Alx*_*Alx 92 authentication redirect node.js express passport.js
我正在尝试使用node.js,express和passport.js建立登录机制.登录本身工作得非常好,会话与redis很好地存储,但是在提示进行身份验证之前,我确实遇到了将用户重定向到他开始的地方的麻烦.
例如,用户跟随链接http://localhost:3000/hidden
然后被重定向到http://localhost:3000/login
但我希望他再次被重定向回http://localhost:3000/hidden
.
这样做的目的是,如果用户随机访问他需要首先登录的页面,他将被重定向到提供其凭据的/ login站点,然后被重定向回他之前尝试访问的站点.
这是我的登录帖子
app.post('/login', function (req, res, next) {
passport.authenticate('local', function (err, user, info) {
if (err) {
return next(err)
} else if (!user) {
console.log('message: ' + info.message);
return res.redirect('/login')
} else {
req.logIn(user, function (err) {
if (err) {
return next(err);
}
return next(); // <-? Is this line right?
});
}
})(req, res, next);
});
Run Code Online (Sandbox Code Playgroud)
在这里我的ensureAuthenticated方法
function ensureAuthenticated (req, res, next) {
if (req.isAuthenticated()) {
return next();
}
res.redirect('/login');
}
Run Code Online (Sandbox Code Playgroud)
它挂钩到/hidden
页面
app.get('/hidden', ensureAuthenticated, function(req, res){
res.render('hidden', { title: 'hidden page' });
});
Run Code Online (Sandbox Code Playgroud)
登录站点的html输出非常简单
<form method="post" action="/login">
<div id="username">
<label>Username:</label>
<input type="text" value="bob" name="username">
</div>
<div id="password">
<label>Password:</label>
<input type="password" value="secret" name="password">
</div>
<div id="info"></div>
<div id="submit">
<input type="submit" value="submit">
</div>
</form>
Run Code Online (Sandbox Code Playgroud)
lin*_*dan 100
在您的ensureAuthenticated
方法中保存会话中的返回URL,如下所示:
...
req.session.returnTo = req.originalUrl;
res.redirect('/login');
...
Run Code Online (Sandbox Code Playgroud)
然后,您可以将passport.authenticate路线更新为:
app.get('/auth/google/return', passport.authenticate('google'), function(req, res) {
res.redirect(req.session.returnTo || '/');
delete req.session.returnTo;
});
Run Code Online (Sandbox Code Playgroud)
cho*_*ovy 75
我不知道护照,但这是我的方式:
我有一个中间件,我在会话app.get('/account', auth.restrict, routes.account)
中设置redirectTo
了...然后我重定向到/ login
auth.restrict = function(req, res, next){
if (!req.session.userid) {
req.session.redirectTo = '/account';
res.redirect('/login');
} else {
next();
}
};
Run Code Online (Sandbox Code Playgroud)
然后在routes.login.post
我做以下事情:
var redirectTo = req.session.redirectTo || '/';
delete req.session.redirectTo;
// is authenticated ?
res.redirect(redirectTo);
Run Code Online (Sandbox Code Playgroud)
如果您使用的是connect-ensure-login,则可以使用该successReturnToOrRedirect
参数通过Passport以超级简单的集成方式完成此操作.使用时,护照会将您返回到最初请求的URL或回退到您提供的URL.
router.post('/login', passport.authenticate('local', {
successReturnToOrRedirect: '/user/me',
failureRedirect: '/user/login',
failureFlash: true
}));
Run Code Online (Sandbox Code Playgroud)
https://github.com/jaredhanson/connect-ensure-login#log-in-and-return-to
我的做事方式:
const isAuthenticated = (req, res, next) => {
if (req.isAuthenticated()) {
return next()
}
res.redirect( `/login?origin=${req.originalUrl}` )
};
Run Code Online (Sandbox Code Playgroud)
GET / login控制器:
if( req.query.origin )
req.session.returnTo = req.query.origin
else
req.session.returnTo = req.header('Referer')
res.render('account/login')
Run Code Online (Sandbox Code Playgroud)
POST /登录控制器:
let returnTo = '/'
if (req.session.returnTo) {
returnTo = req.session.returnTo
delete req.session.returnTo
}
res.redirect(returnTo);
Run Code Online (Sandbox Code Playgroud)
POST /登出控制器(不确定是否100%确定,欢迎发表评论):
req.logout();
res.redirect(req.header('Referer') || '/');
if (req.session.returnTo) {
delete req.session.returnTo
}
Run Code Online (Sandbox Code Playgroud)
清除returnTo中间件(清除除auth路由以外的任何路由上的会话中的returnTo -对我来说,它们是/ login和/ auth /:provider):
String.prototype.startsWith = function(needle)
{
return(this.indexOf(needle) == 0)
}
app.use(function(req, res, next) {
if ( !(req.path == '/login' || req.path.startsWith('/auth/')) && req.session.returnTo) {
delete req.session.returnTo
}
next()
})
Run Code Online (Sandbox Code Playgroud)
此方法具有两个功能: