You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为dstore/Rest实例的PUT/POST请求添加Token参数?

Adding Token to dstore/Rest Requests

Great question! dstore/Rest provides flexible hooks to modify requests before they're sent, so you have two solid options to handle adding your token—either as a query parameter (as you specified) or in request headers (the more secure, recommended practice). Here's how to implement both:

Option 1: Add Token as a Query Parameter (For PUT/POST Requests)

You can override the beforeRequest method of your Rest store instance to dynamically append the token to the URL for POST/PUT requests. This method runs right before the request is sent, giving you full control over the request details:

const entries = new Rest({ 
    target: '/rest/entries'
});

// Override beforeRequest to inject token into query params for POST/PUT
entries.beforeRequest = function (kwArgs) {
    // Check if this is a POST (add) or PUT (update) request
    if (kwArgs.method === 'POST' || kwArgs.method === 'PUT') {
        const token = 'some_token'; // Replace with your actual token source (e.g., auth service)
        const requestUrl = new URL(kwArgs.url);
        requestUrl.searchParams.append('token', token);
        kwArgs.url = requestUrl.toString();
    }
    // Call the original beforeRequest logic to maintain default behavior
    return this.inherited(arguments);
};

When you call entries.add({id: 100500, value: 'someValue'}), this will generate a POST request to /rest/entries?token=some_token. For an update like entries.put({id: 100500, value: 'updatedValue'}), it will target /rest/entries/100500?token=some_token—exactly the format you need.

Option 2: Add Token to Request Headers (More Secure Alternative)

Putting tokens in headers is generally better practice because query parameters can be logged, cached, or exposed in browser history. You can use the same beforeRequest hook to add an authorization header:

const entries = new Rest({ 
    target: '/rest/entries'
});

entries.beforeRequest = function (kwArgs) {
    // Initialize headers object if it doesn't exist
    kwArgs.headers = kwArgs.headers || {};
    
    const token = 'some_token';
    // Use the standard Bearer token format (adjust if your API expects a different header)
    kwArgs.headers['Authorization'] = `Bearer ${token}`;
    // Or use a custom header if required:
    // kwArgs.headers['X-API-Token'] = token;
    
    return this.inherited(arguments);
};

This approach keeps your token hidden from URL exposure while still authenticating your add() and put() calls.

Scalable Reuse (For Multiple Stores)

If you need this token logic across multiple dstore instances, create a subclass of Rest to avoid repeating code:

class TokenAuthenticatedRest extends Rest {
    constructor(options) {
        super(options);
        this.authToken = options.token; // Pass token during initialization
    }

    beforeRequest(kwArgs) {
        if (kwArgs.method === 'POST' || kwArgs.method === 'PUT') {
            const requestUrl = new URL(kwArgs.url);
            requestUrl.searchParams.append('token', this.authToken);
            kwArgs.url = requestUrl.toString();
        }
        return super.beforeRequest(kwArgs);
    }
}

// Usage:
const entries = new TokenAuthenticatedRest({ 
    target: '/rest/entries', 
    token: 'some_token' 
});

内容的提问来源于stack exchange,提问作者soeik

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 08:23:35