[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"public:announcements":3,"public:navigations:zh":4,"footer:categories:zh":56,"post:detail:post-19-JWT认证安全最佳:zh":177},[],[5,18,25,33,41,49],{"id":6,"title":7,"url":12,"icon":13,"parent_id":13,"location":14,"order":6,"is_active":15,"target_blank":16,"created_at":17,"updated_at":13},1,{"zh":8,"en":9,"ja":10,"zh_TW":11},"首页","Home","ホーム","首頁","\u002F",null,"header",true,false,"2026-09-30T18:09:54.251095Z",{"id":19,"title":20,"url":24,"icon":13,"parent_id":13,"location":14,"order":19,"is_active":15,"target_blank":16,"created_at":17,"updated_at":13},2,{"zh":21,"en":22,"ja":23,"zh_TW":21},"文章","Posts","記事","\u002Fposts",{"id":26,"title":27,"url":32,"icon":13,"parent_id":13,"location":14,"order":26,"is_active":15,"target_blank":16,"created_at":17,"updated_at":13},3,{"zh":28,"en":29,"ja":30,"zh_TW":31},"分类","Categories","カテゴリー","分類","\u002Fcategories",{"id":34,"title":35,"url":40,"icon":13,"parent_id":13,"location":14,"order":34,"is_active":15,"target_blank":16,"created_at":17,"updated_at":13},4,{"zh":36,"en":37,"ja":38,"zh_TW":39},"标签","Tags","タグ","標籤","\u002Ftags",{"id":42,"title":43,"url":48,"icon":13,"parent_id":13,"location":14,"order":42,"is_active":15,"target_blank":16,"created_at":17,"updated_at":13},5,{"zh":44,"en":45,"ja":46,"zh_TW":47},"关于","About","概要","關於","\u002Fpage\u002Fabout",{"id":50,"title":51,"url":55,"icon":13,"parent_id":13,"location":14,"order":50,"is_active":15,"target_blank":16,"created_at":17,"updated_at":13},6,{"zh":52,"en":53,"ja":54,"zh_TW":52},"留言板","Guestbook","ゲストブック","\u002Fpage\u002Fguestbook",[57,73,87,102,117,133,148,162],{"id":6,"name":58,"slug":63,"description":64,"icon":69,"color":70,"cover_image":13,"created_at":71,"post_count":72},{"en":59,"ja":60,"zh":61,"zh_Hant":62},"Technology","テクノロジー","技术","技術","technology",{"en":65,"ja":66,"zh":67,"zh_Hant":68},"Cutting-edge technology exploration and in-depth analysis covering programming languages, frameworks, and architecture design","プログラミング言語、フレームワーク、アーキテクチャ設計を含む先端技術の探究","前沿技术探索与深度分析，涵盖编程语言、框架、架构设计等核心领域","前沿技術探索與深度分析，涵蓋編程語言、框架、架構設計等核心領域","heroicons:cog-6-tooth","#6366f1","2026-09-30T18:09:53.633610Z",8,{"id":19,"name":74,"slug":78,"description":79,"icon":84,"color":85,"cover_image":13,"created_at":86,"post_count":50},{"en":75,"ja":76,"zh":77,"zh_Hant":77},"Tutorial","チュートリアル","教程","tutorial",{"en":80,"ja":81,"zh":82,"zh_Hant":83},"Hands-on tutorials from scratch with clear steps and complete code for developers at all levels","ゼロから始める実践的なチュートリアル。