IndexController.php 2.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Models\User;
  4. use Illuminate\Http\Request;
  5. use Illuminate\Support\Facades\Auth;
  6. class IndexController extends Controller
  7. {
  8. public function __construct()
  9. {
  10. // 这里额外注意了:官方文档样例中只除外了『login』
  11. // 这样的结果是,token 只能在有效期以内进行刷新,过期无法刷新
  12. // 如果把 refresh 也放进去,token 即使过期但仍在刷新期以内也可刷新
  13. // 不过刷新一次作废
  14. $this->middleware('auth:api', ['except' => ['login']]);
  15. // 另外关于上面的中间件,官方文档写的是『auth:api』
  16. // 但是我推荐用 『jwt.auth』,效果是一样的,但是有更加丰富的报错信息返回
  17. }
  18. /**
  19. * Get a JWT via given credentials.
  20. *
  21. * @return \Illuminate\Http\JsonResponse
  22. */
  23. public function login(Request $request)
  24. {
  25. $credentials = request(['id', 'password']);
  26. $credentials['password'] = md5($request->password);
  27. if (! $token = auth('api')->attempt($credentials)) {
  28. return response()->json(['error' => 'Unauthorized'], 401);
  29. }
  30. return $this->respondWithToken($token);
  31. }
  32. /**
  33. * Get the authenticated User.
  34. *
  35. * @return \Illuminate\Http\JsonResponse
  36. */
  37. public function me()
  38. {
  39. return response()->json(auth('api')->user());
  40. }
  41. /**
  42. * Log the user out (Invalidate the token).
  43. *
  44. * @return \Illuminate\Http\JsonResponse
  45. */
  46. public function logout()
  47. {
  48. auth('api')->logout();
  49. return response()->json(['message' => 'Successfully logged out']);
  50. }
  51. /**
  52. * Refresh a token.
  53. * 刷新token,如果开启黑名单,以前的token便会失效。
  54. * 值得注意的是用上面的getToken再获取一次Token并不算做刷新,两次获得的Token是并行的,即两个都可用。
  55. * @return \Illuminate\Http\JsonResponse
  56. */
  57. public function refresh()
  58. {
  59. return $this->respondWithToken(auth('api')->refresh());
  60. }
  61. /**
  62. * Get the token array structure.
  63. *
  64. * @param string $token
  65. *
  66. * @return \Illuminate\Http\JsonResponse
  67. */
  68. protected function respondWithToken($token)
  69. {
  70. return response()->json([
  71. 'access_token' => $token,
  72. 'token_type' => 'bearer',
  73. 'expires_in' => auth('api')->factory()->getTTL() * 60
  74. ]);
  75. }
  76. }