在Flutter中使用CSRF令牌进行OAuth2身份验证

时间:2019-07-08 13:10:57

标签: cookies flutter dart oauth-2.0 csrf-token

我想使用Oauth2 package对我的flutter应用进行身份验证,以使用REST API,但是REST API在请求中询问CSRF令牌。这是我的代码,有人知道如何以及在何处添加此令牌吗?

我试图修改Oauth2 flutter库提供的代码示例,但是它不起作用。

void Login() async {
  final authorizationEndpoint = Uri.parse(
      "http://ipadress:8000/oauth2/authorization/");

  final username = "user";
  final password = "pass";

  final identifier = "DG9GSrfae8gCzWDJU0jbxQC6DAUsTl8dSBMxwPEz";
  final secret = await getCsrftoken();

  var client = await oauth2.resourceOwnerPasswordGrant(
    authorizationEndpoint, username, password,
    identifier: identifier, secret: secret,);

  var result = await client.read("http://ipadress/api/users/me/");
  print(result);

new File("~/.myapp/credentials.json")
    .writeAsString(client.credentials.toJson());

}

Future<String> getCsrftoken() async {
  var response =
  await http.get(Uri.encodeFull('http://ipadress:8000/login/'));
  var csrftoken =
  response.headers.remove('set-cookie').substring(10, 74); //csrf 64 chars
  return csrftoken;
}

$禁止(未设置CSRF cookie。):/ oauth2 / authorization /

$“ POST / oauth2 / authorization / HTTP / 1.1” 403 2990

0 个答案:

没有答案