Laravel中Firebase/JWT生成Token时Base64编码密钥签名无效问题
问题描述
在Laravel控制器中使用Firebase/JWT包生成JWT Token后,在Jwt.io上验证时出现以下情况:
- 不勾选“secret base64 encoded”选项时,签名验证有效
- 勾选该选项时,签名显示无效
但业务需求要求必须勾选此选项,相关代码如下:
$payload=[ "enable_auto_capture" => "false", "merchant_code" => "234dfrwer8975027a7c746ccb2eaf02bdf19a7ed", "merchant_reference" => "PGcfcE20pmm6RaPRBLFxO8T1xnqqE8uK", "payment_profile_code" => "", "instalment_profile_code" => "", "currency" => "MYR", "amount" => "242.50", "description" => "Flight Ticket KL to Sabah", "response_url" => "http://127.0.0.1:8000/success", "additional_reference" => "test", "customer" => [ "customer_id" => "cust_john_5678", "customer_name" => "John C", "customer_contact_no" => "0134567890", "customer_email" => "john_c@paymenthub.com" ], "billing" => [ "billing_address_line_1" => "C-7-7, Centum @ Oasis Corporate Park", "billing_address_line_2" => "Jalan PJU 1A/3", "billing_address_line_3" => "", "billing_address_city" => "Petaling Jaya", "billing_address_state" => "Selangor", "billing_address_postal_code" => "47301", "billing_address_country_code" => "MYS" ], ]; $apiKey = 'my-api-key'; // Create a JWT token $jwtToken = JWT::encode($payload, $apiKey, 'HS256');
解决方案
问题根源是:勾选“secret base64 encoded”时,Jwt.io会将输入的密钥先做Base64解码,再用于签名验证;而你当前直接用明文密钥生成签名,导致两端密钥处理逻辑不一致,签名不匹配。
只需将明文API密钥先做Base64编码,再传入JWT::encode方法即可解决,修改后的代码如下:
$payload=[ "enable_auto_capture" => "false", "merchant_code" => "234dfrwer8975027a7c746ccb2eaf02bdf19a7ed", "merchant_reference" => "PGcfcE20pmm6RaPRBLFxO8T1xnqqE8uK", "payment_profile_code" => "", "instalment_profile_code" => "", "currency" => "MYR", "amount" => "242.50", "description" => "Flight Ticket KL to Sabah", "response_url" => "http://127.0.0.1:8000/success", "additional_reference" => "test", "customer" => [ "customer_id" => "cust_john_5678", "customer_name" => "John C", "customer_contact_no" => "0134567890", "customer_email" => "john_c@paymenthub.com" ], "billing" => [ "billing_address_line_1" => "C-7-7, Centum @ Oasis Corporate Park", "billing_address_line_2" => "Jalan PJU 1A/3", "billing_address_line_3" => "", "billing_address_city" => "Petaling Jaya", "billing_address_state" => "Selangor", "billing_address_postal_code" => "47301", "billing_address_country_code" => "MYS" ], ]; $apiKey = 'my-api-key'; // 对明文密钥进行Base64编码 $base64EncodedKey = base64_encode($apiKey); // 使用编码后的密钥生成JWT Token $jwtToken = JWT::encode($payload, $base64EncodedKey, 'HS256');
逻辑说明
- Jwt.io勾选“secret base64 encoded”时,会执行
base64_decode(输入的密钥)后再校验签名 - 你生成Token时提前用
base64_encode(明文密钥)处理,这样两端的密钥最终都是明文状态,签名就能匹配通过
内容的提问来源于stack exchange,提问作者Fahim Ahmed
相关产品推荐
相关产品推荐

