使用itsdangerous生成有时间限制的token

>>> from itsdangerous import TimedJSONWebSignatureSerializer as Serializer
# 设置加密密钥为“key”,限制时间为60秒
>>> s = Serializer("key", 60)
>>> token = s.dumps({'id':'12345'}).decode('utf-8')
>>> s.loads(token.encode('utf-8'))
{'id': '12345'}
# 过60秒后
>>> s.loads(token.encode('utf-8'))
---------------------------------------------------------------------------
SignatureExpired                          Traceback (most recent call last)
<ipython-input-10-bd8c51b9c85a> in <module>
----> 1 s.loads(token.encode('utf-8'))

~/.local/lib/python3.6/site-packages/itsdangerous/jws.py in loads(self, s, salt, return_header)
    203                 "Signature expired",
    204                 payload=payload,
--> 205                 date_signed=self.get_issue_date(header),
    206             )
    207 

SignatureExpired: Signature expired
使用的是Python+vue来写的,但是现在有个问题,import json # import simplejson from flask import Flask, request from flask_cors import CORS # from util.redis_poi import Redis # from util import Serializers from blueprint.main_blue_print import main_bp from blueprint.seafly_blue_print import sf_bp from config.CONFIG import openapi_pass_router, pass_router_admin from config_ import CODE from util.common import get_data from util.token_szl import check_token """ 初始化 """ app = Flask(__name__) CORS(app, resources=r'/*', supports_credentials=True) pass_router = pass_router_admin + openapi_pass_router app.register_blueprint(sf_bp) # 以下蓝图需要加解密注解 app.register_blueprint(main_bp) """ 除了oa,main,cw,dev的蓝图,其他的蓝图路由内的业务代码必要通过@encrypt_decrypt_decorator注解加密解密 """ @app.before_request def before_request(): if request.path in pass_router: if request.path in openapi_pass_router: request_data = get_data(request) if not request_data.get('access_key') or not request_data.get('encrypt'): return { "code": CODE.CODE.FAIL.RQU_PARA_MISS_ENCRY, "message": '缺少必要总参' } pass else: check = check_token(request.headers.get('token')) if not check: return { "code": CODE.CODE.FAIL.TOKEN_ERROR, "message": 'token验证失效' } @app.after_request def after_request(response): response.headers['Access-Control-Allow-Origin'] = '*' response.headers['Access-Control-Allow-Methods'] = 'PUT,GET,POST,DELETE,OPTION' response.headers['Access-Control-Allow-Headers'] = 'Content-Type,Authorization,Token' response.headers['Access-Control-Allow-Credentials'] = 'true' response.headers['Access-Control-Expose-Headers'] = 'token' return response if __name__ == '__main__': app.run(host='0.0.0.0', port=8878, debug=True)
最新发布
03-14
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值