|
|
|
@@ -1,6 +1,7 @@
|
|
|
|
|
package jwtx
|
|
|
|
|
|
|
|
|
|
import (
|
|
|
|
|
"encoding/json"
|
|
|
|
|
"errors"
|
|
|
|
|
"time"
|
|
|
|
|
|
|
|
|
@@ -8,80 +9,78 @@ import (
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
var (
|
|
|
|
|
TokenExpired error = errors.New("token is expired")
|
|
|
|
|
TokenNotValidYet error = errors.New("token not active yet")
|
|
|
|
|
TokenMalformed error = errors.New("that's not even a token")
|
|
|
|
|
TokenInvalid error = errors.New("couldn't handle this token")
|
|
|
|
|
TokenGenerateFailed error = errors.New("generate token failed!")
|
|
|
|
|
|
|
|
|
|
// defaultSignKey string = "hcVI@Nm4cjhjPVvCpL5^1%jY"
|
|
|
|
|
defaultSignKey = "XiaoXinPlus"
|
|
|
|
|
|
|
|
|
|
RedisUserKey string = "user:%d"
|
|
|
|
|
ErrTokenExpired error = errors.New("token is expired")
|
|
|
|
|
ErrTokenNotValidYet error = errors.New("token not active yet")
|
|
|
|
|
ErrTokenMalformed error = errors.New("that's not even a token")
|
|
|
|
|
ErrTokenInvalid error = errors.New("couldn't handle this token")
|
|
|
|
|
ErrTokenGenerateFailed error = errors.New("generate token failed!")
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
type jwtx struct {
|
|
|
|
|
SigningKey []byte
|
|
|
|
|
SignKey []byte
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
type Claims struct {
|
|
|
|
|
TenantId int64 `json:"tenant_id"`
|
|
|
|
|
ClientId int64 `json:"client_id"`
|
|
|
|
|
UserId int64 `json:"user_id"`
|
|
|
|
|
|
|
|
|
|
Tag string `json:"tag"` // 额外标记
|
|
|
|
|
|
|
|
|
|
UserData string `json:"user_data"`
|
|
|
|
|
jwt.StandardClaims
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func NewJWT() *jwtx {
|
|
|
|
|
func NewJWT(signKey string) *jwtx {
|
|
|
|
|
return &jwtx{
|
|
|
|
|
[]byte(defaultSignKey),
|
|
|
|
|
[]byte(signKey),
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// 仅解析Token
|
|
|
|
|
func (j *jwtx) Decode(tokenString string) (*Claims, error) {
|
|
|
|
|
func (j *jwtx) Decode(tokenString string, userData interface{}) error {
|
|
|
|
|
token, err := jwt.ParseWithClaims(tokenString, &Claims{}, func(token *jwt.Token) (interface{}, error) {
|
|
|
|
|
return j.SigningKey, nil
|
|
|
|
|
return j.SignKey, nil
|
|
|
|
|
})
|
|
|
|
|
if err != nil {
|
|
|
|
|
if ve, ok := err.(*jwt.ValidationError); ok {
|
|
|
|
|
if ve.Errors&jwt.ValidationErrorMalformed == jwt.ValidationErrorMalformed {
|
|
|
|
|
return nil, TokenMalformed
|
|
|
|
|
return ErrTokenMalformed
|
|
|
|
|
} else if ve.Errors&jwt.ValidationErrorExpired == jwt.ValidationErrorExpired {
|
|
|
|
|
// Token is expired
|
|
|
|
|
return nil, TokenExpired
|
|
|
|
|
return ErrTokenExpired
|
|
|
|
|
} else if ve.Errors&jwt.ValidationErrorNotValidYet == jwt.ValidationErrorNotValidYet {
|
|
|
|
|
return nil, TokenNotValidYet
|
|
|
|
|
return ErrTokenNotValidYet
|
|
|
|
|
} else {
|
|
|
|
|
return nil, TokenInvalid
|
|
|
|
|
return ErrTokenInvalid
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
claims, ok := token.Claims.(*Claims)
|
|
|
|
|
if !ok || !token.Valid {
|
|
|
|
|
return nil, TokenInvalid
|
|
|
|
|
return ErrTokenInvalid
|
|
|
|
|
}
|
|
|
|
|
return claims, nil
|
|
|
|
|
|
|
|
|
|
return json.Unmarshal([]byte(claims.UserData), userData)
|
|
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// 根据参数生成和设置 token
|
|
|
|
|
func (j *jwtx) Encode(claims *Claims, expiresTime time.Time) (string, error) {
|
|
|
|
|
func (j *jwtx) Encode(userData interface{}, expiresTime time.Time) (string, error) {
|
|
|
|
|
|
|
|
|
|
expSecond := expiresTime.Unix()
|
|
|
|
|
nowSecond := time.Now().Unix()
|
|
|
|
|
|
|
|
|
|
if expSecond-nowSecond < 0 {
|
|
|
|
|
if expiresTime.Before(time.Now()) {
|
|
|
|
|
return "", errors.New("时间无效")
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
db, err := json.Marshal(userData)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return "", errors.New("json序列化失败")
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
claims := Claims{
|
|
|
|
|
UserData: string(db),
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// 设置有效时间
|
|
|
|
|
claims.StandardClaims.ExpiresAt = expiresTime.Unix()
|
|
|
|
|
token := jwt.NewWithClaims(jwt.SigningMethodHS256, claims)
|
|
|
|
|
tokenString, err := token.SignedString(j.SigningKey)
|
|
|
|
|
tokenString, err := token.SignedString(j.SignKey)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return "", TokenGenerateFailed
|
|
|
|
|
return "", ErrTokenGenerateFailed
|
|
|
|
|
}
|
|
|
|
|
return tokenString, nil
|
|
|
|
|
}
|
|
|
|
|