Springboot-14 shiro整合mybati 密码可以用md5盐值加密 更加安全 授权认证登录

本文详细介绍了如何在Spring Boot项目中使用Apache Shiro进行权限管理,包括配置ShiroFilterFactoryBean,自定义UserRealm实现认证与授权,以及整合Thymeleaf实现登录用户显示。

导入pom.xml

<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
         xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
    <modelVersion>4.0.0</modelVersion>
    <parent>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-parent</artifactId>
        <version>2.3.3.RELEASE</version>
        <relativePath/> <!-- lookup parent from repository -->
    </parent>
    <groupId>com.xuyuan</groupId>
    <artifactId>shiro-springboot</artifactId>
    <version>0.0.1-SNAPSHOT</version>
    <name>shiro-springboot</name>
    <description>Demo project for Spring Boot</description>

    <properties>
        <java.version>1.8</java.version>
    </properties>

    <dependencies>
        <!-- https://mvnrepository.com/artifact/org.apache.shiro/shiro-spring -->
        <dependency>
            <groupId>org.apache.shiro</groupId>
            <artifactId>shiro-spring</artifactId>
            <version>1.6.0</version>
        </dependency>
        <dependency>
            <groupId>mysql</groupId>
            <artifactId>mysql-connector-java</artifactId>
        </dependency>
        <dependency>
            <groupId>log4j</groupId>
            <artifactId>log4j</artifactId>
            <version>1.2.17</version>
        </dependency>
        <dependency>
            <groupId>com.alibaba</groupId>
            <artifactId>druid</artifactId>
            <version>1.1.23</version>
        </dependency>
        <dependency>
            <groupId>org.mybatis.spring.boot</groupId>
            <artifactId>mybatis-spring-boot-starter</artifactId>
            <version>2.1.3</version>
        </dependency>
        <dependency>
            <groupId>org.projectlombok</groupId>
            <artifactId>lombok</artifactId>
            <version>1.18.12</version>
        </dependency>
        <dependency>
            <groupId>org.thymeleaf</groupId>
            <artifactId>thymeleaf-spring5</artifactId>
        </dependency>
        <dependency>
            <groupId>org.thymeleaf.extras</groupId>
            <artifactId>thymeleaf-extras-java8time</artifactId>
        </dependency>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-web</artifactId>
        </dependency>

        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-test</artifactId>
            <scope>test</scope>
            <exclusions>
                <exclusion>
                    <groupId>org.junit.vintage</groupId>
                    <artifactId>junit-vintage-engine</artifactId>
                </exclusion>
            </exclusions>
        </dependency>
    </dependencies>

    <build>
        <plugins>
            <plugin>
                <groupId>org.springframework.boot</groupId>
                <artifactId>spring-boot-maven-plugin</artifactId>
            </plugin>
        </plugins>
    </build>

</project>

创建application.yaml

spring:
  datasource:
    username: root
    password: 123
    url: jdbc:mysql://localhost:3306/mybatis?serverTimezone=GMT%2B8&characterEncoding=utf-8&useUnicode=true&
    driver-class-name: com.mysql.cj.jdbc.Driver
      #Spring Boot 默认是不注入这些属性值的,需要自己绑定
      #druid 数据源专有配置

application.properties

mybatis.type-aliases-package=com.xuyuan.pojo
mybatis.mapper-locations=classpath:mapper/*.xml

创建pojo

package com.xuyuan.pojo;

import lombok.AllArgsConstructor;
import lombok.Data;
import lombok.NoArgsConstructor;

@Data
@AllArgsConstructor
@NoArgsConstructor
public class User {
    private int id;
    private String name;
    private String pwd;
}

mapper接口:

package com.xuyuan.mapper;

import com.xuyuan.pojo.User;
import org.apache.ibatis.annotations.Mapper;
import org.mybatis.spring.annotation.MapperScan;
import org.springframework.stereotype.Repository;

@Repository
@Mapper
public interface UserMapper {
    public User queryByName(String name);

}

service业务

package com.xuyuan.service;

import com.xuyuan.pojo.User;

public interface UserService {
    public User queryByName(String name);
}

实现类

package com.xuyuan.service;

import com.xuyuan.mapper.UserMapper;
import com.xuyuan.pojo.User;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Repository;
import org.springframework.stereotype.Service;

