Skip to content

认证与授权 ​

MengStack 内置完整的认证授权系统,基于 JWT 双 Token 机制。

认证流程 ​

┌────────┐     POST /auth/register     ┌────────┐
│ Client │ ──────────────────────────→ │ Server │
│        │ ←────────────────────────── │        │
│        │   { access_token, refresh }  │        │
│        │                              │        │
│        │     POST /auth/login         │        │
│        │ ──────────────────────────→ │        │
│        │ ←────────────────────────── │        │
│        │   { access_token, refresh }  │        │
│        │                              │        │
│        │   GET /api/v1/profile        │        │
│        │   Authorization: Bearer xxx  │        │
│        │ ──────────────────────────→ │        │
│        │ ←────────────────────────── │        │
│        │   { user data }              │        │
│        │                              │        │
│        │   POST /auth/refresh         │        │
│        │   { refresh_token }          │        │
│        │ ──────────────────────────→ │        │
│        │ ←────────────────────────── │        │
│        │   { new token pair }         │        │
└────────┘                              └────────┘

API 端点 ​

端点方法说明认证
/api/v1/auth/registerPOST用户注册无
/api/v1/auth/loginPOST用户登录无
/api/v1/auth/refreshPOST刷新令牌无
/api/v1/passwordPOST修改密码Bearer
/api/v1/profileGET获取当前用户Bearer

注册 ​

bash
curl -X POST http://localhost:2222/api/v1/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "email": "user@example.com",
    "username": "johndoe",
    "nickname": "John Doe",
    "password": "securepass123"
  }'

响应:

json
{
  "code": 0,
  "message": "success",
  "data": {
    "access_token": "eyJhbGciOiJIUzI1NiIs...",
    "refresh_token": "eyJhbGciOiJIUzI1NiIs...",
    "expires_in": 7200
  },
  "trace_id": "abc-123-def"
}

登录 ​

bash
curl -X POST http://localhost:2222/api/v1/auth/login \
  -H "Content-Type: application/json" \
  -d '{
    "email": "user@example.com",
    "password": "securepass123"
  }'

使用 Access Token ​

在请求头中携带 Authorization: Bearer <access_token>:

bash
curl http://localhost:2222/api/v1/profile \
  -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIs..."

刷新 Token ​

Access Token 过期后,使用 Refresh Token 获取新的令牌对:

bash
curl -X POST http://localhost:2222/api/v1/auth/refresh \
  -H "Content-Type: application/json" \
  -d '{
    "refresh_token": "eyJhbGciOiJIUzI1NiIs..."
  }'

安全特性 ​

  • 密码哈希:使用 bcrypt 加密存储,永不明文
  • 双 Token:Access Token 短期有效(2h),Refresh Token 长期有效(7d)
  • Token 轮换:每次刷新都生成全新的令牌对
  • 验证约束:用户名 3-64 字符,密码 8-128 字符,邮箱格式校验