server: 平台抽象层+bilibili、服务端加密凭据库、角色中间件;web: 精简页面/路由、macOS 客户端(Swift)与多份方案文档;移除误入库的编译产物
This commit is contained in:
@@ -52,7 +52,7 @@ func TestJWTAccessExpired(t *testing.T) {
|
||||
|
||||
func TestJWTRefreshRoundTrip(t *testing.T) {
|
||||
secret := "test-secret"
|
||||
token, err := IssueRefresh(secret, 9, "jti-1")
|
||||
token, err := IssueRefresh(secret, 9, 7, "jti-1")
|
||||
if err != nil {
|
||||
t.Fatalf("issue: %v", err)
|
||||
}
|
||||
@@ -60,7 +60,7 @@ func TestJWTRefreshRoundTrip(t *testing.T) {
|
||||
if err != nil {
|
||||
t.Fatalf("parse: %v", err)
|
||||
}
|
||||
if claims.UID != 9 || claims.JTI != "jti-1" {
|
||||
if claims.UID != 9 || claims.WorkspaceID != 7 || claims.JTI != "jti-1" {
|
||||
t.Fatalf("claims mismatch: %+v", claims)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -25,8 +25,9 @@ type AccessClaims struct {
|
||||
|
||||
// RefreshClaims 刷新令牌声明
|
||||
type RefreshClaims struct {
|
||||
UID uint64 `json:"uid"`
|
||||
JTI string `json:"jti"`
|
||||
UID uint64 `json:"uid"`
|
||||
WorkspaceID uint64 `json:"wsid"`
|
||||
JTI string `json:"jti"`
|
||||
jwt.RegisteredClaims
|
||||
}
|
||||
|
||||
@@ -53,10 +54,10 @@ func IssueAccess(secret string, uid, wsid uint64, role, memberRole string) (stri
|
||||
}
|
||||
|
||||
// IssueRefresh 签发刷新令牌
|
||||
func IssueRefresh(secret string, uid uint64, jti string) (string, error) {
|
||||
func IssueRefresh(secret string, uid, wsid uint64, jti string) (string, error) {
|
||||
now := time.Now()
|
||||
claims := RefreshClaims{
|
||||
UID: uid, JTI: jti,
|
||||
UID: uid, WorkspaceID: wsid, JTI: jti,
|
||||
RegisteredClaims: jwt.RegisteredClaims{
|
||||
IssuedAt: jwt.NewNumericDate(now),
|
||||
ExpiresAt: jwt.NewNumericDate(now.Add(RefreshTTL)),
|
||||
|
||||
Reference in New Issue
Block a user