@Service
public class UserServiceImpl implements UserService {
    @Autowired
     UserMapper userMapper;
    @Override
    public User queryByName(String name) {
        return userMapper.queryByName(name);
    }
}

controller

package com.xuyuan.Controller;

import org.apache.catalina.security.SecurityUtil;
import org.apache.shiro.SecurityUtils;
import org.apache.shiro.authc.IncorrectCredentialsException;
import org.apache.shiro.authc.UnknownAccountException;
import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.subject.Subject;
import org.springframework.stereotype.Controller;
import org.springframework.ui.Model;
import org.springframework.web.bind.annotation.RequestMapping;

@Controller
public class indexcontroller {
    @RequestMapping({"/","/index"})
   public String indexC(Model model){
       model.addAttribute("msg","helloShiro");
       return "index";
   }
   @RequestMapping("/user/add")
   public  String add(){
        return "user/add";
   }
    @RequestMapping("/user/updata")
    public  String updata(){
        return "user/updata";
    }
    @RequestMapping("/tologin")
    public String tologin(){
        return "login";
    }
    @RequestMapping("/login")
    public String login(String username,String password,Model model){
//获取当前用户
        Subject subject = SecurityUtils.getSubject();
        UsernamePasswordToken token = new UsernamePasswordToken(username, password);
        try{
            subject.login(token);//执行登录方法 如果有异常就不行了
            return "index";
        }catch (UnknownAccountException e){
            //用户名不存在
            model.addAttribute("msg","用户名错误");
            return "login";
        }catch (IncorrectCredentialsException e){//密码错误
            model.addAttribute("msg","密码错误");
            return "login";
        }

    }
}

先在test中测试

package com.xuyuan;

import com.xuyuan.service.UserServiceImpl;
import org.junit.jupiter.api.Test;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.test.context.SpringBootTest;

@SpringBootTest
class ShiroSpringbootApplicationTests {
    @Autowired
UserServiceImpl userService;


    @Test
    void contextLoads() {
        System.out.println(userService.queryByName("徐源"));


    }

}

在这里插入图片描述改变UserRealm 删除之间伪造的 用数据库
config目录下

package com.xuyuan.config;

import com.xuyuan.pojo.User;
import com.xuyuan.service.UserService;
import org.apache.shiro.authc.*;
import org.apache.shiro.authz.AuthorizationInfo;
import org.apache.shiro.realm.AuthorizingRealm;
import org.apache.shiro.subject.PrincipalCollection;
import org.springframework.beans.factory.annotation.Autowired;
//自定义 UserRealm    extends AuthorizingRealm

public class UserRealm extends AuthorizingRealm {
    @Autowired
    UserService userService;
    //授权
    @Override
    protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principalCollection) {
        System.out.println("执行授权了=》doGetAuthorizationInfo");
        return null;
    }
//认证
    @Override
    protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken token) throws AuthenticationException {
        System.out.println("执行授权了=》doGetAuthenticationInfo");
     //连接真实数据库

        UsernamePasswordToken usertoken = (UsernamePasswordToken) token;
        User user = userService.queryByName(usertoken.getUsername());
       if (user==null){//没有这个人
           return null;

       }
//密码认证 shior做

        return new SimpleAuthenticationInfo("",user.getPwd(),"");
    }
}

ShoroConfig

package com.xuyuan.config;
import org.apache.shiro.spring.web.ShiroFilterFactoryBean;
import org.apache.shiro.web.mgt.DefaultWebSecurityManager;
import org.springframework.beans.factory.annotation.Qualifier;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.bind.annotation.PathVariable;

import java.util.LinkedHashMap;
import java.util.Map;

