跳到主要内容
GeekHonize 官方站点
  1. 首页
  2. 文档
  3. 账号与授权
  4. OAuth 授权码接入

OAuth 授权码接入

最后更新于 2026-09-18

流程

1. 你的站点                    GET /admin/login
2. 302 → auth.geekhonize.top   /authorize?client_id=…&redirect_uri=…&state=…
3. 用户在账号中心登录并同意
4. 回跳                        redirect_uri?code=…&state=…
5. 服务端换令牌                POST /api/v1/auth/exchange

第一步:申请 client

在 SSO 的 apps 表中登记:

INSERT INTO apps (app_key, display_name, enabled, redirect_uris, client_secret)
VALUES ('your-app', '你的应用', 1, 'https://your.app/callback', '<随机密钥>');

第二步:发起授权

https://auth.geekhonize.top/authorize
  ?client_id=your-app
  &redirect_uri=https%3A%2F%2Fyour.app%2Fcallback
  &state=<随机串>
  &scope=openid+profile

redirect_uri 必须与登记的值完全一致,否则会被拒绝。

第三步:换令牌

curl -X POST https://auth.geekhonize.top/api/v1/auth/exchange \n  -H "content-type: application/json" \n  -d '{"client_id":"your-app","client_secret":"***","code":"<授权码>"}'

返回:

{
  "ok": true,
  "access_token": "eyJ…",
  "token_type": "Bearer",
  "expires_in": 604800,
  "user": {
    "uid": 6, "username": "huang1057",
    "display_name": "Huang", "email": "…",
    "roles": ["player", "admin"]
  }
}

授权码一次性使用,有效期 2 分钟。

第四步:验证会话

用拿到的 access_token 调用 GET /api/v1/auth/me 可以随时确认账号状态——账号被封禁或令牌失效会返回 401/403。