基于Denylist策略撤销devise-jwt访问权限:revoke_jwt方法的payload参数咨询
payload Parameter for revoke_jwt in warden-jwt_auth Great question! When you're using revoke_jwt(payload, user) from warden-jwt_auth (the underlying gem for devise-jwt), the payload parameter is the decoded hash representation of a JWT token's contents. Let's break down exactly what you need to know:
Core Requirement: The jti Field
The most critical part of the payload is the jti (JWT ID) claim. This is a unique identifier for each JWT token that devise-jwt generates by default, and it's what warden-jwt_auth uses to track and revoke tokens. Without the jti in the payload, the revocation method won't know which token to invalidate.
How to Get the Payload
You'll typically obtain the payload in one of two scenarios:
1. Revoking a Specific Token (e.g., User Logs Out)
If you have the actual JWT token string (like from the user's Authorization header), decode it first to get the payload hash:
# Extract the token from the request header (adjust as needed for your setup) token = request.headers['Authorization'].split(' ').last # Decode the token using your devise-jwt secret key and algorithm decoded_token = JWT.decode( token, Rails.application.credentials.devise_jwt_secret_key, true, algorithm: 'HS256' # Match the algorithm you configured in devise-jwt ) # The first element of the decoded result is the payload hash payload = decoded_token.first # Now call revoke_jwt Warden::JWTAuth::RevocationStrategies::YourRevocationStrategy.revoke_jwt(payload, current_user)
Note: Replace YourRevocationStrategy with the actual strategy you're using (e.g., Denylist or a custom one).
2. Revoking All Tokens for a User
If you need to invalidate every token issued to a user, you'll need to fetch all valid jti values associated with that user (this assumes you're storing jtis in a database, which is recommended for revocation). For each jti, construct a minimal payload hash containing just the jti:
# Assuming you have a Jti model that belongs_to :user user.jtis.each do |jti_record| minimal_payload = { jti: jti_record.jti } Warden::JWTAuth::RevocationStrategies::YourRevocationStrategy.revoke_jwt(minimal_payload, user) end
Most revocation strategies only care about the jti in the payload, so other fields (like exp or iat) aren't strictly necessary here.
A Quick Note on Revocation Strategies
Different revocation strategies might have minor variations in how they use the payload, but the jti is universal. For example:
- The
Denyliststrategy adds thejtito a blacklist. - A custom database-based strategy might mark the
jtias invalid in your records.
In all cases, the payload needs to include the jti to target the correct token(s).
内容的提问来源于stack exchange,提问作者Petros Kalafatidis

