无法获取刷新令牌并取回响应

如何解决无法获取刷新令牌并取回响应

在这个项目中,我刚刚添加了一个用户实体和角色实体,并添加了 jwt auth,在 jwt 到期之前,一切正常。添加过滤器和入口点后,我收到入口点引发的错误:

{
    "error": "Full authentication is required to access this resource"
}

在 JwtRequest 过滤器中,我添加了一个 try catch 来捕获 ExpiredJwtException,但我仍然无法刷新令牌并获得请求的端点的响应。

/* Intercepts every request and examine the header for jwt */
@Component
public class JwtRequestFilter extends OncePerRequestFilter
{

    @Autowired
    private AuthService authService;

    @Autowired
    private RestTemplate restTemplate;

    @Autowired
    private JwtUtil jwtUtil;

    private static final String REFRESH_TOKEN = "http://localhost:8080/refreshtoken";
    private static final String AUTHENTICATION_URL = "http://localhost:8080/authenticate";


    protected void doFilterInternal(HttpServletRequest request,HttpServletResponse response,FilterChain filterChain) throws ServletException,IOException
    {
        try {
            /*Get only the token */
            String jwt = extractJwtFromRequest(request);
            if(StringUtils.hasText(jwt) && this.jwtUtil.validateToken(jwt))
            {
                System.out.println("Entro," +jwt);
                UserDetails userDetails = this.authService.refreshTokenUserDetails(this.jwtUtil.getUsernameFromToken(jwt));
                UsernamePasswordAuthenticationToken authToken = new UsernamePasswordAuthenticationToken(userDetails,null,userDetails.getAuthorities());

                /* After setting the auth in the context,we specify that the current user is authenticated..
                 * So it passes the Spring Security Config successfully */
                SecurityContextHolder.getContext().setAuthentication(authToken);

            } else {
                System.out.println("Cannot set the Security Context");
            }
        } catch (ExpiredJwtException ex) {
            /* Expired token */
            if (ex.getMessage().contains("io.jsonwebtoken.ExpiredJwtException"))
            {
                request.setAttribute("claims",ex.getClaims());
                /* Refresh token*/
                String jwt = this.refreshToken(extractJwtFromRequest(request));
                request.setAttribute("Autorization",jwt);
                Object[] res = this.getData(request,jwt);
                byte[] body = new ObjectMapper().writeValueAsBytes(res);
                response.getOutputStream().write(body);
                
            }

        } catch (BadCredentialsException ex) {
            request.setAttribute("exception",ex);
            throw ex;
        } catch (Exception e) {
            System.out.println(e);
            throw e;
        }
        filterChain.doFilter(request,response);
    }

    private String getData(HttpServletRequest request,String token)
    {
        String response = null;
        HttpHeaders headers = getHeaders();
        headers.set("Authorization",token);
        headers.set("isRefreshToken","true");
        HttpEntity<String> jwtEntity = new HttpEntity<String>(headers);

        /* Use token to get response */
        String urlRequested = request.getRequestURL().toString();
        ResponseEntity<String> requested = restTemplate.exchange(urlRequested,HttpMethod.GET,jwtEntity,String.class);

        if(requested.getStatusCode().equals(HttpStatus.OK))
        {
            response = requested.getBody();
        }
        return response;
    }

    private HttpHeaders getHeaders()
    {
        HttpHeaders headers = new HttpHeaders();
        headers.set("Content-Type",MediaType.APPLICATION_JSON_VALUE);
        headers.set("Accept",MediaType.APPLICATION_JSON_VALUE);
        return headers;
    }

    private String extractJwtFromRequest(HttpServletRequest request)
    {
        String authorizationHeader = request.getHeader("Authorization");
        if (authorizationHeader != null && authorizationHeader.startsWith("Bearer ")) {
            return authorizationHeader.substring(7);
        }
        return null;
    }

    private String refreshToken(String token)
    {
        HttpHeaders headers = getHeaders();
        headers.set("Authorization","true");
        HttpEntity<String> jwtEntity = new HttpEntity<String>(headers);

