params['secretKey']; $key = new Key($salt); $host = httpUtil::getHost(); $sourceId = WxOpenService::getSourceId(); $jwtId = $sourceId . '_' . $uniqueId; $token = (new Builder())->issuedBy($host)//发布者的url地址 ->canOnlyBeUsedBy($host)//接受者的url地址 ->identifiedBy($jwtId, true)//该jwt的唯一ID编号 ->issuedAt($time)//该jwt的发布时间 ->canOnlyBeUsedAfter($time)//该jwt的使用时间不能早于该时间 ->expiresAt($time + 8640000)//该jwt销毁的时间 ->set('uniqueId', $uniqueId) ->set('sourceId', $sourceId) ->sign($signer, $key)->getToken(); return (string)$token; } public static function getKeyName($sourceId, $uniqueId) { return 'JWT_' . $sourceId . '_' . $uniqueId; } //验证token public static function validate($token) { $token = (new Parser())->parse($token); //数据校验 $data = new ValidationData();//使用当前时间来校验数据 if (!$token->validate($data)) { Yii::info('token时间验证没有通过。token:' . $token); return 0; } //token校验 $signer = new Sha256();//生成JWT时使用的加密方式 $salt = Yii::$app->params['secretKey']; if (!$token->verify($signer, new Key($salt))) { Yii::info('token解密没有通过。token:' . $token); return 0; } $token->getHeaders(); // 获取JWT的Header(头部)信息 $token->getClaims(); // 获取JWT的PayLoad(负载)信息 $uniqueId = $token->getClaim('uniqueId'); $sourceId = $token->getClaim('sourceId'); $currentSourceId = WxOpenService::getSourceId(); if ($sourceId != $currentSourceId) { return 0; } return $uniqueId; } //判断有没登陆并返回id shish 2019.11.22 public static function getLoginId() { $header = httpUtil::getHeader(); $token = isset($header['token']) ? $header['token'] : ''; if (empty($token)) { return 0; } return self::validate($token); } public static function delToken($uniqueId) { $token = httpUtil::getToken(); $host = httpUtil::getHost(); $signer = new Sha256();//生成JWT时使用的加密方式 $salt = Yii::$app->params['secretKey']; $signKey = new Key($salt); $token = (new Parser())->parse($token); //数据校验 $data = new ValidationData();//使用当前时间来校验数据 $data->setIssuer($host); $data->setAudience($host); if (!$token->verify($signer, $signKey)) { Yii::info('token解密没有通过。token:' . $token); return false; } if (!$token->validate($data)) { Yii::info('token验证没有通过。token:' . $token); return false; } $token->getHeaders(); // 获取JWT的Header(头部)信息 $token->getClaims(); // 获取JWT的PayLoad(负载)信息 $returnId = $token->getClaim('uniqueId'); $sourceId = $token->getClaim('sourceId'); $currentSourceId = WxOpenService::getSourceId(); echo $currentSourceId.' '.$sourceId.' '.$returnId.' '.$uniqueId; die; if($currentSourceId != $sourceId){ Yii::info('不是你此端的token。token:' . $token); return false; } if ($returnId != $uniqueId) { Yii::info('token验证出的id不是登陆用户id。token:' . $token); return false; } //设置为过期 $data->setCurrentTime(time() + 600); return true; } }