{"id":208228,"date":"2025-07-08T14:09:41","date_gmt":"2025-07-08T06:09:41","guid":{"rendered":"https:\/\/server.hk\/cnblog\/208228\/"},"modified":"2025-07-08T14:09:41","modified_gmt":"2025-07-08T06:09:41","slug":"%e4%b8%ad%e9%97%b4%e4%bb%b6-http-%e6%b5%8b%e8%af%95%e5%9c%a8%e4%b8%8d%e5%ba%94%e9%80%9a%e8%bf%87%e7%9a%84%e6%83%85%e5%86%b5%e4%b8%8b%e9%80%9a%e8%bf%87","status":"publish","type":"post","link":"https:\/\/server.hk\/cnblog\/208228\/","title":{"rendered":"\u4e2d\u95f4\u4ef6 HTTP \u6d4b\u8bd5\u5728\u4e0d\u5e94\u901a\u8fc7\u7684\u60c5\u51b5\u4e0b\u901a\u8fc7"},"content":{"rendered":"<p><b><\/b> <\/p>\n<p>\u5f53\u524d\u4f4d\u7f6e\uff1a <span>&gt;<\/span> <span>&gt;<\/span> <span>&gt;<\/span> <span>&gt;<\/span> <span>\u4e2d\u95f4\u4ef6 HTTP \u6d4b\u8bd5\u5728\u4e0d\u5e94\u901a\u8fc7\u7684\u60c5\u51b5\u4e0b\u901a\u8fc7<\/span><\/p>\n<p><span>\u6765\u6e90\uff1astackoverflow<\/span><br \/>\n<span>2024-04-30 15:18:37<\/span><br \/>\n<span><i><\/i>0\u6d4f\u89c8<\/span><br \/>\n<span style=\"cursor: pointer\"><i><\/i>\u6536\u85cf<\/span> <\/p>\n<p>\u6700\u8fd1\u53d1\u73b0\u4e0d\u5c11\u5c0f\u4f19\u4f34\u90fd\u5bf9<span style=\"color: #FF6600;, Helvetica, Arial, sans-serif;font-size: 14px;background-color: #FFFFFF\">Golang<\/span>\u5f88\u611f\u5174\u8da3\uff0c\u6240\u4ee5\u4eca\u5929\u7ee7\u7eed\u7ed9\u5927\u5bb6\u4ecb\u7ecd<span style=\"color: #FF6600;, Helvetica, Arial, sans-serif;font-size: 14px;background-color: #FFFFFF\">Golang<\/span>\u76f8\u5173\u7684\u77e5\u8bc6\uff0c\u672c\u6587<span style=\"color: #FF6600;, Helvetica, Arial, sans-serif;font-size: 14px;background-color: #FFFFFF\">\u300a\u4e2d\u95f4\u4ef6 HTTP \u6d4b\u8bd5\u5728\u4e0d\u5e94\u901a\u8fc7\u7684\u60c5\u51b5\u4e0b\u901a\u8fc7\u300b<\/span>\u4e3b\u8981\u5185\u5bb9\u6d89\u53ca\u5230<span style=\"color: #FF6600;, Helvetica, Arial, sans-serif;font-size: 14px;background-color: #FFFFFF\"><\/span>\u7b49\u7b49\u77e5\u8bc6\u70b9\uff0c\u5e0c\u671b\u80fd\u5e2e\u5230\u4f60\uff01\u5f53\u7136\u5982\u679c\u9605\u8bfb\u672c\u6587\u65f6\u5b58\u5728\u4e0d\u540c\u60f3\u6cd5\uff0c\u53ef\u4ee5\u5728\u8bc4\u8bba\u4e2d\u8868\u8fbe\uff0c\u4f46\u662f\u8bf7\u52ff\u4f7f\u7528\u8fc7\u6fc0\u7684\u63aa\u8f9e~<\/p>\n<p> \u95ee\u9898\u5185\u5bb9<br \/>\n <\/p>\n<p>\u6211\u7f16\u5199\u4e86\u4e00\u4e9b\u4e2d\u95f4\u4ef6\u6765\u68c0\u67e5\u4ee5\u786e\u4fdd jwt \u4ee4\u724c\u6709\u6548\uff1a<\/p>\n<pre>func jwtverify(next http.handler) http.handler {\n    return http.handlerfunc(func(rw http.responsewriter, r *http.request) {\n\n        \/\/get the token from the header\n        header := r.header.get(\"authorization\")\n\n        \/\/if authorization is empty, return a 403\n        if header == \"\" {\n            rw.writeheader(http.statusforbidden)\n            json.newencoder(rw).encode(errormsg{ message: \"missing authentication token\" })\n            return\n        }\n\n        header = strings.split(header, \"bearer \")[1]\n\n        token, err := jwt.parse(header, func(token *jwt.token) (i interface{}, err error) {\n            if _, ok := token.method.