You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Express Gateway全局授权疑问:请求转发及优化方案咨询

如何在Express Gateway中实现全局JWT认证(无需为每个Pipeline添加策略)

你当前的方案存在端口冲突(同时启动Express和Gateway在8080),且确实冗余——因为Express Gateway本身支持全局策略配置,不需要额外搭建Express服务。下面提供两种解决方案:

方案一:利用Express Gateway原生能力实现全局认证(推荐)

Express Gateway支持通过全局Pipeline或Pipeline继承实现统一认证,无需重复配置每个业务Pipeline。

配置步骤:

修改gateway-config.yml,定义一个匹配所有请求的全局认证Pipeline,再将认证后的请求转发到对应业务Pipeline:

apiEndpoints:
  # 定义匹配所有请求的端点
  global:
    host: '*'
    paths: '*'
  # 你的业务端点(比如原来的testing)
  testing:
    host: '*'
    paths: '/testing/*'

serviceEndpoints:
  # 你的业务服务端点(示例)
  test-service:
    url: 'http://localhost:3000'

pipelines:
  # 全局认证Pipeline:先处理JWT验证,再转发到对应业务Pipeline
  global-auth:
    apiEndpoints:
      - global
    policies:
      # JWT认证策略
      - jwt:
          - action:
              secretOrPublicKeyFile: certs/key.pem
              credentialsRequired: true
      # 使用pipeline策略,将请求转发到匹配的业务Pipeline
      - pipeline:
          - action:
              name: dispatch
              # 根据请求路径匹配对应的业务Pipeline
              match:
                - pipeline: testing
                  path: '/testing/*'

  # 业务Pipeline:无需再配置JWT,直接处理路由和代理
  testing:
    apiEndpoints:
      - testing
    policies:
      - proxy:
          - action:
              serviceEndpoint: test-service

原理:

  • global-auth Pipeline匹配所有请求,先执行JWT认证,认证通过后通过pipeline策略将请求分发到对应的业务Pipeline。
  • 所有业务Pipeline无需重复添加JWT策略,实现全局统一认证。

方案二:通过Express前置代理转发已认证请求(适合已有Passport逻辑的场景)

如果你坚持使用Express+Passport做认证,需要将Express作为前置代理,认证通过后转发请求到Express Gateway(需分开端口)。

修改步骤:

  1. 调整Express Gateway的端口(避免冲突),在gateway-config.yml中添加:
http:
  port: 8081
  1. 安装代理中间件:
npm install http-proxy-middleware --save
  1. 修改server.js,实现认证后转发:
const path = require('path');
const gateway = require('express-gateway');
const express = require('express');
const { createProxyMiddleware } = require('http-proxy-middleware');
const authenticationMiddleware = require('./middleware/auth-middleware');
const passport = require('./middleware/passport-config');

// 启动Express Gateway,监听8081
gateway()
  .load(path.join(__dirname, 'config'))
  .run();

const app = express();

// 初始化Passport
app.use(passport.initialize());
// 全局认证中间件
app.use(authenticationMiddleware);

// 转发所有请求到Express Gateway
app.use('*', createProxyMiddleware({
  target: 'http://localhost:8081',
  changeOrigin: true,
  // 可选:将认证后的用户信息通过请求头传递给网关
  onProxyReq: (proxyReq, req) => {
    if (req.user) {
      proxyReq.setHeader('X-User', JSON.stringify(req.user));
    }
  }
}));

// Express监听8080作为入口
app.listen(8080, () => {
  console.log('Auth proxy running on port 8080');
});

注意事项:

  • 确保Express和Gateway使用不同端口,避免端口占用错误。
  • 可以通过请求头将用户信息传递给Gateway,方便后续业务使用。

方案对比

方案优点缺点
原生全局Pipeline简洁、符合网关设计、无额外服务开销需要熟悉Gateway的Pipeline配置
Express前置代理复用已有Passport逻辑、灵活度高多一层代理、增加系统复杂度

内容的提问来源于stack exchange,提问作者Zoe Lubanza

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 12:04:56