You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

FeathersJS认证:基于local JWT实现用户禁用功能的配置咨询

How to Implement User Disabling Checks in FeathersJS 3.x with Local JWT Auth

Hey there! Let's get this user disabling feature sorted for your FeathersJS app. Since you already have the isDisabled field in your user model and are running local + JWT auth with the versions you listed, here's exactly where and how to add the necessary checks:

1. Block Disabled Users from Logging In (Local Authentication)

First, we need to stop disabled users from getting a JWT token in the first place when they try to log in. We'll customize the local authentication strategy's verify function to check the isDisabled field before allowing login.

In your authentication configuration file (usually src/authentication.js), update the local strategy setup:

const authentication = require('@feathersjs/authentication');
const local = require('@feathersjs/authentication-local');
const jwt = require('@feathersjs/authentication-jwt');

module.exports = function(app) {
  const config = app.get('authentication');

  app.configure(authentication(config));
  app.configure(local({
    // Custom verify function to check user status
    verify: async (req, loginIdentifier, password) => {
      const userService = app.service('users');
      
      // Fetch the user by your login field (adjust to use username if that's your setup)
      const user = await userService.find({
        query: {
          email: loginIdentifier,
          $limit: 1
        }
      }).then(results => results[0]);

      if (!user) {
        throw new Error('User not found');
      }

      // Reject login if user is disabled
      if (user.isDisabled) {
        throw new Error('This account has been disabled. Please contact support.');
      }

      // Verify password using the default local auth method
      const isPasswordValid = await local.verifyPassword(password, user.password);
      if (!isPasswordValid) {
        throw new Error('Invalid password');
      }

      return user;
    }
  }));
  app.configure(jwt());

  // Rest of your authentication config...
};

2. Block Disabled Users from Accessing Protected Services (JWT Auth)

Even if a disabled user already has a valid JWT token, we need to block them from accessing any protected routes on every request. We'll create a custom hook to check the user's isDisabled status, then apply it to your services.

Step 2.1: Create the Custom Hook

Make a new file src/hooks/check-user-disabled.js with this code:

module.exports = function(options = {}) {
  return async context => {
    const { user } = context.params;

    // If the user exists and is disabled, throw an error
    if (user && user.isDisabled) {
      throw new Error('Your account has been disabled. Please contact support.');
    }

    return context;
  };
};

Step 2.2: Apply the Hook to Protected Services

Add this hook to the before hooks of any service that requires authentication. For example, in src/services/users/users.hooks.js:

const { authenticate } = require('@feathersjs/authentication');
const checkUserDisabled = require('../../hooks/check-user-disabled');

module.exports = {
  before: {
    all: [ authenticate('jwt'), checkUserDisabled() ],
    find: [],
    get: [],
    create: [],
    update: [],
    patch: [],
    remove: []
  },
  // Rest of your user service hooks...
};

If you want to apply this check globally to all services (except the authentication service itself), update src/app.hooks.js:

const { authenticate } = require('@feathersjs/authentication');
const checkUserDisabled = require('./hooks/check-user-disabled');

module.exports = {
  before: {
    all: [
      // Skip authentication for the authentication service to avoid loops
      context => {
        if (context.path !== 'authentication') {
          return authenticate('jwt')(context);
        }
        return context;
      },
      checkUserDisabled()
    ],
    // Rest of your app hooks...
  }
};

Optional: Invalidate Existing JWTs for Disabled Users

If you need to invalidate active JWT tokens immediately when a user is disabled (instead of waiting for the token to expire), you'll need to implement a JWT blacklist. For Feathers 3.x, you can use a storage like Redis to track invalid tokens, then add a check in the JWT authentication hook to verify the token isn't in the blacklist.

Just remember to update the blacklist whenever you set isDisabled: true for a user.

内容的提问来源于stack exchange,提问作者Ricardas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:58:37