OAuth 授权码接入
最后更新于 2026-09-18
流程
1. 你的站点 GET /admin/login
2. 302 → auth.geekhonize.top /authorize?client_id=…&redirect_uri=…&state=…
3. 用户在账号中心登录并同意
4. 回跳 redirect_uri?code=…&state=…
5. 服务端换令牌 POST /api/v1/auth/exchange第一步:申请 client
在 SSO 的 apps 表中登记:
INSERT INTO apps (app_key, display_name, enabled, redirect_uris, client_secret)
VALUES ('your-app', '你的应用', 1, 'https://your.app/callback', '<随机密钥>');第二步:发起授权
https://auth.geekhonize.top/authorize
?client_id=your-app
&redirect_uri=https%3A%2F%2Fyour.app%2Fcallback
&state=<随机串>
&scope=openid+profileredirect_uri 必须与登记的值完全一致,否则会被拒绝。
第三步:换令牌
curl -X POST https://auth.geekhonize.top/api/v1/auth/exchange \n -H "content-type: application/json" \n -d '{"client_id":"your-app","client_secret":"***","code":"<授权码>"}'返回:
{
"ok": true,
"access_token": "eyJ…",
"token_type": "Bearer",
"expires_in": 604800,
"user": {
"uid": 6, "username": "huang1057",
"display_name": "Huang", "email": "…",
"roles": ["player", "admin"]
}
}授权码一次性使用,有效期 2 分钟。
第四步:验证会话
用拿到的 access_token 调用 GET /api/v1/auth/me 可以随时确认账号状态——账号被封禁或令牌失效会返回 401/403。