NestJS Passport LocalStrategy扩展验证参数:如何传入env参数?
解决LocalStrategy传递额外参数的问题
你当前的问题出在LocalStrategy的配置上——Passport LocalStrategy的构造选项里并没有environment这个字段,所以你这么配置根本没法把自定义参数映射到validate方法里,反而把Passport内部的verified回调函数当成了environment参数,这就是你打印出[Function: verified]的原因。
要保留LocalStrategy和validate方法实现需求,只需要做以下修改:
1. 修改LocalStrategy构造配置,开启请求传递
在super()里添加passReqToCallback: true,让Passport把整个Request对象传给validate方法:
@Injectable() export class LocalStrategy extends PassportStrategy(Strategy, 'local') { constructor(private authService: AuthService) { super({ usernameField: 'email', passReqToCallback: true, // 开启后request会被传入validate方法 }); }
2. 调整validate方法参数,从Request中取额外参数
validate方法的第一个参数会变成Request对象,你可以直接从req.body里拿到前端传的env参数,再传给AuthService:
async validate( req: Request, // 第一个参数为request对象 email: string, password: string, ): Promise<User> { const environment = req.body.env; // 从请求体获取前端传入的env参数 return this.authService.getAuthenticatedUser(email, password, environment); } }
3. 在AuthService中添加权限校验逻辑
在getAuthenticatedUser方法里,验证完用户名密码后,检查用户类型与环境的匹配性:
async getAuthenticatedUser(email: string, password: string, environment: string) { // 先完成用户名密码验证逻辑 const user = await this.userService.findOneByEmail(email); if (!user || !await bcrypt.compare(password, user.password)) { throw new UnauthorizedException('用户名或密码错误'); } // 校验仪表盘访问权限 if (environment === 'dashboard' && user.type === 'member') { throw new BadRequestException('普通成员无法访问仪表盘'); } return user; }
这样就能实现你要的需求:当用户是member类型且请求仪表盘登录时,返回400错误。
内容的提问来源于stack exchange,提问作者piraha
相关产品推荐
相关产品推荐