@Configuration
public class ShoroConfig {
    @Bean
//    ShiroFilterFactoryBean:3
    public ShiroFilterFactoryBean getShiroFilterFactoryBean(@Qualifier("SecurityManager") DefaultWebSecurityManager defaultWebSecurityManager){
        ShiroFilterFactoryBean bean = new ShiroFilterFactoryBean();
        bean.setSecurityManager(defaultWebSecurityManager);
        /*
        *anno:无需认证就可以访问
        *authc: 必须认证了才能访问
        * user:必须拥有记住我 功能才能访问
        * perms:拥有对某个资源的权限才能访问
        * role:拥有某个角色权限才能访问
        * */
        Map<String, String> Filtermap = new LinkedHashMap<>();
        Filtermap.put("/user/*","authc");
        bean.setFilterChainDefinitionMap(Filtermap);
//设置登录请求
        bean.setLoginUrl("/tologin");

        return bean;
    }
@Bean(name="SecurityManager")
//DefaultwebSecurityManager:2
public DefaultWebSecurityManager getDefaultWebSecurityManager(@Qualifier("userRealm") UserRealm userRealm){
    DefaultWebSecurityManager manager = new DefaultWebSecurityManager();
    manager.setRealm(userRealm);
    return manager;
}
//创建  realm 对象 ,需要自定义类:1
    @Bean
    public  UserRealm userRealm(){return  new UserRealm();}
}

测试:
在这里插入图片描述
成功

在这里插入图片描述

**授权**

在shoroconfig下

package com.xuyuan.config;

import org.apache.shiro.spring.web.ShiroFilterFactoryBean;
import org.apache.shiro.web.mgt.DefaultWebSecurityManager;
import org.springframework.beans.factory.annotation.Qualifier;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.bind.annotation.PathVariable;

import java.util.LinkedHashMap;
import java.util.Map;

@Configuration
public class ShoroConfig {
    @Bean
//    ShiroFilterFactoryBean:3
    public ShiroFilterFactoryBean getShiroFilterFactoryBean(@Qualifier("SecurityManager") DefaultWebSecurityManager defaultWebSecurityManager){
        ShiroFilterFactoryBean bean = new ShiroFilterFactoryBean();
        bean.setSecurityManager(defaultWebSecurityManager);
        /*
        *anno:无需认证就可以访问
        *authc: 必须认证了才能访问
        * user:必须拥有记住我 功能才能访问
        * perms:拥有对某个资源的权限才能访问
        * role:拥有某个角色权限才能访问
        * */
        Map<String, String> Filtermap = new LinkedHashMap<>();
        //授权,正常那个情况下,没有授权会跳到未授权的页面
        Filtermap.put("/user/add","perms[user:add]");
        Filtermap.put("/user/*","authc");

        bean.setFilterChainDefinitionMap(Filtermap);
//设置登录请求
        bean.setLoginUrl("/tologin");

        return bean;
    }
@Bean(name="SecurityManager")
//DefaultwebSecurityManager:2
public DefaultWebSecurityManager getDefaultWebSecurityManager(@Qualifier("userRealm") UserRealm userRealm){
    DefaultWebSecurityManager manager = new DefaultWebSecurityManager();
    manager.setRealm(userRealm);
    return manager;
}
//创建  realm 对象 ,需要自定义类:1
    @Bean
    public  UserRealm userRealm(){return  new UserRealm();}
}

在这里插入图片描述未授权add页面**

写一个跳转页面
controller

  @RequestMapping("/noauth")
    @ResponseBody
    public  String unauthorized(){
        return "未经授权页面";
    }

shoroconfig

   bean.setLoginUrl("/tologin");
    //未授权页面
    bean.setUnauthorizedUrl("/noauth");

在这里插入图片描述
给他授权
在ShoroConfig中写授权的权限

package com.xuyuan.config;

import org.apache.shiro.spring.web.ShiroFilterFactoryBean;
import org.apache.shiro.web.mgt.DefaultWebSecurityManager;
import org.springframework.beans.factory.annotation.Qualifier;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.bind.annotation.PathVariable;

import java.util.LinkedHashMap;
import java.util.Map;