(*jwt.signingmethodhmac); !ok {\n                 return nil, fmt.errorf(\"unexpected signing method: %v\", token.header[\"alg\"])\n            }\n            \/\/ todo: remove the secret\n            return []byte(\"mytestsecret\"), nil\n        })\n\n       \/\/ return the error\n        if err != nil {\n            rw.writeheader(http.statusforbidden)\n            json.newencoder(rw).encode(errormsg{message: err.error()})\n            return\n        }\n\n        if token.valid {\n            log.println(\"jwt token is valid\")\n            next.servehttp(rw, r)\n        }\n    })\n}<\/pre>\n<p>\u6211\u5c1d\u8bd5\u4e3a\u6b64\u7f16\u5199\u4e00\u4e9b\u6d4b\u8bd5\uff0c\u4f46\u6211\u53ea\u80fd\u6293\u4f4f\u54ea\u91cc\u51fa\u9519\u4e86\uff0c\u6d4b\u8bd5\u5e94\u8be5\u5931\u8d25\uff0c\u56e0\u4e3a\u4ee4\u724c\u65e0\u6548\u4f46\u5b83\u4ecd\u7136\u901a\u8fc7\uff1a<\/p>\n<pre>func TestJwtVerify(t *testing.T) {\n    token := \"Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpYXQiOjE1ODcwNTIzMTcsImV4cCI6MTU4NzA1MjkxNywic2Vzc2lvbi1kYXRhIjoiVGVzdC5NY1Rlc3RGYWNlQG1haWwuY29tIn0.f0oM4fSH_b1Xi5zEF0VK-t5uhpVidk5HY1O0EGR4SQQ\"\n    req, err := http.NewRequest(\"GET\", \"\/jwt\", nil)\n    if err != nil {\n        t.Fatal(err)\n    }\n    req.Header.Set(\"Authorization\", token)\n\n    testHandler := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {\n        if r.Response.StatusCode == 403 {\n            t.Fatalf(\"Response should be 200 for a valid JWT Token\")\n        }\n    })\n\n    rw := httptest.NewRecorder()\n    handler := JwtVerify(testHandler)\n    handler.ServeHTTP(rw, req)\n}<\/pre>\n<p>\u6709\u4eba\u53ef\u4ee5\u89e3\u91ca\u4e00\u4e0b\u6211\u54ea\u91cc\u51fa\u9519\u4e86\u5417\uff1f<\/p>\n<p> <\/p>\n<h2>\u89e3\u51b3\u65b9\u6848<\/h2>\n<p> <\/p>\n<p>\u60a8\u6709\u51e0\u4e2a\u95ee\u9898\u3002<\/p>\n<p>\u9996\u5148\uff0c\u60a8\u7684\u6d4b\u8bd5\u63d0\u4f9b\u4e86\u4e00\u4e2a <code>testhandler<\/code> \u51fd\u6570\uff0c\u8be5\u51fd\u6570\u5e94\u8be5\u5728\u51fa\u73b0\u4efb\u4f55\u9519\u8bef\u65f6\u8fd0\u884c\uff0c\u4f46\u60a8\u7684 <code>jwtverify<\/code> \u51fd\u6570\u4ec5\u5728\u4ee4\u724c\u6709\u6548\u65f6\u8fd0\u884c\u4e0b\u4e00\u4e2a\u5904\u7406\u7a0b\u5e8f\uff1a<\/p>\n<pre>if token.valid {\n    log.println(\"jwt token is valid\")\n    next.servehttp(rw, r)\n}<\/pre>\n<p>\u56e0\u6b64\uff0c\u60a8\u5df2\u786e\u4fdd\u5f53\u4ee4\u724c\u65e0\u6548\u65f6 <code>testhandler<\/code> \u6c38\u8fdc\u4e0d\u4f1a\u8fd0\u884c\uff0c\u56e0\u6b64\u60a8\u7684\u6d4b\u8bd5\u4e0d\u4f1a\u5931\u8d25\u3002<\/p>\n<p>\u60a8\u7684\u7b2c\u4e8c\u4e2a\u95ee\u9898\u5728\u8fd9\u91cc\uff1a<\/p>\n<pre>if