feat: Bearer Token 认证,修复 Web 管理后台 401 问题
- HmacAuthInterceptor 增加 Bearer Token 优先认证(Web 管理后台) - AuthController.login 使用 hmac.secret 签发 24h 有效 token - AccountDTO 新增 token 字段(@JsonInclude NON_NULL) - 前端 Login.vue 存储登录返回的 token - 原有 HMAC 签名认证不受影响(外部 API 客户端继续可用)
This commit is contained in:
@@ -5,6 +5,7 @@ import com.par.core.dto.ApiResponse;
|
||||
import com.par.core.dto.LoginRequest;
|
||||
import com.par.core.dto.RegisterRequest;
|
||||
import com.par.core.entity.Account;
|
||||
import com.par.core.interceptor.HmacAuthInterceptor;
|
||||
import com.par.core.service.AccountService;
|
||||
import jakarta.validation.Valid;
|
||||
import lombok.RequiredArgsConstructor;
|
||||
@@ -20,6 +21,7 @@ import org.springframework.web.bind.annotation.*;
|
||||
public class AuthController {
|
||||
|
||||
private final AccountService accountService;
|
||||
private final HmacAuthInterceptor hmacAuthInterceptor;
|
||||
|
||||
/**
|
||||
* 用户注册
|
||||
@@ -31,11 +33,13 @@ public class AuthController {
|
||||
}
|
||||
|
||||
/**
|
||||
* 用户登录(仅验证密码,返回账户信息)
|
||||
* 用户登录,返回 Bearer token(有效期 24 小时)
|
||||
*/
|
||||
@PostMapping("/login")
|
||||
public ApiResponse<AccountDTO> login(@Valid @RequestBody LoginRequest request) {
|
||||
Account account = accountService.login(request);
|
||||
return ApiResponse.success(accountService.toDTO(account));
|
||||
AccountDTO dto = accountService.toDTO(account);
|
||||
dto.setToken(hmacAuthInterceptor.generateToken(account.getEmail()));
|
||||
return ApiResponse.success(dto);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user