明確な手順と完全なコードで、全てのレベルの開発者に最適","从零开始的实战教程，步骤清晰，代码完整，适合各阶段开发者学习","從零開始的實戰教程，步驟清晰，代碼完整，適合各階段開發者學習","heroicons:academic-cap","#10b981","2026-09-30T18:09:53.641581Z",{"id":26,"name":88,"slug":92,"description":93,"icon":98,"color":99,"cover_image":13,"created_at":100,"post_count":101},{"en":89,"ja":90,"zh":91,"zh_Hant":91},"Frontend","フロントエンド","前端","frontend",{"en":94,"ja":95,"zh":96,"zh_Hant":97},"Full coverage of web frontend development including Vue, React, new CSS features, and performance optimization","Vue、React、CSSの新機能やパフォーマンス最適化を含むWebフロントエンド開発の全領域","Web前端开发全栈覆盖，包括Vue、React、CSS新特性及性能优化等话题","Web前端開發全棧覆蓋，包括Vue、React、CSS新特性及性能優化等話題","heroicons:computer-desktop","#ec4899","2026-09-30T18:09:53.644838Z",7,{"id":34,"name":103,"slug":108,"description":109,"icon":114,"color":115,"cover_image":13,"created_at":116,"post_count":26},{"en":104,"ja":105,"zh":106,"zh_Hant":107},"Backend","バックエンド","后端","後端","backend",{"en":110,"ja":111,"zh":112,"zh_Hant":113},"Server-side development best practices including API design, database optimization, and microservices architecture","API設計、データベース最適化、マイクロサービスアーキテクチャを含むサーバーサイド開発の実践","服务端开发实战经验，API设计、数据库优化、微服务架构等深度内容","服務端開發實戰經驗，API設計、數據庫優化、微服務架構等深度內容","heroicons:server-stack","#f59e0b","2026-09-30T18:09:53.647836Z",{"id":42,"name":118,"slug":123,"description":124,"icon":129,"color":130,"cover_image":13,"created_at":131,"post_count":132},{"en":119,"ja":120,"zh":121,"zh_Hant":122},"Fullstack","フルスタック","全栈","全棧","fullstack",{"en":125,"ja":126,"zh":127,"zh_Hant":128},"End-to-end development guides covering the full project lifecycle and technology stack selection","フロントエンドからバックエンドまでの開発プロセス全体をカバーするガイド","从前端到后端的全流程开发指南，覆盖完整项目生命周期与技术选型","從前端到後端的全流程開發指南，覆蓋完整項目生命週期與技術選型","heroicons:swatch","#8b5cf6","2026-09-30T18:09:53.650513Z",0,{"id":50,"name":134,"slug":139,"description":140,"icon":145,"color":146,"cover_image":13,"created_at":147,"post_count":34},{"en":135,"ja":136,"zh":137,"zh_Hant":138},"Essays","エッセイ","随笔","隨筆","essays",{"en":141,"ja":142,"zh":143,"zh_Hant":144},"Technical reflections and development insights recording the programmer's growth journey","プログラマーの成長の軌跡を記録する技術的考察と開発の洞察","技术思考与开发心得分享，记录程序员成长路上的点滴感悟","技術思考與開發心得分享，記錄程序員成長路上的點滴感悟","heroicons:pencil-square","#f43f5e","2026-09-30T18:09:53.653105Z",{"id":101,"name":149,"slug":153,"description":154,"icon":159,"color":160,"cover_image":13,"created_at":161,"post_count":34},{"en":150,"ja":151,"zh":152,"zh_Hant":152},"Tools","ツール","工具","tools",{"en":155,"ja":156,"zh":157,"zh_Hant":158},"Development toolchain and productivity tool recommendations to supercharge your development experience","開発効率を飛躍的に向上させるツールチェーンと生産性ツールの推奨","开发工具链与效率提升利器推荐，让你的开发体验如虎添翼","開發工具鏈與效率提升利器推薦，讓你的開發體驗如虎添翼","heroicons:wrench-screwdriver","#06b6d4","2026-09-30T18:09:53.655605Z",{"id":72,"name":163,"slug":168,"description":169,"icon":174,"color":175,"cover_image":13,"created_at":176,"post_count":132},{"en":164,"ja":165,"zh":166,"zh_Hant":167},"Translation","翻訳","翻译","翻譯","translation",{"en":170,"ja":171,"zh":172,"zh_Hant":173},"Curated