package jwtutil import ( "errors" "time" "github.com/golang-jwt/jwt/v5" ) // 密钥(后续可从配置中读取) var secret = []byte("yunzer_jwt_secret_key") // Claims 定义JWT的claims结构 type Claims struct { UserID int `json:"user_id"` Username string `json:"username"` TenantId int `json:"tenant_id"` // 租户ID UserType string `json:"user_type"` // 用户类型:"user" / "employee" / "platform" 等 jwt.RegisteredClaims } // GenerateToken 生成JWT token func GenerateToken(userID int, username string, tenantId int, userType string) (string, error) { expirationTime := time.Now().Add(24 * time.Hour) claims := &Claims{ UserID: userID, Username: username, TenantId: tenantId, UserType: userType, RegisteredClaims: jwt.RegisteredClaims{ ExpiresAt: jwt.NewNumericDate(expirationTime), IssuedAt: jwt.NewNumericDate(time.Now()), NotBefore: jwt.NewNumericDate(time.Now()), }, } token := jwt.NewWithClaims(jwt.SigningMethodHS256, claims) tokenString, err := token.SignedString(secret) return tokenString, err } // ParseToken 解析JWT token func ParseToken(tokenString string) (*Claims, error) { claims := &Claims{} token, err := jwt.ParseWithClaims(tokenString, claims, func(token *jwt.Token) (interface{}, error) { if _, ok := token.Method.(*jwt.SigningMethodHMAC); !ok { return nil, errors.New("unexpected signing method") } return secret, nil }) if err != nil { return nil, err } if !token.Valid { return nil, errors.New("invalid token") } return claims, nil }