Spring-Security 6.x版本入门讲解

本文详细介绍了如何在SpringSecurity中配置认证和授权,包括使用@EnableWebSecurity,自定义UsernamePasswordAuthenticationFilter和JwtAuthorizationFilter,以及JWT在权限验证中的应用。

Spring-Security

配置代码
package magnus.configuration;

import com.fasterxml.jackson.databind.ObjectMapper;
import jakarta.ws.rs.core.MediaType;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.authentication.AuthenticationManager;
import org.springframework.security.authentication.AuthenticationProvider;
import org.springframework.security.authentication.ProviderManager;
import org.springframework.security.authentication.dao.DaoAuthenticationProvider;
import org.springframework.security.config.Customizer;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configurers.AbstractHttpConfigurer;
import org.springframework.security.config.annotation.web.configurers.LogoutConfigurer;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.provisioning.InMemoryUserDetailsManager;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter;

import java.nio.charset.StandardCharsets;
import java.util.ArrayList;
import java.util.HashMap;
import java.util.List;
import java.util.Map;

@Configuration
@EnableWebSecurity
public class MagnusSecurityConfiguration {
   
   

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity httpSecurity,
                                                   ObjectMapper objectMapper) throws Exception {
   
   
        // 定义安全请求拦截规则
        httpSecurity.authorizeHttpRequests(request -> request.anyRequest().authenticated());
        // 给SpringSecurity注入 /login登录页面及用户密码表单处理的登录请求
        httpSecurity.formLogin(Customizer.withDefaults());
        // 登出请求注册
        httpSecurity.logout(LogoutConfigurer::permitAll);
//        httpSecurity.addFilterBefore(magnusUsernamePasswordFilter(objectMapper),
//                                     UsernamePasswordAuthenticationFilter.class);
        // 关闭csrf
        httpSecurity.csrf(AbstractHttpConfigurer::disable);
        return httpSecurity.build();
    }

    @Bean
    public UsernamePasswordAuthenticationFilter magnusUsernamePasswordFilter(ObjectMapper objectMapper) {
   
   
        // 配置自定义的UsernamePasswordAuthenticationFilter
        MagnusUsernamePasswordFilter magnusUsernamePasswordFilter = new MagnusUsernamePasswordFilter();
        magnusUsernamePasswordFilter.setAuthenticationManager(providerManager());
        magnusUsernamePasswordFilter.setObjectMapper(objectMapper);
        magnusUsernamePasswordFilter.initialize();
        return magnusUsernamePasswordFilter;
    }

    @Bean
    public UserDetailsService userDetailsService() {
   
   
        UserDetails build = User.withUsername("username").password("{noop}password").roles("user").build();
        return new InMemoryUserDetailsManager(build);
    }

    @Bean
    public AuthenticationManager providerManager() {
   
   
        List<AuthenticationProvider> providers = new ArrayList<>();
        // 自定义Provider,此处可以定义多数据源。
        DaoAuthenticationProvider provider = new DaoAuthenticationProvider();
        provider.setUserDetailsService(userDetailsSe
评论 1
成就一亿技术人!
拼手气红包6.0元
还能输入1000个字符
 
红包 添加红包
表情包 插入表情
 条评论被折叠 查看
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值