You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Denylist策略撤销devise-jwt访问权限:revoke_jwt方法的payload参数咨询

Understanding the payload Parameter for revoke_jwt in warden-jwt_auth

Great question! When you're using revoke_jwt(payload, user) from warden-jwt_auth (the underlying gem for devise-jwt), the payload parameter is the decoded hash representation of a JWT token's contents. Let's break down exactly what you need to know:

Core Requirement: The jti Field

The most critical part of the payload is the jti (JWT ID) claim. This is a unique identifier for each JWT token that devise-jwt generates by default, and it's what warden-jwt_auth uses to track and revoke tokens. Without the jti in the payload, the revocation method won't know which token to invalidate.

How to Get the Payload

You'll typically obtain the payload in one of two scenarios:

1. Revoking a Specific Token (e.g., User Logs Out)

If you have the actual JWT token string (like from the user's Authorization header), decode it first to get the payload hash:

# Extract the token from the request header (adjust as needed for your setup)
token = request.headers['Authorization'].split(' ').last

# Decode the token using your devise-jwt secret key and algorithm
decoded_token = JWT.decode(
  token,
  Rails.application.credentials.devise_jwt_secret_key,
  true,
  algorithm: 'HS256' # Match the algorithm you configured in devise-jwt
)

# The first element of the decoded result is the payload hash
payload = decoded_token.first

# Now call revoke_jwt
Warden::JWTAuth::RevocationStrategies::YourRevocationStrategy.revoke_jwt(payload, current_user)

Note: Replace YourRevocationStrategy with the actual strategy you're using (e.g., Denylist or a custom one).

2. Revoking All Tokens for a User

If you need to invalidate every token issued to a user, you'll need to fetch all valid jti values associated with that user (this assumes you're storing jtis in a database, which is recommended for revocation). For each jti, construct a minimal payload hash containing just the jti:

# Assuming you have a Jti model that belongs_to :user
user.jtis.each do |jti_record|
  minimal_payload = { jti: jti_record.jti }
  Warden::JWTAuth::RevocationStrategies::YourRevocationStrategy.revoke_jwt(minimal_payload, user)
end

Most revocation strategies only care about the jti in the payload, so other fields (like exp or iat) aren't strictly necessary here.

A Quick Note on Revocation Strategies

Different revocation strategies might have minor variations in how they use the payload, but the jti is universal. For example:

  • The Denylist strategy adds the jti to a blacklist.
  • A custom database-based strategy might mark the jti as invalid in your records.

In all cases, the payload needs to include the jti to target the correct token(s).

内容的提问来源于stack exchange,提问作者Petros Kalafatidis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 18:52:39