package com.kucun;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.boot.web.servlet.support.SpringBootServletInitializer;
@SpringBootApplication(
)
public class DemoApplication extends SpringBootServletInitializer {
public static void main(String[] args) {
//
// ConfigurableApplicationContext ctx = SpringApplication.run(Application.class, args);
// Arrays.stream(ctx.getBeanNamesForType(SecurityFilterChain.class))
// .forEach(System.out::println);
//
//
// // 测试密码加密示例
// BCryptPasswordEncoder encoder = new BCrypt();
// String rawPassword = "987987";
// String encodedPassword = encoder.encode(rawPassword);
// System.out.println("加密后的密码:" + encodedPassword);
SpringApplication.run(DemoApplication.class, args);
}
}<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<groupId>KuCun2</groupId>
<artifactId>KuCun2</artifactId>
<version>0.0.1-SNAPSHOT</version>
<packaging>war</packaging>
<name>KuCun2</name>
<description/>
<parent>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-parent</artifactId>
<version>2.3.12.RELEASE</version> <!-- 请根据需要选择版本 -->
<relativePath/> <!-- lookup parent from repository -->
</parent>
<properties>
<webVersion>4.0</webVersion>
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
<protobuf.version>3.21.12</protobuf.version>
</properties>
<dependencies>
<dependency>
<groupId>javax</groupId>
<artifactId>javaee-api</artifactId>
<version>8.0</version>
<scope>provided</scope>
</dependency>
<dependency>
<groupId>org.glassfish.web</groupId>
<artifactId>javax.servlet.jsp.jstl</artifactId>
<version>1.2.4</version>
</dependency>
<!-- Spring Boot Starter Data JPA -->
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-data-jpa</artifactId>
</dependency>
<!-- MySQL Connector -->
<dependency>
<groupId>mysql</groupId>
<artifactId>mysql-connector-java</artifactId>
<version>8.0.33</version>
<exclusions>
<exclusion>
<groupId>com.google.protobuf</groupId>
<artifactId>protobuf-java</artifactId>
</exclusion>
</exclusions>
</dependency>
<!-- Optional: Lombok for reducing boilerplate code -->
<dependency>
<groupId>org.projectlombok</groupId>
<artifactId>lombok</artifactId>
<optional>true</optional>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-web</artifactId>
<exclusions>
<exclusion>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-security</artifactId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-webmvc</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-web</artifactId>
<exclusions>
<exclusion>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-tomcat</artifactId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-tomcat</artifactId>
<scope>provided</scope>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-web</artifactId>
<exclusions>
<exclusion>
<groupId>com.fasterxml.jackson.datatype</groupId>
<artifactId>jackson-datatype-jsr310</artifactId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>com.fasterxml.jackson.datatype</groupId>
<artifactId>jackson-datatype-jsr310</artifactId>
</dependency>
<!-- Jackson Databind -->
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
</dependency>
<!-- Jackson Core -->
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-core</artifactId>
</dependency>
<!-- Jackson Annotations -->
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-annotations</artifactId>
</dependency>
<dependency>
<groupId>org.mindrot</groupId>
<artifactId>jbcrypt</artifactId>
<version>0.4</version>
</dependency>
<dependency>
<groupId>com.google.protobuf</groupId>
<artifactId>protobuf-java</artifactId>
<version>${protobuf.version}</version>
</dependency>
<dependency>
<groupId>org.yaml</groupId>
<artifactId>snakeyaml</artifactId>
<version>1.30</version> <!-- 统一版本号 -->
</dependency>
</dependencies>
<build>
<plugins>
<plugin>
<artifactId>maven-compiler-plugin</artifactId>
<version>2.3.2</version>
<configuration>
<source>1.8</source>
<target>1.8</target>
<compilerArgs>
<arg>-parameters</arg>
</compilerArgs>
</configuration>
</plugin>
<plugin>
<artifactId>maven-war-plugin</artifactId>
<version>2.6</version>
<configuration>
<failOnMissingWebXml>false</failOnMissingWebXml>