translations of high-quality foreign technical articles to keep up with international trends","国際的な技術トレンドを追うための厳選された海外技術記事の翻訳","优质外文技术文章精选翻译，紧跟国际技术前沿动态","優質外文技術文章精選翻譯，緊跟國際技術前沿動態","heroicons:language","#84cc16","2026-09-30T18:09:53.658041Z",{"id":178,"title":179,"subtitle":13,"slug":180,"source":181,"source_url":13,"audio":13,"video":13,"video_url":13,"content":182,"excerpt":183,"cover_image":13,"author":184,"category":187,"tags":188,"status":210,"visibility":211,"password":13,"views":212,"likes_count":132,"is_pinned":16,"allow_comments":15,"comments_count":42,"is_password_protected":16,"meta_title":179,"meta_description":183,"meta_keywords":213,"created_at":214,"published_at":214,"updated_at":215,"reading_time":6},19,"JWT 认证安全最佳实践 + OAuth2 vs SAML","post-19-JWT认证安全最佳","原创","# JWT 认证安全最佳实践 + OAuth2 vs SAML\n\nJWT 因其无状态、跨服务易用被广泛采用，但配置不严谨会成攻击重灾区。现代系统常需第三方登录或企业 SSO，选对联邦协议也是架构师必修课。\n\n## JWT 安全实现要点\n\n绝对不要使用对称密钥 HMAC 直接在前端签发（密钥会泄漏），生产用 RS256\u002FES256 非对称，公钥公开验证。严格白名单允许算法、用 timingSafeEqual 做 iss\u002Faud 对比防时序攻击，jti 黑名单支持吊销。\n\n```typescript\n```typescript\nimport { createSign, createVerify, randomBytes, timingSafeEqual } from \"node:crypto\";\n\nexport interface JwtConfig {\n    algorithm: \"RS256\";\n    privateKeyPem: string;\n    publicKeyPem: string;\n    issuer: string;\n    audience: string;\n    accessTokenTtlSec: number;\n    allowedAlgos: readonly string[];\n}\nexport interface TokenPayload {\n    sub: string; scopes: readonly string[]; jti: string;\n    exp: number; nbf: number; iat: number; iss: string; aud: string;\n}\nconst B64 = {\n    enc: (b: Buffer) => b.toString(\"base64url\"),\n    dec: (s: string) => Buffer.from(s, \"base64url\"),\n};\nconst DENIED = new Set\u003Cstring>();\n\nexport function createJwt(cfg: JwtConfig, claims: Partial\u003CTokenPayload> & { sub: string; scopes: readonly string[] }): string {\n    const now = Math.floor(Date.now() \u002F 1000);\n    const header = { alg: cfg.algorithm, typ: \"JWT\", kid: \"k1\" };\n    const payload: TokenPayload = {\n        sub: claims.sub, scopes: claims.scopes,\n        jti: randomBytes(16).toString(\"hex\"),\n        iat: now, nbf: now, exp: now + cfg.accessTokenTtlSec,\n        iss: cfg.issuer, aud: cfg.audience,\n    };\n    const input = `${B64.enc(Buffer.from(JSON.stringify(header)))}.${B64.enc(Buffer.from(JSON.stringify(payload)))}`;\n    const s = createSign(\"RSA-SHA256\"); s.update(input);\n    return `${input}.${B64.enc(s.sign(cfg.privateKeyPem))}`;\n}\n\nexport function verifyJwt(cfg: JwtConfig, token: string): TokenPayload {\n    const parts = token.split(\".\");\n    if (parts.length !