如何自定义Doorkeeper生成的Access Token及令牌响应
Hey there! Let's break down how to handle your Doorkeeper Access Token customization needs step by step:
1. Customizing the Access Token Response
Doorkeeper gives you two flexible ways to tweak the JSON response returned when an access token is created:
Option 1: Use the custom_response config block
Add this to your config/initializers/doorkeeper.rb to directly modify the response payload with minimal code:
Doorkeeper.configure do # ... keep your existing configuration settings custom_response do |token, options| # Start with default required fields, then merge in your custom data default_payload = { access_token: token.token, token_type: token.token_type, expires_in: token.expires_in, refresh_token: token.refresh_token } default_payload.merge({ resource_owner_id: token.resource_owner_id, app_display_name: token.application&.name, your_custom_field: "any_value_you_need" }) end end
Option 2: Override the TokenResponse class
For more complex response logic (like fetching related model data), create a custom response class in app/lib/doorkeeper/custom_token_response.rb:
module Doorkeeper class CustomTokenResponse < TokenResponse def body # Call super to get the default response, then append custom fields super.merge({ user_email: token.resource_owner&.email, # Pull data from your User model custom_metadata: "custom_data_for_frontend" }) end end end
Then reference this class in your Doorkeeper config:
Doorkeeper.configure do # ... existing configs access_token_response_class Doorkeeper::CustomTokenResponse end
2. Adding Custom Attributes to Access Tokens
To store custom data alongside the access token in the oauth_access_tokens table, follow these steps:
- Add database columns via a Rails migration:
rails generate migration AddCustomFieldsToOauthAccessTokens user_context:string preferences:text rails db:migrate
- Whitelist the attributes in your Doorkeeper config (
config/initializers/doorkeeper.rb):
Doorkeeper.configure do # ... existing configs access_token_attributes :user_context, :preferences end
- Include custom attributes when creating tokens:
Now you can pass your custom fields directly to thecreate!method:
Doorkeeper::AccessToken.create!( application_id: application_id, resource_owner_id: resource_owner_id, user_context: "mobile_app", preferences: { notification_enabled: true }.to_json )
3. Customizing the Auto-Generated Access Token String
Doorkeeper uses SecureRandom.hex by default for token generation. To replace this with your own logic:
Option 1: Simple customization with a Proc
Add this to your Doorkeeper config to generate tokens in a different format (e.g., base64 instead of hex):
Doorkeeper.configure do # ... existing configs access_token_generator ->(token) { SecureRandom.base64(32) } # Generates a 44-character token end
Option 2: Custom generator class for complex logic
For advanced use cases (like including user IDs, timestamps, or custom hashing), create app/lib/doorkeeper/custom_access_token_generator.rb:
module Doorkeeper class CustomAccessTokenGenerator < AccessTokenGenerator def generate(access_token) # Example: Combine resource owner ID, timestamp, and random string for uniqueness timestamp = Time.current.to_i random_segment = SecureRandom.hex(16) "#{access_token.resource_owner_id}_#{timestamp}_#{random_segment}" end end end
Then register the generator in your config:
Doorkeeper.configure do # ... existing configs access_token_generator Doorkeeper::CustomAccessTokenGenerator end
内容的提问来源于stack exchange,提问作者viveksrivastava

