【问题标题】:Sending a graphql response from Guardian error handler when using Absinthe使用苦艾酒时从 Guardian 错误处理程序发送 graphql 响应
【发布时间】:2018-11-21 21:31:22
【问题描述】:

我有一个带有 Absinthe 的 Phoenix 应用程序,用于 Graphql API。

Guardian 用于验证在标头中提供 Bearer 令牌的请求。在提供无效令牌之前,这一切都很好。我在我的 Guardian 管道中指定了一个错误处理程序,它目前只响应 401 http 响应:

def auth_error(conn, {type, _reason}, _opts) do
    body = to_string(type)

    conn
    |> put_resp_content_type("text/plain")
    |> send_resp(401, body)
end

这对任何 graphql 客户端都不友好,我的解析器并不真正关心令牌是否无效,因为他们有自己的检查来查看上下文中是否提供了用户。

如果令牌无效,是否有办法从错误处理程序继续管道,以便我可以给出正确的 graphql 响应?

【问题讨论】:

    标签: elixir graphql phoenix-framework absinthe guardian


    【解决方案1】:

    我的建议是创建一个 Plug 来验证 Bearer 令牌并在上下文中设置当前用户。然后你可以编写一个 Absinthe.Middleware 来验证当前用户是否存在,如果不存在则设置错误。

    另外,查看blunder-absinthe 以获得更好的错误。

    【讨论】:

      猜你喜欢
      • 2018-12-14
      • 2020-05-04
      • 2021-07-08
      • 2021-08-20
      • 2018-12-25
      • 2019-12-12
      • 2018-01-16
      • 2021-12-15
      • 2020-04-09
      相关资源
      最近更新 更多