1. 程式人生 > >框架中的RESTful api快速領悟(中):token認證

框架中的RESTful api快速領悟(中):token認證

我們講一下RESTful api中很重要的環節—token認證。本課程主要演示如何快速藉助YII2配置出簡單的token認證方法,並給出擴充套件的思路

CREATE TABLE `clients` (
  `client_id` int(11) unsigned NOT NULL AUTO_INCREMENT,
  `client_appid` varchar(255) NOT NULL DEFAULT '',
  `client_appkey` varchar(255) NOT NULL DEFAULT '',
varchar(255) DEFAULT NULL, PRIMARY KEY (`client_id`) ) ENGINE=MyISAM DEFAULT CHARSET=utf8mb4;



namespace app\models;

use yii\db\ActiveRecord;

class Clients extends ActiveRecord
    static public function tableName()
        return 'clients'
; } }

namespace app\controllers;

use yii\filters\auth\QueryParamAuth;
use yii\rest\ActiveController;
use yii\web\Response;

class UserController extends ActiveController
    public $modelClass = 'app\models\Users';

    public function init()
$this->enableCsrfValidation = false; //關掉session \Yii::$app->user->enableSession = false; } public function behaviors() { $behaviors = parent::behaviors(); //設定響應格式 $behaviors['contentNegotiator']['formats']['text/html'] = Response::FORMAT_JSON; //授權認證 $behaviors['authenticator'] = [ 'class' => QueryParamAuth::className(), //我們使用的是QueryParamAuth ]; return $behaviors; } }



        'user' => [
//            'identityClass' => 'app\models\User',
//            'enableAutoLogin' => true,
            'identityClass' => 'app\models\Clients', //驗證的時候呼叫這個類



namespace app\models;

use yii\db\ActiveRecord;
use yii\web\IdentityInterface;

class Clients extends ActiveRecord implements identityInterface
    static public function tableName()
        return 'clients';

     * Finds an identity by the given ID.
     * @param string|integer $id the ID to be looked for
     * @return IdentityInterface the identity object that matches the given ID.
     * Null should be returned if such an identity cannot be found
     * or the identity is not in an active state (disabled, deleted, etc.)
    public static function findIdentity($id)
        // TODO: Implement findIdentity() method.

     * Finds an identity by the given token.
     * @param mixed $token the token to be looked for
     * @param mixed $type the type of the token. The value of this parameter depends on the implementation.
     * For example, [[\yii\filters\auth\HttpBearerAuth]] will set this parameter to be `yii\filters\auth\HttpBearerAuth`.
     * @return IdentityInterface the identity object that matches the given token.
     * Null should be returned if such an identity cannot be found
     * or the identity is not in an active state (disabled, deleted, etc.)
    public static function findIdentityByAccessToken($token, $type = null)
        // TODO: Implement findIdentityByAccessToken() method.
        return self::findOne(['client_token'=>$token]);

     * Returns an ID that can uniquely identify a user identity.
     * @return string|integer an ID that uniquely identifies a user identity.
    public function getId()
        // TODO: Implement getId() method.

     * Returns a key that can be used to check the validity of a given identity ID.
     * The key should be unique for each individual user, and should be persistent
     * so that it can be used to check the validity of the user identity.
     * The space of such keys should be big enough to defeat potential identity attacks.
     * This is required if [[User::enableAutoLogin]] is enabled.
     * @return string a key that is used to check the validity of a given identity ID.
     * @see validateAuthKey()
    public function getAuthKey()
        // TODO: Implement getAuthKey() method.

     * Validates the given auth key.
     * This is required if [[User::enableAutoLogin]] is enabled.
     * @param string $authKey the given auth key
     * @return boolean whether the given auth key is valid.
     * @see getAuthKey()
    public function validateAuthKey($authKey)
        // TODO: Implement validateAuthKey() method.
{"name":"Unauthorized","message":"Your request was made with invalid credentials.","code":0,"status":401,"type":"yii\\web\\UnauthorizedHttpException"}