</configuration>
</plugin>
</plugins>
</build>
</project> package com.kucun.Config.user;
import java.util.Collection;
import com.kucun.data.entity.User;
public class CustomUserDetails /*implements UserDetails*/ {
// /**
// *
// */
// private static final long serialVersionUID = 1L;
// private final String andy; // 对应andy字段
// private final String name;
// private final int role;
// private final String password;
// private final User users;
// private final Collection<? extends GrantedAuthority> authorities;
//
// public CustomUserDetails(User user, Collection<? extends GrantedAuthority> authorities) {
// this.andy = user.getAndy();
// this.name = user.getName();
// this.role = user.getRole();
// this.password = user.getPass();
// user.setPass(null);
// this.users=user;
// this.authorities = authorities;
// }
//
// // 实现UserDetails接口方法
// @Override public String getUsername() { return andy; }
// @Override public String getPassword() { return password; }
// @Override public Collection<? extends GrantedAuthority> getAuthorities() { return authorities; }
//
// // 自定义字段访问方法
// public String getName() { return name; }
// public User getUser() { return users; }
// public int getRole() { return role; }
//
// // 其他必要方法
// @Override public boolean isAccountNonExpired() { return true; }
// @Override public boolean isAccountNonLocked() { return true; }
// @Override public boolean isCredentialsNonExpired() { return true; }
// @Override public boolean isEnabled() { return true; }
}package com.kucun.Config.Role;
import java.util.Collections;
import java.util.HashMap;
import java.util.List;
import java.util.Map;
import javax.annotation.PostConstruct;
import javax.json.Json;
import org.springframework.stereotype.Component;
import com.fasterxml.jackson.core.JsonProcessingException;
import com.fasterxml.jackson.databind.ObjectMapper;
/**
* 权限转化
* @author Administrator
*
*/
@Component
public class RoleConverter {
// private static final Map<Integer, String> ROLE_MAP = new HashMap<>();
//
// @PostConstruct
// public void init() {
// ROLE_MAP.put(0, "ROLE_ADMIN");
// ROLE_MAP.put(1, "ROLE_USER");
// ROLE_MAP.put(2, "ROLE_MANAGER");
// ROLE_MAP.put(3, "ROLE_AUDITOR");
// }
//
// public List<GrantedAuthority> convert(int roleCode) {
// ObjectMapper mapper = new ObjectMapper();
// try {
// System.out.println(mapper.writeValueAsString(Collections.singletonList(
// new SimpleGrantedAuthority(ROLE_MAP.getOrDefault(roleCode, "ROLE_GUEST")))).toString());//输出[{"authority":"ROLE_ADMIN"}]
// } catch (JsonProcessingException e) {
// // TODO Auto-generated catch block
// e.printStackTrace();
// }
//
// return Collections.singletonList(
// new SimpleGrantedAuthority(ROLE_MAP.getOrDefault(roleCode, "ROLE_GUEST"))
// );
// }
//
}package com.kucun.Config;
// 2. 基础安全配置
//@Configuration
//@EnableWebSecurity // 启用Web安全功能
public class SecurityConfig
//extends WebSecurityConfigurerAdapter
{
// @Override
// public void configure(WebSecurity web) {
// web.ignoring().antMatchers("/check-session");
// }
// // 添加自定义Controller
// @RestController
// public static class SessionCheckController {
// @GetMapping("/check-session")
// public ResponseEntity<?> checkSession(HttpServletRequest request) {
// return request.getSession(false) != null ?
// ResponseEntity.ok().build() :
// ResponseEntity.status(HttpStatus.UNAUTHORIZED).build();
// }
// }
// /**
// * 核心安全过滤器链配置
// * @param http HTTP安全构建器
// * @return 安全过滤器链
// * @throws Exception 配置异常
// *
// * █ 配置逻辑说明:
// * 1. authorizeHttpRequests: 定义访问控制规则
// * 2. formLogin: 配置表单登录
// * 3. logout: 配置注销行为
// * 4. exceptionHandling: 处理权限异常[^3]
// */
//
// // 修正后的配置方法
// @Override
// protected void configure(HttpSecurity http) throws Exception {
//
//
//
// http
// .csrf().disable()
// .sessionManagement()
// .sessionCreationPolicy(SessionCreationPolicy.ALWAYS)
// .invalidSessionUrl("/login.html?session=invalid")
// .maximumSessions(1)
// .maxSessionsPreventsLogin(false)
// .and()
// .and()
// .addFilterBefore(jsonAuthFilter(), UsernamePasswordAuthenticationFilter.class) // 关键配置
// .authorizeRequests()
// .antMatchers("/login.html", "/users/login").permitAll()
