authorization.js 902 B

12345678910111213141516171819202122232425262728293031
  1. import jwt from "jsonwebtoken";
  2. import environment from "#environment";
  3. const secretKey = "secretKey";
  4. // 生成token
  5. export function generateToken(payload) {
  6. const token =
  7. "Bearer " +
  8. jwt.sign(payload, secretKey, {
  9. // expiresIn: 60 * 60 * 24 * 7 * 4 * 12, // 一年过期
  10. // expiresIn: 60 * 60 * 24 * 7 * 4, // 一个月
  11. // expiresIn: 60 * 60 * 24 * 7, // 一周
  12. expiresIn: 60 * 60 * 24, // 一天
  13. // expiresIn: 60 * 60, // 一个小时
  14. }, environment.privateKey, { algorithm: 'RS256' });
  15. return token;
  16. }
  17. // 验证token
  18. export function verifyToken(req, res, next) {
  19. const token = req.headers.authorization.split(" ")[1];
  20. jwt.verify(token, secretKey, function (err, decoded) {
  21. if (err) {
  22. console.log("verify error", err);
  23. return res.json({ code: "404", msg: "token无效" });
  24. }
  25. req.body.decoded = decoded
  26. next();
  27. });
  28. }