r.Response.StatusCode == 403 {\n    t.Fatalf(\"Response should be 200 for a valid JWT Token\")\n}<\/pre>\n<p>\u6839\u636e <code>http.request<\/code> \u7684\u6587\u6863\uff1a<\/p>\n<p>\u54cd\u5e94\u662f\u5bfc\u81f4\u6b64\u8bf7\u6c42\u7684\u91cd\u5b9a\u5411\u54cd\u5e94 \u521b\u5efa\u7684\u3002\u8be5\u5b57\u6bb5\u4ec5\u5728\u5ba2\u6237\u7aef\u91cd\u5b9a\u5411\u671f\u95f4\u586b\u5145\u3002<\/p>\n<p>\u5e76\u4e14\u7531\u4e8e\u6b64\u8bf7\u6c42\u4e0d\u662f\u54cd\u5e94\u5ba2\u6237\u7aef\u91cd\u5b9a\u5411\uff0c\u56e0\u6b64\u4e0d\u4f1a\u586b\u5145 <code>response<\/code> \u5b57\u6bb5\uff0c\u7279\u522b\u662f\u72b6\u6001\u4ee3\u7801\u4e0d\u4f1a\u7531\u60a8\u5199\u5165 <code>http.responsewriter<\/code> \u7684\u6807\u5934\u786e\u5b9a\u3002\u4e00\u822c\u6765\u8bf4\uff0c\u4f60\u65e0\u6cd5\u901a\u8fc7\u8fd9\u79cd\u65b9\u5f0f\u83b7\u53d6\u72b6\u6001\u7801\uff0c\u6b63\u5e38\u7684\u65b9\u6cd5\u662f\u8ba9\u65e9\u671f\u7684\u4e2d\u95f4\u4ef6\u5305\u88c5 <code>http.responsewriter<\/code>\uff0c\u5e76\u5728\u5199\u5165\u72b6\u6001\u7684\u4e2d\u95f4\u4ef6\u8fd4\u56de\u540e\u4ece\u8be5\u5305\u88c5\u5668\u7f16\u5199\u5668\u83b7\u53d6\u72b6\u6001\u3002 p&gt; <\/p>\n<p>\u6b63\u5982\u8bc4\u8bba\u4e2d\u63d0\u5230\u7684\uff0c\u6b63\u786e\u7684\u65b9\u6cd5\u662f\u68c0\u67e5 <code>httptest.responserecorder<\/code> \u7684\u72b6\u6001\u4ee3\u7801\uff0c\u56e0\u4e3a\u5176\u76ee\u7684\u662f\u5728\u6d4b\u8bd5\u671f\u95f4\u68c0\u67e5 http \u54cd\u5e94\u3002<\/p>\n<p>\u4eca\u5929\u5173\u4e8e\u300a\u4e2d\u95f4\u4ef6 HTTP \u6d4b\u8bd5\u5728\u4e0d\u5e94\u901a\u8fc7\u7684\u60c5\u51b5\u4e0b\u901a\u8fc7\u300b\u7684\u5185\u5bb9\u4ecb\u7ecd\u5c31\u5230\u6b64\u7ed3\u675f\uff0c\u5982\u679c\u6709\u4ec0\u4e48\u7591\u95ee\u6216\u8005\u5efa\u8bae\uff0c\u53ef\u4ee5\u5728\u516c\u4f17\u53f7\u4e0b\u591a\u591a\u56de\u590d\u4ea4\u6d41\uff1b\u6587\u4e2d\u82e5\u6709\u4e0d\u6b63\u4e4b\u5904\uff0c\u4e5f\u5e0c\u671b\u56de\u590d\u7559\u8a00\u4ee5\u544a\u77e5\uff01<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5f53\u524d\u4f4d\u7f6e\uff1a &gt; &gt; &#46;&#46;&#46;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4925],"tags":[],"class_list":["post-208228","post","type-post","status-publish","format-standard","hentry","category-4925"],"_links":{"self":[{"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/posts\/208228","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/comments?post=208228"}],"version-history":[{"count":0,"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/posts\/208228\/revisions"}],"wp:attachment":[{"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/media?parent=208228"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/categories?post=208228"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/tags?post=208228"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}