You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将Laravel Passport的认证请求头改为X-Access-Token?

当然可以搞定这个需求!Laravel Passport虽然底层依赖League的OAuth2 Server组件,但我们有几种灵活的方式来把默认的Authorization请求头改成X-Access-Token,下面给你详细说说两种可行的方案:

方案一:自定义授权验证器(替换底层逻辑)

这种方式直接修改Passport依赖的League组件的验证逻辑,适合你想完全替换掉Authorization头的场景:

  1. 创建自定义验证器类
    在你的项目里新建一个自定义验证器,继承League的默认验证器,重写validateAuthorization方法来检查X-Access-Token头:
<?php

namespace App\OAuth2;

use League\OAuth2\Server\AuthorizationValidators\DefaultAuthorizationValidator;
use League\OAuth2\Server\Exception\OAuthServerException;
use Psr\Http\Message\ServerRequestInterface;

class CustomAuthorizationValidator extends DefaultAuthorizationValidator
{
    public function validateAuthorization(ServerRequestInterface $request)
    {
        // 只检查X-Access-Token头,如果需要兼容Authorization可以保留判断
        if (!$request->hasHeader('X-Access-Token')) {
            throw OAuthServerException::accessDenied('Missing "X-Access-Token" header');
        }

        $tokenHeader = $request->getHeaderLine('X-Access-Token');
        // 确保token带有Bearer前缀(如果你的前端没带的话)
        if (!str_starts_with($tokenHeader, 'Bearer ')) {
            $tokenHeader = 'Bearer ' . $tokenHeader;
        }

        // 将处理后的头注入回请求,让父类的逻辑继续执行
        $request = $request->withHeader('authorization', $tokenHeader);

        return parent::validateAuthorization($request);
    }
}
  1. 绑定自定义验证器到容器
    在App\Providers\AppServiceProvider的boot方法里,把默认的验证器替换成我们自定义的:
use App\OAuth2\CustomAuthorizationValidator;
use League\OAuth2\Server\AuthorizationValidators\AuthorizationValidatorInterface;

public function boot()
{
    $this->app->bind(AuthorizationValidatorInterface::class, CustomAuthorizationValidator::class);
}

方案二:用中间件转换请求头(更简单友好)

如果只是想兼容X-Access-Token头,不想改动底层验证逻辑,用中间件转换是更轻量的选择:

  1. 创建转换头的中间件
    新建一个中间件,在请求到达Passport验证前,把X-Access-Token的值转成Authorization头:
<?php

namespace App\Http\Middleware;

use Closure;
use Illuminate\Http\Request;

class ConvertAccessTokenHeader
{
    public function handle(Request $request, Closure $next)
    {
        // 如果存在X-Access-Token头且没有Authorization头,就进行转换
        if ($request->hasHeader('X-Access-Token') && !$request->hasHeader('Authorization')) {
            $token = $request->header('X-Access-Token');
            // 加上Bearer前缀,匹配Passport的预期格式
            $request->headers->set('Authorization', 'Bearer ' . $token);
        }

        return $next($request);
    }
}
  1. 注册中间件
    打开app/Http/Kernel.php,把这个中间件加到api中间件组里(因为Passport主要用于API路由):
protected $middlewareGroups = [
    'api' => [
        // 其他已有的中间件...
        \App\Http\Middleware\ConvertAccessTokenHeader::class,
    ],
];

小提示

  • 如果你想完全禁用Authorization头,只保留X-Access-Token,方案一更适合;
  • 如果只是想兼容两种头,方案二的成本更低,而且后续升级Passport时不会有冲突风险;
  • 记得确认前端传递的X-Access-Token是否带Bearer 前缀,如果没有,一定要在代码里补上,否则Passport会验证失败。

内容的提问来源于stack exchange,提问作者Stefano Maglione

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 07:47:53