提问者:小点点

无法使JWT身份验证与Socket.io一起工作


服务器端:

var express = require('express');
var http = require('http');
var path = require('path');
var socketIO = require('socket.io');
var socketioJwt = require('socketio-jwt');
var app = express();
var server = http.Server(app);
var io = socketIO(server);
app.use('/files', express.static(__dirname + '/files'));
app.get('/', function(request, response) {
    response.sendFile('G:/jwtclient.html');
});
// Accept connection and authorize token
io.on('connection', socketioJwt.authorize({
    secret: 'SECRET_KEY',
    timeout: 15000,
}));
io.on('authenticated', function (socket) {
    console.log(socket.decoded_token);
    console.log('Authenticated!');
});
server.listen(1111);

客户端:

<!DOCTYPE html>
<html>
<head>
  <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
  <title>Js1</title>
  <link href="" rel="stylesheet" type="text/css">
  <script src="/socket.io/socket.io.js"></script>
</head>
<body>
    <p id = 'test'></p>
    <script>var token = sessionStorage.token;
var socket = io('localhost:1111');
socket.on('connect', function () {
    console.log('connected!');
  socket.on('authenticated', function () {
      document.getElementById('test').innerHTML = 'Authenticated!!!';
    });
  socket.emit('authenticate', {token: token}); //send the jwt
});
</script>
</body>
</html>

我确实得到了一个‘连接!’登录我的控制台,但身份验证似乎没有发生。我不知道我做错了什么。如有任何帮助,我们将不胜感激。

编辑:我也试过这个:

服务器:

var express = require('express');
var http = require('http');
var path = require('path');
var socketIO = require('socket.io');
var socketioJwt = require('socketio-jwt');
var app = express();
var server = http.Server(app);
var io = socketIO(server);
app.use('/files', express.static(__dirname + '/files'));
app.get('/', function(request, response) {
    response.sendFile('G:/jwtclient.html');
});
io.use(socketioJwt.authorize({
  secret: 'secret',
  handshake: true,
}));
// Accept connection and authorize token
io.on('connection', function() {
    console.log('authorized');
});
server.listen(1111);

客户:

<!DOCTYPE html>
<html>
<head>
  <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
  <title>Js1</title>
  <link href="" rel="stylesheet" type="text/css">
  <script src="/socket.io/socket.io.js"></script>
</head>
<body>
    <p id = 'test'></p>
    <script>var token = sessionStorage.token;
var socket = io.connect('http://localhost:1111', {
  'query': 'token=' + token,
});
socket.on('connect', function (sock) {
    console.log('connected!');
});
</script>
</body>
</html>

两者都与这里的官方文档完全相同:https://www.npmjs.com/package/socketio-jwt

什么都不管用。这个软件包是不是被废弃了,变得无用了,还是我做错了什么?因为我正在复制文件里的所有东西。。。


共1个答案

匿名用户

在服务器端,您应该接受并验证JWT,如下所示:

socket.on("authenticate", function(jwt){

      socket.emit("authenticated"); // if autehnticated
})