== 3) throw new Error(\"malformed\");\n    const [hB64, pB64, sB64] = parts;\n    const header = JSON.parse(B64.dec(hB64).toString());\n    if (!cfg.allowedAlgos.includes(header.alg) || header.alg === \"none\") throw new Error(\"alg not allowed\");\n    const ver = createVerify(\"RSA-SHA256\"); ver.update(`${hB64}.${pB64}`);\n    if (!ver.verify(cfg.publicKeyPem, B64.dec(sB64))) throw new Error(\"signature mismatch\");\n    const p = JSON.parse(B64.dec(pB64).toString()) as TokenPayload;\n    if (!timingSafeEqual(Buffer.from(p.iss), Buffer.from(cfg.issuer))) throw new Error(\"iss\");\n    if (p.aud !== cfg.audience) throw new Error(\"aud\");\n    const now = Math.floor(Date.now() \u002F 1000);\n    if (p.exp \u003C now) throw new Error(\"expired\");\n    if (p.nbf > now) throw new Error(\"not yet valid\");\n    if (DENIED.has(p.jti)) throw new Error(\"revoked\");\n    return p;\n}\n```\n```\n\n## OAuth2 \u002F OIDC \u002F SAML 对比\n\nOAuth2 是授权框架不是认证协议，OpenID Connect 在其之上加了 id_token 才是登录。SAML 2.0 是传统企业联邦协议，XML 格式兼容性强但移动端体验差。\n\n| 特性 | OAuth2 + PKCE | OIDC (基于OAuth2) | SAML 2.0 |\n|------|--------------|------------------|----------|\n| 本质 | 授权(delegation) | 认证(authentication) | 认证+授权联邦 |\n| 适用 | 移动端\u002FSPA | Web\u002F移动\u002FAPI | 企业内部SSO |\n| Token | access_token | access_token + id_token(JWT) | SAML Assertion(XML) |\n| 安全性 | 需PKCE防code注入 | 原生支持nonce | 签名XML流程复杂 |\n| 移动端体验 | 好(App转场) | 好 | 差(重定向多) |\n| 集成复杂度 | 中 | 低 | 高(双方元数据) |\n\n## 最佳实践\n\nJWT 存敏感信息：短 TTL(5-15min) + refresh_token 轮换。SPA 用 HttpOnly Cookie 承载 refresh_token 避免 XSS。第三方登录场景统一用 OIDC。","系统性归纳 JWT 常见安全漏洞防护：算法混淆攻击（none\u002FRS256→HS256）、密钥爆破、KID注入、重放攻击防御，再从多个维度对比 OAuth2（授权码+PKCE）、OIDC、SAML 2.0 三种主流认证协议选型。",{"id":6,"username":185,"nickname":185,"avatar":13,"cover_image":13,"bio":13,"website":13,"github":13,"avatar_source":13,"resolved_avatar_url":13,"title":13,"created_at":186},"Choyeon","2026-09-30T18:09:53.330367Z",{"id":50,"name":137,"slug":139,"description":143,"icon":145,"color":146,"cover_image":13,"created_at":147,"post_count":132},[189,194,199,204],{"id":6,"name":190,"slug":191,"color":192,"icon":13,"is_active":15,"created_at":193,"post_count":132},"Python","python","#3776ab","2026-09-30T18:09:53.663835Z",{"id":19,"name":195,"slug":196,"color":197,"icon":13,"is_active":15,"created_at":198,"post_count":132},"FastAPI","fastapi","#009688","2026-09-30T18:09:53.669567Z",{"id":72,"name":200,"slug":201,"color":202,"icon":13,"is_active":15,"created_at":203,"post_count":132},"Node.js","nodejs","#339933","2026-09-30T18:09:53.685769Z",{"id":205,"name":206,"slug":207,"color":208,"icon":13,"is_active":15,"created_at":209,"post_count":132},16,"安全","security","#14b8a6","2026-09-30T18:09:53.709991Z","published","public",135,"安全,FastAPI,Node.js,Python","2026-09-11T20:09:53.733462Z","2026-10-01T04:54:47.655492Z"]