我将Symfony2与DunglasAngularCsrfBundle结合使用,当我运行PHpunit测试时,会得到错误{“代码”:403,“消息”:“不好的CSRF令牌”}。
如果使用http basic的auth用户
self::$user_client = static::createClient(array(), array(
'PHP_AUTH_USER' => 'user1@mail.com',
'PHP_AUTH_PW' => 'user1',
'HTTP_HOST' => static::getHost()
));此条件在EventListener\AngularCsrfValidationListener中返回false
if (!$value || !$this->angularCsrfTokenManager->isTokenValid($value)) {
throw new AccessDeniedHttpException('Bad CSRF token.');
}在测试中生成的令牌不相等,我尝试下面的另一个方法:
protected function logIn($email)
{
$this->client = static::createClient();
$user = $this->client->getContainer()
->get('doctrine')
->getManager()
->getRepository('UserBundle:User')
->findOneByEmail($email);
$providerKey = static::$kernel->getContainer()->getParameter('fos_user.firewall_name');
$token = new UsernamePasswordToken($user, null, $providerKey, $user->getRoles());
$session = $this->client->getContainer()->get('session');
$session->set('_security_'.$providerKey, serialize($token));
$session->save();
$cookie = new Cookie($session->getName(), $session->getId());
$this->client->getCookieJar()->set($cookie);}
令牌未创建。在Symfony\Component\Security\Csrf\CsrfTokenManager::isTokenValid:中返回false
$this->storage->hasToken($token->getId())请帮助解决这个问题,谢谢
发布于 2016-01-28 13:00:53
解出
self::$client->request('GET', '/') 在cookie中设置令牌
https://stackoverflow.com/questions/34989606
复制相似问题