gpt4 book ai didi

spring - JWT 签名与本地计算的签名不匹配。 JWT 有效性无法断言,不应被信任

转载 作者:行者123 更新时间:2023-12-03 17:02:52 25 4
gpt4 key购买 nike

我正在构建一个服务器端 REST 服务应用程序。我的 JWT 身份验证 token 有问题。登录后我可以轻松获取 token (这里我使用 Postman)。

enter image description here

但是,当我尝试使用相同的 token 验证访问 protected REST Controller 的请求时,出现以下错误:

io.jsonwebtoken.SignatureException: JWT signature does not match locally computed signature. JWT validity cannot be asserted and should not be trusted.
at io.jsonwebtoken.impl.DefaultJwtParser.parse(DefaultJwtParser.java:354)
at io.jsonwebtoken.impl.DefaultJwtParser.parse(DefaultJwtParser.java:481)
at io.jsonwebtoken.impl.DefaultJwtParser.parseClaimsJws(DefaultJwtParser.java:541)
at com.configuration.jwt.JwtTokenUtil.extractClaims(JwtTokenUtil.java:104)
at com.configuration.jwt.JwtTokenUtil.getUsernameFromToken(JwtTokenUtil.java:39)
at com.configuration.jwt.JwtAuthenticationFilter.doFilterInternal(JwtAuthenticationFilter.java:44)
at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)
...

就像应用程序不记得它生成的 token 一样。这是来自 Postman 的 get 请求,它产生了这个错误:

enter image description here

我想异常的来源来自方法 extractClaims我类的 JwtTokenUtil :
@Component
public final class JwtTokenUtil {

public static final int EXPIRATION_IN_SECONDS = 120;

private static final String JWT_SECRET = "Some$ecretKey";

private Clock clock = DefaultClock.INSTANCE;

@Value("${jwt.secret}")
private String secret;

@Value("${jwt.expiration}")
private Long expiration;

private JwtTokenUtil() {
// Hide default constructor
}

public String getUsernameFromToken(String token) {
return extractClaims(token).getSubject();
}

public Boolean validateToken(String token, UserDetails userDetails) {
UserDetailsImp user = (UserDetailsImp) userDetails;
final String username = getUsernameFromToken(token);
return (username.equals(user.getUsername()) && !isTokenExpired(token));
}

public Date getIssuedAtDateFromToken(String token) {
return extractClaims(token).getIssuedAt();
}

public String generateToken(UserDetails userDetails) {
Map<String, Object> claims = new HashMap<String, Object>();
return doGenerateToken(claims, userDetails.getUsername());
}

private String doGenerateToken(Map<String, Object> claims, String subject) {
final Date createdDate = clock.now();
final Date expirationDate = calculateExpirationDate(createdDate);

return Jwts.builder().setClaims(claims).setSubject(subject).setIssuedAt(createdDate)
.setExpiration(expirationDate).signWith(SignatureAlgorithm.HS512, secret).compact();
}

private Date calculateExpirationDate(Date createdDate) {
return new Date(createdDate.getTime() + expiration * 1000);
}

public static String createToken(String username, Date issueDate) {
String jwtToken = Jwts.builder().setSubject(username).setIssuedAt(issueDate)
.setExpiration(new Date(issueDate.getTime() + EXPIRATION_IN_SECONDS))
.signWith(SignatureAlgorithm.HS512, JWT_SECRET).compact();

return jwtToken;
}

public static String getSubject(String token) {
Claims claims = extractClaims(token);
return claims.getSubject();
}

public static String refreshToken(String token, long expirationInSeconds) {
final Claims claims = extractClaims(token);

Date now = new Date();
claims.setIssuedAt(now);
claims.setExpiration(new Date(now.getTime() + EXPIRATION_IN_SECONDS));

return createTokenFromClaims(claims);
}

public static boolean isTokenExpired(String token) {
final Claims claims = extractClaims(token);
Date now = new Date();

return now.after(claims.getExpiration());
}

private static String createTokenFromClaims(Claims claims) {
return Jwts.builder().setClaims(claims).signWith(SignatureAlgorithm.HS512, JWT_SECRET).compact();
}

private static Claims extractClaims(String token) {
return Jwts.parser().setSigningKey(JWT_SECRET).parseClaimsJws(token).getBody();
}

}

这是我的 JwtAuthenticationFilter类(class):
public class JwtAuthenticationFilter extends OncePerRequestFilter {

@Autowired
private UserDetailsService userDetailsService;

@Autowired
private JwtTokenUtil jwtTokenUtil;

@Override
protected void doFilterInternal(HttpServletRequest req, HttpServletResponse res, FilterChain chain)
throws IOException, ServletException {

String header = req.getHeader("Authorization");
String username = null;
String authToken = null;

if (header != null && header.startsWith("Bearer ")) {

authToken = header.replace("Bearer ", "");

try {

username = jwtTokenUtil.getUsernameFromToken(authToken);

} catch (IllegalArgumentException e) {

logger.error("an error occured during getting username from token", e);

} catch (ExpiredJwtException e) {

logger.warn("the token is expired and not valid anymore", e);
}
} else {
logger.warn("couldn't find bearer string, will ignore the header");
}

if (username != null && SecurityContextHolder.getContext().getAuthentication() == null) {

UserDetails userDetails = userDetailsService.loadUserByUsername(username);

if (jwtTokenUtil.validateToken(authToken, userDetails)) {

String role = "";

role = userDetails.getAuthorities().size() > 1 ? "ROLE_ADMIN" : "ROLE_TOURIST";

UsernamePasswordAuthenticationToken authentication = new UsernamePasswordAuthenticationToken(
userDetails, null, Arrays.asList(new SimpleGrantedAuthority(role)));

authentication.setDetails(new WebAuthenticationDetailsSource().buildDetails(req));

logger.info("authenticated user " + username + ", setting security context");

SecurityContextHolder.getContext().setAuthentication(authentication);
}
}

chain.doFilter(req, res);
}
}

我不知道登录 Controller 是否与问题有关,但无论如何这里是它的代码:
@PostMapping(value = "/signin")
public ResponseEntity<?> signin(@Valid @RequestBody LoginForm loginForm) throws AuthenticationException {

final Authentication authentication = authenticationManager.authenticate(
new UsernamePasswordAuthenticationToken(loginForm.getUsername(), loginForm.getPassword()));
SecurityContextHolder.getContext().setAuthentication(authentication);

final UserDetails user = userService.loadUserByUsername(loginForm.getUsername());

final String token = jwtTokenUtil.generateToken(user);

return ResponseEntity.ok(new JwtResponse(token, user.getUsername(), user.getAuthorities()));
}

我希望有人可以提供帮助。

最佳答案

我想 EXPIRATION_IN_SECONDS应该以毫秒为单位,因为您将它添加到以毫秒为单位的 getTime()。所以实际上应该是120000。

关于spring - JWT 签名与本地计算的签名不匹配。 JWT 有效性无法断言,不应被信任,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/56639392/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com