我在前端发送请求,它返回 401 Unathorized,当我在控制器上 console.log(headers) 时,没有保护 x-access-token 存在,当我删除保护时一切正常,图像 url 被发送回前端。
const response = await axios
.get(
'/auth/avatar',
{
headers: {
'x-access-token': sessionStorage.getItem('token')
},
params: {
username: sessionStorage.getItem('username')
}
}
)
console.log(response.data);
在/auth控制器上
@Get('/avatar')
@UseGuards(AuthGuard('jwt'))
getAvatar(
@Query('username') username: string,
): Promise<string> {
return this.authService.getAvatar(username);
}
服务:
getAvatar(username: string): Promise<string> {
return this.usersRepository.getAvatarUrl(username);
}
存储库:
async getAvatarUrl(username: string): Promise<string> {
const user = await this.findOne({ where: { username } });
return user.documentLocation;
}
jwt-策略
import { Injectable, UnauthorizedException } from '@nestjs/common';
import { ConfigService } from '@nestjs/config';
import { PassportStrategy } from '@nestjs/passport';
import { InjectRepository } from '@nestjs/typeorm';
import { ExtractJwt, Strategy } from 'passport-jwt';
import { JwtPayload } from './jwt-payload.interface';
import { User } from './user.entity';
import { UsersRepository } from './users.repository';
@Injectable()
export class JwtStrategy extends PassportStrategy(Strategy) {
constructor(
@InjectRepository(UsersRepository)
private usersRepository: UsersRepository,
private configService: ConfigService,
) {
super({
secretOrKey: configService.get('JWT_SECRET'),
jwtFromRequest: ExtractJwt.fromAuthHeaderAsBearerToken(),
});
}
async validate(payload: JwtPayload): Promise<User> {
const { username } = payload;
const user: User = await this.usersRepository.findOne({ username });
if (!user) {
throw new UnauthorizedException();
}
return user;
}
}
认证模块:
JwtModule.registerAsync({
imports: [ConfigModule],
inject: [ConfigService],
useFactory: async (configService: ConfigService) => ({
secret: configService.get('JWT_SECRET'),
signOptions: {
expiresIn: 3600,
},
}),
}),