具有用于请求身份验证的中间件和JWT的Web APIPython,Flask引发DecodeError“签名验证失败”

问题描述

我无法解码通过请求标头收到的令牌。

应用程序:

from flask import Flask
from flask import jsonify
from flask_restplus import Resource,Api
from helpers.load import get_env as _
from middleware.environment_middleware import EnvironmentMiddleware
from flask_jwt_extended import JWTManager


app = Flask(__name__)
app.config['SQLALCHEMY_DATABASE_URI'] = _('DATABASE_URI')
app.config['SQLALCHEMY_DATABASE_URI'] = _('DATABASE_URI')
app.config['SECRET_KEY'] = _('SECRET_KEY')
app.config['JWT_SECRET_KEY'] = _('JWT_SECRET')
app.wsgi_app = EnvironmentMiddleware(app.wsgi_app)

jwt = JWTManager(app)
api = Api(app)
jwt._set_error_handler_callbacks(api)

中间件类:

from werkzeug.wrappers import Request,Response,ResponseStream
from helpers.load import load_db_env
from flask_jwt_extended import get_jwt_identity,jwt_required,verify_jwt_in_request
import jwt


class EnvironmentMiddleware():
    def __init__(self,app):
        self.app = app

    def __call__(self,environ,start_response):
        request = Request(environ)
        if request.headers:
            params = load_db_env(request.headers.get('Whitelabel'))
            jwt.decode(request.headers.get('Authorization').replace('Bearer ',''),params['JWT_SECRET'],algorithm='HS256')
            return self.app(environ,start_response)

        res = Response(u'Unauthorized.',mimetype='application/json',status=401)
        return res(environ,start_response)

load_db_env 根据“ whitelabel”参数(包括 JWT_SECRET )和我的 environ 带来了我数据库中所有参数的字典。身份验证所需的数据,标题等。

但是出于某些原因,我无法从验证和识别用户的请求中解码并找到Bearer令牌内的信息。

Traceback (most recent call last):
  File "<string>",line 1,in <module>
  File "/home/bela/dev/bela/lib/python3.8/site-packages/jwt/api_jwt.py",line 63,in decode
    decoded = super(PyJWT,self).decode(jwt,key,verify,algorithms,File "/home/bela/dev/bela/lib/python3.8/site-packages/jwt/api_jws.py",line 115,in decode
    self._verify_signature(payload,signing_input,header,signature,line 186,in _verify_signature
    raise DecodeError('Signature verification failed')
jwt.exceptions.DecodeError: Signature verification failed

我希望我很清楚,我来自巴西,我的英语不是最好的。

Obrigada! :*

解决方法

暂无找到可以解决该程序问题的有效方法,小编努力寻找整理中!

如果你已经找到好的解决方法,欢迎将解决方案带上本链接一起发送给小编。

小编邮箱:dio#foxmail.com (将#修改为@)

相关问答

错误1:Request method ‘DELETE‘ not supported 错误还原:...
错误1:启动docker镜像时报错:Error response from daemon:...
错误1:private field ‘xxx‘ is never assigned 按Alt...
报错如下,通过源不能下载,最后警告pip需升级版本 Requirem...