php - 如何使用 Laravel Passport 在查询字符串而不是 header 中访问 token 来验证请求?

标签 php laravel laravel-5.3 laravel-passport

使用 'middleware' => 'auth:api' 身份验证工作正常在客户端发送 Authorization=Bearer <access_token> 的常规端点上.

但现在我想处理纯图像下载请求,没有授权 header ,在查询字符串中具有访问 token ,如下所示:GET /picture/my_picture.png?access_token=1234 .

我在我的中间件中尝试过类似的东西,但我似乎无法向请求添加 header :

if ($request->has('access_token')) {
    // something like $request->header->set('Authorization', 'Bearer ' . $request->get('access_token'));
}

if ($this->auth->guard($guard)->guest()) {
    // throw exception
}

这能做到吗?也许拦截或覆盖某些东西/其他地方?

最佳答案

我有类似的问题 在你的 应用\Http\Kernal.php

注册你的中间件 $中间件和 $路由中间件

<?php

namespace App\Http;

use Illuminate\Foundation\Http\Kernel as HttpKernel;

class Kernel extends HttpKernel
{
    /**
     * The application's global HTTP middleware stack.
     *
     * These middleware are run during every request to your application.
     *
     * @var array
     */
    protected $middleware = [
        \App\Http\Middleware\AddHeaderAccessToken::class,

        \Illuminate\Foundation\Http\Middleware\CheckForMaintenanceMode::class,
        \Illuminate\Foundation\Http\Middleware\ValidatePostSize::class,
        \App\Http\Middleware\TrimStrings::class,
        \Illuminate\Foundation\Http\Middleware\ConvertEmptyStringsToNull::class,
    ];

    /**
     * The application's route middleware groups.
     *
     * @var array
     */
    protected $middlewareGroups = [
        'web' => [
            \App\Http\Middleware\EncryptCookies::class,
            \Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse::class,
            \Illuminate\Session\Middleware\StartSession::class,
            // \Illuminate\Session\Middleware\AuthenticateSession::class,
            \Illuminate\View\Middleware\ShareErrorsFromSession::class,
//            \App\Http\Middleware\VerifyCsrfToken::class,
            \Illuminate\Routing\Middleware\SubstituteBindings::class,
        ],

        'api' => [
            'throttle:60,1',
            'bindings',
        ],
    ];

    /**
     * The application's route middleware.
     *
     * These middleware may be assigned to groups or used individually.
     *
     * @var array
     */
    protected $routeMiddleware = [
        'addAccessToken' => \App\Http\Middleware\AddHeaderAccessToken::class,
        'auth' => \Illuminate\Auth\Middleware\Authenticate::class,
        'auth.basic' => \Illuminate\Auth\Middleware\AuthenticateWithBasicAuth::class,
        'bindings' => \Illuminate\Routing\Middleware\SubstituteBindings::class,
        'can' => \Illuminate\Auth\Middleware\Authorize::class,
        'guest' => \App\Http\Middleware\RedirectIfAuthenticated::class,
        'throttle' => \Illuminate\Routing\Middleware\ThrottleRequests::class,

        'scopes' => \Laravel\Passport\Http\Middleware\CheckScopes::class,
        'scope' => \Laravel\Passport\Http\Middleware\CheckForAnyScope::class
    ];
}

中间件

<?php

namespace App\Http\Middleware;

use Closure;

class AddHeaderAccessToken
{
    /**
     * Handle an incoming request.
     *
     * @param  \Illuminate\Http\Request  $request
     * @param  \Closure  $next
     * @return mixed
     */
    public function handle($request, Closure $next)
    {
      if ($request->has('access_token')) {
         $request->headers->set('Authorization', 'Bearer ' . $request->get('access_token'));
        }
        return $next($request);
    }
}

关于php - 如何使用 Laravel Passport 在查询字符串而不是 header 中访问 token 来验证请求?,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/41506312/

相关文章:

php - 使用 Doctrine 按特定列连接表

php - mysqli 处理具有不同列的多个结果集的准备过程调用

php - 无法在新服务器上执行 Ajax 查询

twitter-bootstrap - Bootstrap 在 laravel 5.6 中不起作用

php - 拉维尔 5.3 : Setting time zones based on users location

php - 我如何重写这个动态 SQL 循环以包括 PDO 清理?

Laravel PUT请求参数

php - 碳 : displaying hours and minutes?

Laravel:电子邮件的自定义验证

laravel - Vuejs js 用于多页面,不适用于单页面应用