@Configuration
public class ShoroConfig {
    @Bean
//    ShiroFilterFactoryBean:3
    public ShiroFilterFactoryBean getShiroFilterFactoryBean(@Qualifier("SecurityManager") DefaultWebSecurityManager defaultWebSecurityManager){
        ShiroFilterFactoryBean bean = new ShiroFilterFactoryBean();
        bean.setSecurityManager(defaultWebSecurityManager);
        /*
        *anno:无需认证就可以访问
        *authc: 必须认证了才能访问
        * user:必须拥有记住我 功能才能访问
        * perms:拥有对某个资源的权限才能访问
        * role:拥有某个角色权限才能访问
        * */
        Map<String, String> Filtermap = new LinkedHashMap<>();
        //授权,正常那个情况下,没有授权会跳到未授权的页面
        Filtermap.put("/user/add","perms[user:add]");
        Filtermap.put("/user/updata","perms[user:updata]");
        Filtermap.put("/user/*","authc");

        bean.setFilterChainDefinitionMap(Filtermap);
//设置登录请求
        bean.setLoginUrl("/tologin");
        //未授权页面
        bean.setUnauthorizedUrl("/noauth");

        return bean;
    }
@Bean(name="SecurityManager")
//DefaultwebSecurityManager:2
public DefaultWebSecurityManager getDefaultWebSecurityManager(@Qualifier("userRealm") UserRealm userRealm){
    DefaultWebSecurityManager manager = new DefaultWebSecurityManager();
    manager.setRealm(userRealm);
    return manager;
}
//创建  realm 对象 ,需要自定义类:1
    @Bean
    public  UserRealm userRealm(){return  new UserRealm();}
}

在UserRealm中授权

package com.xuyuan.config;

import com.xuyuan.pojo.User;
import com.xuyuan.service.UserService;
import org.apache.catalina.security.SecurityUtil;
import org.apache.shiro.SecurityUtils;
import org.apache.shiro.authc.*;
import org.apache.shiro.authz.AuthorizationInfo;
import org.apache.shiro.authz.SimpleAuthorizationInfo;
import org.apache.shiro.realm.AuthorizingRealm;
import org.apache.shiro.subject.PrincipalCollection;
import org.apache.shiro.subject.Subject;
import org.springframework.beans.factory.annotation.Autowired;
//自定义 UserRealm    extends AuthorizingRealm

public class UserRealm extends AuthorizingRealm {
    @Autowired
    UserService userService;
    //授权
    @Override
    protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principalCollection) {
        System.out.println("执行授权了=》doGetAuthorizationInfo");
        SimpleAuthorizationInfo info = new SimpleAuthorizationInfo();
        info.addStringPermission("user:add");
        //拿到当前登录的对象
        Subject subject = SecurityUtils.getSubject();
        User currentUser = (User) subject.getPrincipal();//拿到user对象
//        设置当前用户的权限
       info.addStringPermission(currentUser.getName());//数据库中读出来的
        return info;
    }
//认证
    @Override
    protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken token) throws AuthenticationException {
        System.out.println("执行授权了=》doGetAuthenticationInfo");
     //连接真实数据库

        UsernamePasswordToken usertoken = (UsernamePasswordToken) token;
        User user = userService.queryByName(usertoken.getUsername());
       if (user==null){//没有这个人
           return null;

       }
//密码认证 shior做

        return new SimpleAuthenticationInfo(user,user.getPwd(),"");
    }
}

在数据库中添加字段在这里插入图片描述记得在pojo中添加perms
数据库
在这里插入图片描述成功
在这里插入图片描述在这里插入图片描述在这里插入图片描述
shiro和thymelesf整合实现谁等陆显示谁
导入pom.xml

 <dependency>
            <groupId>com.github.theborakompanioni</groupId>
            <artifactId>thymeleaf-extras-shiro</artifactId>
            <version>2.0.0</version>
        </dependency>

index

<!DOCTYPE html>
<html lang="en"  xmlns:th="http://www.thymeleaf.org"
      xmlns:shiro="http://www.thymeleaf.org/thymeleaf-extras-shiro">
<head>
    <meta charset="UTF-8">
    <title>Title</title>
</head>
<body>
<h1>首页</h1>
<div th:if="${session.loginUser==null}">
    <a th:href="@{/tologin}">登录</a>
</div>
<p th:text="${msg}"></p>
<hr>
<div shiro:hasPermission="user:add">
<a th:href="@{/user/add}">增加</a>
</div>
<div shiro:hasPermission="user:updata">
<a th:href="@{/user/updata}">是修改</a>
</div>
</body>
</html>

