0

我正在使用 satellizer 使用 nodejs 通过后端对我的应用程序进行身份验证,但是每个 http 请求都不会影响 req.headers.authorization,我不知道为什么,请提前帮我解决这个问题

应用程序.js

angular.module('userApp', ['angular-ladda','mgcrea.ngStrap', 'ui.router', 'satellizer', 'angular-loading-bar'])
.config(function($httpProvider, $stateProvider, $urlRouterProvider, $authProvider, $locationProvider) {

    $stateProvider
        .state('/home', {
            url: '/',
            templateUrl: 'app/views/pages/home.html'
        })

        .state('/login', {
            url: '/login',
            templateUrl: 'app/views/pages/login.html',
            controller: 'LoginCtrl',
            controllerAs: 'login'
        })

        .state('/signup', {
            url: '/signup',
            templateUrl: 'app/views/pages/signup.html',
            controller: 'SignupCtrl',
            controllerAs: 'signup'
        })

        .state('users', {
            url: '/users',
            templateUrl: 'app/views/pages/user/all.html',
            controller: 'UserCtrl',
            controllerAs: 'user',
            resolve: {
                authenticated: function($q, $location, $auth) {
                    var deferred = $q.defer();

                    if (!$auth.isAuthenticated()) {
                        $location.path('/login');
                    } else {
                        deferred.resolve();
                    }

                    return deferred.promise;
                }
            }
        });


    $authProvider.facebook({
        clientId: 'xxxxxxxxxxx'
    });

    $urlRouterProvider.otherwise('/');
    $locationProvider.html5Mode(true);

});

用户控制器.js

angular.module('userApp')
.controller('UserCtrl', function(User, $alert) {
    vm = this;

    vm.getAllUser = function() {
        vm.processing = true;
        User.all()
            .success(function(data) {
                vm.processing = true;
                vm.users = data;
            })
            .error(function(error) {
                $alert({
                    content: error.message,
                    animation: 'fadeZoomFadeDown',
                    type: 'material',
                    duration: 3
                });
            });
    };

    vm.getAllUser();
});

用户服务.js

angular.module('userApp')
.factory('User', function($http) {
    return{
        all: function() {
            return $http.get('/api/all');
        }
    };
});

在调用 restfull api 之前检查身份验证的函数

function ensureAuthenticated(req, res, next) {
if (!req.headers.authorization) {
    return res.status(401).send({ message: 'Please make sure your request has an Authorization header' });
}

var token = req.headers.authorization;

var payload = null;
try {
    payload = jwt.decode(token, config.TOKEN_SECRET);
} catch(err) {
    return res.status(401).send({ message: err.message });
}
req.user = payload.sub;
next();

}

api

apiRouter.get('/all', ensureAuthenticated, function(req, res) {
    User.find({}, function(err, users) {
        res.send(users);
    });
});
4

0 回答 0