        /* Use Token to get Response */
        ResponseEntity<AuthResponse> refreshTokenResponse = restTemplate.exchange(REFRESH_TOKEN,AuthResponse.class);

        if(refreshTokenResponse.getStatusCode().equals(HttpStatus.OK))
        {
            return "Bearer " + refreshTokenResponse.getBody().getJwt();
        }
        return null;
    }

    private void allowForRefreshToken(ExpiredJwtException ex,HttpServletRequest request)
    {
        /* Create a UsernameAuthenticationToken with null values */
        UsernamePasswordAuthenticationToken upat = new UsernamePasswordAuthenticationToken(null,null);

        /* After setting the auth in the context,we specify that the current user is authenticated. So it
        * passes the Spring Security Config successfully */
        SecurityContextHolder.getContext().setAuthentication(upat);

        /* Set the claims so that in controller we will be using it to create new Jwt */
        request.setAttribute("claims",ex.getClaims());
    }
}

JwtAuthenticationEntryPoint

@Component
public class JwtAuthenticationEntryPoint implements AuthenticationEntryPoint
{

    @Override
    public void commence(HttpServletRequest request,AuthenticationException authException) throws IOException,ServletException {

        response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
        response.setContentType(MediaType.APPLICATION_JSON_VALUE);
        String message;

        /* Check if the request as any exception that we have stored in Request */
        final Exception exception = (Exception) request.getAttribute("exception");

        // If yes then use it to create the response message else use the authException
        if (exception != null)
        {
            byte[] body = new ObjectMapper().writeValueAsBytes(Collections.singletonMap("cause",exception.toString()));
            response.getOutputStream().write(body);
        } else {

            if (authException.getCause() != null) {
                message = authException.getCause().toString() + " " + authException.getMessage();
            } else {
                message = authException.getMessage();
            }
             /* Error on postman */
            byte[] body = new ObjectMapper().writeValueAsBytes(Collections.singletonMap("error",message));
            response.getOutputStream().write(body);
        }
    }
}

SessionController 端点

@RequestMapping(value = "/refresh-token",method = RequestMethod.GET)
    public ResponseEntity<?> refreshToekn(HttpServletRequest request) throws Exception {
        /* From the http ruest get claims */
        DefaultClaims claims = (io.jsonwebtoken.impl.DefaultClaims) request.getAttribute("claims");
        Map<String,Object> expectedMap = this.authService.getMapFromIoJsonwebtokenClaims(claims);
        String token = this.authService.refreshToken(expectedMap,expectedMap.get("sub").toString());

        return ResponseEntity.ok(new AuthResponse(token));
    }

身份验证服务

public String refreshToken(Map<String,Object> claims,String subject)
    {
        return this.jwtUtil.createTokenInfinity(claims,subject);
    }

    public Map<String,Object> getMapFromIoJsonwebtokenClaims(Claims claims)
    {
        Map<String,Object> expectedMap = new HashMap<String,Object>();
        for (Map.Entry<String,Object> entry : claims.entrySet())
        {
            expectedMap.put(entry.getKey(),entry.getValue());
        }
        return expectedMap;
    }

最后是 JwtUtil

public String createTokenInfinity(Map<String,String subject)
    {
        /* Subject -> person who has been authenticated */
        return Jwts.builder().setClaims(claims).setSubject(subject).setIssuedAt(new Date(System.currentTimeMillis()))
                .setExpiration(new Date(System.currentTimeMillis() + REFRESH_TIME)) //* 60 *60 *800)
                .signWith(SignatureAlgorithm.HS256,SECRET_KEY).compact();
    }

如果你能告诉我一个更好的方法来完成这项工作,那将非常有帮助。

版权声明:本文内容由互联网用户自发贡献,该文观点与技术仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 dio@foxmail.com 举报,一经查实,本站将立刻删除。

相关推荐


依赖报错 idea导入项目后依赖报错,解决方案:https://blog.csdn.net/weixin_42420249/article/details/81191861 依赖版本报错:更换其他版本 无法下载依赖可参考:https://blog.csdn.net/weixin_42628809/a
错误1:代码生成器依赖和mybatis依赖冲突 启动项目时报错如下 2021-12-03 13:33:33.927 ERROR 7228 [ main] o.s.b.d.LoggingFailureAnalysisReporter : *************************** APPL
错误1:gradle项目控制台输出为乱码 # 解决方案:https://blog.csdn.net/weixin_43501566/article/details/112482302 # 在gradle-wrapper.properties 添加以下内容 org.gradle.jvmargs=-Df
错误还原:在查询的过程中,传入的workType为0时,该条件不起作用 &lt;select id=&quot;xxx&quot;&gt; SELECT di.id, di.name, di.work_type, di.updated... &lt;where&gt; &lt;if test=&qu
报错如下,gcc版本太低 ^ server.c:5346:31: 错误:‘struct redisServer’没有名为‘server_cpulist’的成员 redisSetCpuAffinity(server.server_cpulist); ^ server.c: 在函数‘hasActiveC
解决方案1 1、改项目中.idea/workspace.xml配置文件,增加dynamic.classpath参数 2、搜索PropertiesComponent,添加如下 &lt;property name=&quot;dynamic.classpath&quot; value=&quot;tru
删除根组件app.vue中的默认代码后报错:Module Error (from ./node_modules/eslint-loader/index.js): 解决方案:关闭ESlint代码检测,在项目根目录创建vue.config.js,在文件中添加 module.exports = { lin
查看spark默认的python版本 [root@master day27]# pyspark /home/software/spark-2.3.4-bin-hadoop2.7/conf/spark-env.sh: line 2: /usr/local/hadoop/bin/hadoop: No s
使用本地python环境可以成功执行 import pandas as pd import matplotlib.pyplot as plt # 设置字体 plt.rcParams[&#39;font.sans-serif&#39;] = [&#39;SimHei&#39;] # 能正确显示负号 p
错误1:Request method ‘DELETE‘ not supported 错误还原:controller层有一个接口,访问该接口时报错:Request method ‘DELETE‘ not supported 错误原因:没有接收到前端传入的参数,修改为如下 参考 错误2:cannot r
错误1:启动docker镜像时报错:Error response from daemon: driver failed programming external connectivity on endpoint quirky_allen 解决方法:重启docker -&gt; systemctl r
错误1:private field ‘xxx‘ is never assigned 按Altʾnter快捷键,选择第2项 参考:https://blog.csdn.net/shi_hong_fei_hei/article/details/88814070 错误2:启动时报错,不能找到主启动类 #
报错如下,通过源不能下载,最后警告pip需升级版本 Requirement already satisfied: pip in c:\users\ychen\appdata\local\programs\python\python310\lib\site-packages (22.0.4) Coll
错误1:maven打包报错 错误还原:使用maven打包项目时报错如下 [ERROR] Failed to execute goal org.apache.maven.plugins:maven-resources-plugin:3.2.0:resources (default-resources)
错误1:服务调用时报错 服务消费者模块assess通过openFeign调用服务提供者模块hires 如下为服务提供者模块hires的控制层接口 @RestController @RequestMapping(&quot;/hires&quot;) public class FeignControl
错误1:运行项目后报如下错误 解决方案 报错2:Failed to execute goal org.apache.maven.plugins:maven-compiler-plugin:3.8.1:compile (default-compile) on project sb 解决方案:在pom.
参考 错误原因 过滤器或拦截器在生效时,redisTemplate还没有注入 解决方案:在注入容器时就生效 @Component //项目运行时就注入Spring容器 public class RedisBean { @Resource private RedisTemplate&lt;String
使用vite构建项目报错 C:\Users\ychen\work&gt;npm init @vitejs/app @vitejs/create-app is deprecated, use npm init vite instead C:\Users\ychen\AppData\Local\npm-