UserRealm 认证 去掉登录按钮

package com.xuyuan.config;

import com.xuyuan.pojo.User;
import com.xuyuan.service.UserService;
import org.apache.catalina.security.SecurityUtil;
import org.apache.shiro.SecurityUtils;
import org.apache.shiro.authc.*;
import org.apache.shiro.authz.AuthorizationInfo;
import org.apache.shiro.authz.SimpleAuthorizationInfo;
import org.apache.shiro.realm.AuthorizingRealm;
import org.apache.shiro.session.Session;
import org.apache.shiro.subject.PrincipalCollection;
import org.apache.shiro.subject.Subject;
import org.springframework.beans.factory.annotation.Autowired;
//自定义 UserRealm    extends AuthorizingRealm

public class UserRealm extends AuthorizingRealm {
    @Autowired
    UserService userService;
    //授权
    @Override
    protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principalCollection) {
        System.out.println("执行授权了=》doGetAuthorizationInfo");
        SimpleAuthorizationInfo info = new SimpleAuthorizationInfo();
        info.addStringPermission("user:add");
        //拿到当前登录的对象
        Subject subject = SecurityUtils.getSubject();
        User currentUser = (User) subject.getPrincipal();//拿到user对象
//        设置当前用户的权限
       info.addStringPermission(currentUser.getName());//数据库中读出来的
        return info;
    }
//认证
    @Override
    protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken token) throws AuthenticationException {
        System.out.println("执行授权了=》doGetAuthenticationInfo");
     //连接真实数据库

        UsernamePasswordToken usertoken = (UsernamePasswordToken) token;
        User user = userService.queryByName(usertoken.getUsername());
       if (user==null){//没有这个人
           return null;
       }
//密码认证 shior做
        Subject subject = SecurityUtils.getSubject();
        Session session = subject.getSession();
        session.setAttribute("loginUser",user);

        return new SimpleAuthenticationInfo(user,user.getPwd(),"");
    }
}

ShoroConfig整合

package com.xuyuan.config;

import at.pollux.thymeleaf.shiro.dialect.ShiroDialect;
import org.apache.shiro.spring.web.ShiroFilterFactoryBean;
import org.apache.shiro.web.mgt.DefaultWebSecurityManager;
import org.springframework.beans.factory.annotation.Qualifier;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.bind.annotation.PathVariable;

import java.util.LinkedHashMap;
import java.util.Map;

@Configuration
public class ShoroConfig {
    @Bean
//    ShiroFilterFactoryBean:3
    public ShiroFilterFactoryBean getShiroFilterFactoryBean(@Qualifier("SecurityManager") DefaultWebSecurityManager defaultWebSecurityManager){
        ShiroFilterFactoryBean bean = new ShiroFilterFactoryBean();
        bean.setSecurityManager(defaultWebSecurityManager);
        /*
        *anno:无需认证就可以访问
        *authc: 必须认证了才能访问
        * user:必须拥有记住我 功能才能访问
        * perms:拥有对某个资源的权限才能访问
        * role:拥有某个角色权限才能访问
        * */
        Map<String, String> Filtermap = new LinkedHashMap<>();
        //授权,正常那个情况下,没有授权会跳到未授权的页面
        Filtermap.put("/user/add","perms[user:add]");
        Filtermap.put("/user/updata","perms[user:updata]");
        Filtermap.put("/user/*","authc");

        bean.setFilterChainDefinitionMap(Filtermap);
//设置登录请求
        bean.setLoginUrl("/tologin");
        //未授权页面
        bean.setUnauthorizedUrl("/noauth");

        return bean;
    }
@Bean(name="SecurityManager")
//DefaultwebSecurityManager:2
public DefaultWebSecurityManager getDefaultWebSecurityManager(@Qualifier("userRealm") UserRealm userRealm){
    DefaultWebSecurityManager manager = new DefaultWebSecurityManager();
    manager.setRealm(userRealm);
    return manager;
}
//创建  realm 对象 ,需要自定义类:1
    @Bean
    public  UserRealm userRealm(){return  new UserRealm();
    }
    //整合Shiro和thymeleaf  shiroDialect
    @Bean
    public ShiroDialect getshiroDialect(){

        return  new ShiroDialect();
    }
}

在这里插入图片描述

评论 2
成就一亿技术人!
拼手气红包6.0元
还能输入1000个字符
 
红包 添加红包
表情包 插入表情
 条评论被折叠 查看
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值