token配置
直接打开页面(get)请求不能带请求头,无法查询到token所以配合cookie来验证登录的身份 用token来验证用户是否被篡改
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
| const jwtSecret = '招财进宝' const tokenExpiresTime = 1000 * 60 * 60 * 24 * 7
const payload = { user:'abc', environment:'web', expries:Date.now() + tokenExpiresTime }
var token = jwt.encode(payload,jwtSecret)
var decoded = jwt.decode(token,jwtSecret)
app.use(function(ctx,next){ ctx.jwtSecret = jwtSecret ctx.tokenExpiresTime = tokenExpiresTime return next() })
|