env ['warden']不使用Rails 5

Ser*_*koy 6 ruby-on-rails

我按照本指南使用Websockets创建聊天功能. https://www.sitepoint.com/rails-and-actioncable-adding-advanced-features/

env['warden'].user即使我用标准的Devise表单登录到应用程序时,我仍然遇到了一个无法重新调整的问题.

如果我使用另一种方法(现在已经注释) - 它会返回错误的用户

module ApplicationCable
  class Connection < ActionCable::Connection::Base
    identified_by :current_user

    def connect
      self.current_user = find_verified_user
      logger.add_tags 'ActionCable', current_user.email
    end

    protected

    def find_verified_user # this checks whether a user is authenticated with devise
      verified_user = env['warden'].user

      if verified_user
        verified_user
      else
        reject_unauthorized_connection
      end
    end

    # def find_verified_user
    #     user_id = request.headers['HTTP_AUTHORIZATION']
    #     if verified_user = User.find_by(user_id)
    #        verified_user
    #     else
    #        reject_unauthorized_connection
    #     end
    # end

  end
end
Run Code Online (Sandbox Code Playgroud)

日志说

Started GET "/cable/" [WebSocket] for 127.0.0.1 at 2017-04-06 17:40:17 +0300
Successfully upgraded to WebSocket (REQUEST_METHOD: GET, HTTP_CONNECTION: Upgrade, HTTP_UPGRADE: websocket)
An unauthorized connection attempt was rejected
Failed to upgrade to WebSocket (REQUEST_METHOD: GET, HTTP_CONNECTION: Upgrade, HTTP_UPGRADE: websocket)
Run Code Online (Sandbox Code Playgroud)

Oko*_*uko 13

我遇到了同样的问题,但结果证明我的问题是因为我有两个设计模型:User并且Customer,由于 User 用于管理内容,因此 Customer 被设置为 Warden's default_scope. 所以要访问user范围,我必须执行以下操作

env['warden'].user(:user)
Run Code Online (Sandbox Code Playgroud)

最后的符号定义了要使用的范围。

我在这里找到了有关 Warden 范围用户的信息:https : //github.com/wardencommunity/warden/wiki/Scopes#scoped-user-access


Ser*_*koy 7

我找到了这篇文章的解决方案 https://rubytutorial.io/actioncable-devise-authentication/

我不确定它是如何工作的,但它确实达成了协议.如何对有类似问题的人有所帮助.

module ApplicationCable
  class Connection < ActionCable::Connection::Base
    identified_by :current_user

    def connect
      self.current_user = find_verified_user
      logger.add_tags 'ActionCable', current_user.email
    end

    protected
    def find_verified_user
      verified_user = User.find_by(id: cookies.signed['user.id'])
      if verified_user && cookies.signed['user.expires_at'] > Time.now
        verified_user
      else
        reject_unauthorized_connection
      end
    end

  end
end
Run Code Online (Sandbox Code Playgroud)

我还创建了/config/initializers/warden_hooks.rb文件

Warden::Manager.after_set_user do |user,auth,opts|
  scope = opts[:scope]
  auth.cookies.signed["#{scope}.id"] = user.id
  auth.cookies.signed["#{scope}.expires_at"] = 60.minutes.from_now
end

Warden::Manager.before_logout do |user, auth, opts|
  scope = opts[:scope]
  auth.cookies.signed["#{scope}.id"] = nil
  auth.cookies.signed["#{scope}.expires_at"] = nil
end
Run Code Online (Sandbox Code Playgroud)