护照认证在基本示例中失败

sea*_*105 6 javascript node.js passport.js

我试图将这个passport.js示例分解为最基本的元素.我一直收到401(未经授权)的消息,无法弄清楚原因.任何帮助将不胜感激.

谢谢!

Node.js文件:

var http = require('http'),
express = require('express'),
passport = require('passport'),
LocalStrategy = require('passport-local').Strategy,
flash = require('connect-flash');

var port = process.env.PORT || 8080;

passport.serializeUser(function(user, done) {
  done(null, user);
});

passport.deserializeUser(function(obj, done) {
  done(null, obj);
});

passport.use(new LocalStrategy(
  function(username, password, done) {
   console.log("LocalStrategy working...");
   return done(null, { id: 1, username: 'Joe', password: 'schmo'});
  }
));

var app = express();

app.configure(function(){
  app.use(express.static(__dirname + '/app'));
  app.use(express.cookieParser('big secret'));
  app.use(express.bodyParser());
  app.use(express.methodOverride());
  app.use(express.cookieSession());
  app.use(flash());
  app.use(passport.initialize());
  app.use(passport.session());
  app.use(app.router);
});

app.get('/', function (req, res) {
  res.sendfile(__dirname + '/index.html');
});

app.post('/login', passport.authenticate('local'), function (req, res) {
  console.log("authenticated....");
  res.end();
});

app.listen(port);
Run Code Online (Sandbox Code Playgroud)

zel*_*oba 23

新express.js(4.x和更高版本)以及passport.js的所有用户都可能遇到"丢失凭据"问题,因为默认情况下不会解析POST数据.要修复它,请安装body-parser npm install body-parser并在代码中使用:

var bodyParser = require( 'body-parser' );
app.use( bodyParser.urlencoded({ extended: true }) );
Run Code Online (Sandbox Code Playgroud)

来自@ivarni的好点:app.use( bodyParser.urlencoded({ extended: true }) );必须注入任何护照中间件之前放置.


Mik*_*son 17

index.html或登录页面是什么样的?在你的帖子上,你需要确保你至少发送了一个username带有password字段的字体.如果您发送没有这些帖子的帖子,您将收到Missing credentials错误消息.如果要更改这些,可以修改本指南中显示的参数.

您可以通过添加路由来捕获登录错误来自行检查,并在您的呼叫中指定该路由passport.authenticate.

app.post('/login', 
  passport.authenticate('local', { failureRedirect: '/loginerror', failureFlash: true }),
  function(req, res) {
    res.redirect('/');
  });

app.get('/loginerror') function(req,res) {
    console.log(req.flash('error'));
    res.redirect('/login');
}
Run Code Online (Sandbox Code Playgroud)

我已修改您的示例以添加必要的表单.此外,如果有任何错误,则会在登录页面上呈现.例如,如果您只输入用户名而不是密码,则会看到"缺少凭据"错误消息.希望这可以帮助!

var http = require('http'),
    express = require('express'),
    passport = require('passport'),
    LocalStrategy = require('passport-local').Strategy,
    flash = require('connect-flash');

var port = process.env.PORT || 8080;

passport.serializeUser(function(user, done) {
    done(null, user);
});

passport.deserializeUser(function(obj, done) {
    done(null, obj);
});

passport.use(new LocalStrategy(
    function(username, password, done) {
        console.log("LocalStrategy working...");
        return done(null, { id: 1, username: 'Joe', password: 'schmo'});
    }
));

var app = express();

app.configure(function(){
    app.use(express.static(__dirname + '/app'));
    app.use(express.cookieParser('big secret'));
    app.use(express.bodyParser());
    app.use(express.methodOverride());
    app.use(express.cookieSession());
    app.use(flash());
    app.use(passport.initialize());
    app.use(passport.session());
    app.use(app.router);
});

app.get('/', function(req, res){

    var username = "not logged in";

    if (req.user) {
        username = req.user.username;
    }

    var body = '<html><body>';
    body = body + '<p>' + username + '</p>';
    body = body + '<a href="/login">login</a>'
    body = body + '</body></html>'

    res.send(body);
});

app.get('/login', function(req, res){

    var message = req.flash('error');
    var body = '<div><p>' + message + '</p></div>';
    body = body + '<form action="/login" method="post">';
    body = body + '<div><label>Username:</label>';
    body = body + '<input type="text" name="username"/><br/></div>';
    body = body + '<div><label>Password:</label>';
    body = body + '<input type="password" name="password"/></div>';
    body = body + '<div><input type="submit" value="Submit"/></div></form>';
    res.send(body);
});

app.post('/login', 
    passport.authenticate('local', { failureRedirect: '/login', failureFlash: true }),
    function(req, res) {
        res.redirect('/');
});

app.listen(port);
Run Code Online (Sandbox Code Playgroud)

  • 实际上,它必须被称为"用户名".我只使用`name`,反映了我自己的数据模式,这导致登录每次都失败.谢谢,+ 1. (3认同)