • 2011-09-14
  • 1970-01-01
  • 2011-03-13
  • 2020-10-14
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多