如何修复JWT“密钥_username必须是字符串”错误

时间:2019-09-06 09:08:52

标签: symfony jwt

我有一个具有标准连接的网站,并且由于API部分,我想添加一种新的连接方式。

我已遵循此文档: 1 https://github.com/lexik/LexikJWTAuthenticationBundle/blob/master/Resources/doc/index.md#getting-started

因此,我将JWT捆绑软件添加到我的Symfony 3项目中,并更改了security.yml:

# app/config/security.yml

security:
  encoders:
    Symfony\Component\Security\Core\User\User: sha512
    GS\UserBundle\Entity\User: sha512 #sha512

  role_hierarchy:
    ROLE_ADMIN:       ROLE_USER
    ROLE_SUPER_ADMIN: [ROLE_USER, ROLE_ADMIN, ROLE_ALLOWED_TO_SWITCH]

  providers:
    main:
      entity:
        class:    GS\UserBundle\Entity\User
        property: login

  firewalls:
    dev:
      pattern: ^/(_(profiler|wdt)|css|images|js)/
      security: false
    main:
      pattern:   ^/
      anonymous: true
      provider: main
      stateless: true
      form_login:
        login_path: login
        check_path: login_check
        default_target_path: preLogin
      logout:
        path:        logout
        target:      preLogin
      remember_me:
         secret:     '%secret%' # se souvenir de moi
         lifetime: 1000
         always_remember_me: true
    login:
        pattern:  ^/api/login
        stateless: true
        anonymous: true
        provider: main
        json_login:
            check_path:               /api/login_check
            success_handler:          lexik_jwt_authentication.handler.authentication_success
            failure_handler:          lexik_jwt_authentication.handler.authentication_failure
    api:
        pattern:   ^/api
        stateless: true
        guard:
            authenticators:
                - lexik_jwt_authentication.jwt_token_authenticator
  access_control:
    - { path: /admin, roles: ROLE_ADMIN }
    - { path: ^/api/login, roles: IS_AUTHENTICATED_ANONYMOUSLY }
    - { path: ^/api,       roles: IS_AUTHENTICATED_FULLY }

我已经这样配置config.yml:

lexik_jwt_authentication:
    secret_key:       '%kernel.project_dir%/config/jwt/private.pem'
    public_key:       '%kernel.project_dir%/config/jwt/public.pem'  
    user_identity_field: login
    pass_phrase:      'MY PASSWORD'
    token_ttl:        3600

当我试图通过邮递员这样获取令牌时: postman

我遇到此错误:

The key "_username" must be a string, "NULL" given.

因此,我尝试在security.yml中添加“ user_parameter”,以提供用户实体的参数名称,如下所示:

 login:
        pattern:  ^/api/login
        stateless: true
        anonymous: true

        json_login:
            check_path:               /api/login_check
            username_parameter: login
            password_parameter: mdp
            success_handler:          lexik_jwt_authentication.handler.authentication_success
            failure_handler:          lexik_jwt_authentication.handler.authentication_failure

现在邮递员什么也没回答。

编辑:

我找到了一个命令来检查我的配置文件,我得到了这个答案:

commande

如果我删除了username_parameter和password_parameter,则命令检查告诉我该配置是可以的,但邮递员却遇到相同的错误:

The key "username" must be a string, "NULL" given.

请帮助我,我找不到任何解决方案...

1 个答案:

答案 0 :(得分:1)

Lexik JWT身份验证配置需要 security.yaml 中的provider密钥。

login:
        pattern:  ^/api/login
        stateless: true
        anonymous: true
        provider: YOUR_PRODIVER_NAME #in your case it's main
        json_login:
            check_path:               /api/login_check
            username_parameter: login
            password_parameter: mdp
            success_handler:          lexik_jwt_authentication.handler.authentication_success
            failure_handler:          lexik_jwt_authentication.handler.authentication_failure

然后为了能够验证用户信息,它需要知道哪个字段是标识字段。 因此,在 lexik_jwt_authentication.yaml 中:

lexik_jwt_authentication:
    secret_key: '%env(resolve:JWT_SECRET_KEY)%'
    public_key: '%env(resolve:JWT_PUBLIC_KEY)%'
    pass_phrase: '%env(JWT_PASSPHRASE)%'
    user_identity_field: YOUR_USER_FIELD # example email
    token_ttl: 7200

关于请求参数,必须传递usernamepassword(否_)

enter image description here