Auth0 提供方在 Users & Permissions 中的设置

页面摘要: Auth0 提供方设置可为 Users & Permissions 功能启用 OAuth 2.0 身份验证,需要在 Auth0 租户和 Strapi 管理设置中使用 Client ID、Client Secret 和子域名凭据进行配置。

本页介绍如何为 Users & Permissions 功能 设置 Auth0 提供方。

WARNING

Auth0 配置

NOTE

Auth0 接受 localhost URL。

无需使用 ngrok。

  1. 访问你的 Auth0 租户仪表板
  2. 在 API 部分,创建一个新的 API
  3. 在 Application 中,创建一个 machine-to-machine 应用,并选择你刚刚创建的 API
  4. 在该应用的设置中,设置以下值:
    • Allowed Callback URLs:http://localhost:1337/api/connect/auth0/callback
    • Allowed Logout URLs:http://localhost:3000
    • Allowed Web Origins:http://localhost:3000
  5. 在设置底部,展开 "Advanced Settings"(高级设置)并进入 "Grant Types"(授权类型)。确保勾选/启用以下授权:
    • Implicit
    • Authorization Code
    • Refresh Token
    • Client Credentials

Strapi 配置

  1. 访问 User & Permissions 提供方设置页面,地址为 http://localhost:1337/admin/settings/users-permissions/providers
  2. 点击 Auth0 提供方
  3. 填写以下信息:
    • Enable:ON
    • Client ID:<Your Auth0 Client ID>
    • Client Secret:<Your Auth0 Client Secret>
    • Subdomain:<Your Auth0 tenant url>,例如它是以下 URL 中加粗的部分:https://my-tenant.eu.auth0.com/
    • 指向你前端应用的重定向 URL:http://localhost:3000/connect/auth0

你的配置已完成。启动后端和 react 登录示例应用,访问 http://localhost:3000 并尝试连接到你所配置的提供方。