// .antMatchers("/js/**", "/css/**", "/fonts/**", "/images/**","/check-session","/main/bootstrap-3.3.7-dist/**").permitAll()
// .antMatchers("/users/guanli/**").hasAuthority("ROLE_ADMIN")
// .anyRequest().authenticated()
// .and()
// .formLogin().disable()
//// .loginPage("/login.html")
//// .loginProcessingUrl("/users/login")
////
//// .successHandler(ajaxAuthenticationSuccessHandler()) // 自定义成功处理器
//// .failureHandler(ajaxAuthenticationFailureHandler()) // 自定义失败处理器
//// .defaultSuccessUrl("/index.html")
//// .failureUrl("/login.html?error=true")
//// .usernameParameter("andy") // 修改用户名参数名
//// .passwordParameter("pass") // 修改密码参数名
//// .and()
//
// .logout()
// .logoutUrl("/logout")
// .logoutSuccessUrl("/login.html")
// .and()
// .csrf()
// .ignoringAntMatchers("/users/login")
// .and()
// .headers()
// .frameOptions().sameOrigin()
// .and()
// .exceptionHandling()
// .accessDeniedHandler(accessDeniedHandler()); // 统一使用Handler
// }
//
//
//
//
//
// // 返回JSON格式的成功响应
// @Bean
// public AuthenticationSuccessHandler ajaxAuthenticationSuccessHandler() {
// return (request, response, authentication) -> {
//
//
//
// // 强制创建服务端会话
// request.getSession(true);
//
//
//
//
// String contextPath = request.getContextPath();
// HttpSession session = request.getSession(true);
// Cookie cookie = new Cookie("JSESSIONID", session.getId());
// cookie.setPath(contextPath.isEmpty() ? "/" : contextPath + "/");
// cookie.setMaxAge(1800); // 30分钟
// response.addCookie(cookie);
//
//
// //构建安全响应数据
// Map<String, Object> responseData = new HashMap<>();
// responseData.put("sessionId", request.getSession().getId());
// responseData.put("userInfo",Collections.unmodifiableMap(new HashMap<String, Object>() {/**
// *
// */
// private static final long serialVersionUID = 1L;
//
// {
// put("Name", ((CustomUserDetails)authentication.getPrincipal()).getName());
// put("role", ((CustomUserDetails)authentication.getPrincipal()).getRole());
// }}));
//
//
//
// // 统一返回JSON格式
// response.setContentType(MediaType.APPLICATION_JSON_VALUE);
// // new ObjectMapper().writeValue(response.getWriter(), responseData);
//
//
//
//
//
//
//
//
//
// response.setContentType(MediaType.APPLICATION_JSON_VALUE);
// CustomUserDetails userDetails = (CustomUserDetails) authentication.getPrincipal();
//
// response.setStatus(HttpStatus.OK.value());
// System.out.println(authentication.getPrincipal()+""+authentication.getName());
//
// if (request.getHeader("X-Requested-With") == null) { // 非AJAX请求
// response.sendRedirect("/index.html");
// } else {
//
// //String re=userDetails.getUser().toString()
// new ObjectMapper().writeValue(response.getWriter(), userDetails.getUser()
// );
//
// }
//
//
//
//
//
//
// };
// }
//
// // 返回401状态码和错误信息
// @Bean
// public AuthenticationFailureHandler ajaxAuthenticationFailureHandler() {
// return (request, response, exception) -> {
// if (request.getHeader("X-Requested-With") == null) {
// response.sendRedirect("/login.html?error=true");
// } else {
// response.setStatus(HttpStatus.UNAUTHORIZED.value());
// response.getWriter().write("{\"error\":\"Authentication failed\"}");
// }
// };
// }
//
// // 处理未认证请求
// @Bean
// public AuthenticationEntryPoint ajaxAuthenticationEntryPoint() {
// return (request, response, exception) -> {
// if (request.getHeader("X-Requested-With") == null) {
// response.sendRedirect("/login.html?error=true");
// } else {
// response.setStatus(HttpStatus.UNAUTHORIZED.value());
// response.getWriter().write("{\"error\":\"Authentication failed\"}");
// }
// };
// }
//
//
//
//
//
// @Bean
// public JsonUsernamePasswordAuthenticationFilter jsonAuthFilter() throws Exception {
//
// JsonUsernamePasswordAuthenticationFilter filter =
// new JsonUsernamePasswordAuthenticationFilter();
// filter.setAuthenticationManager(authenticationManagerBean());
// filter.setUsernameParameter("andy"); // 设置自定义参数名
// filter.setPasswordParameter("pass");
// filter.setFilterProcessesUrl("/users/login");
// filter.setAuthenticationSuccessHandler(ajaxAuthenticationSuccessHandler());
// filter.setAuthenticationFailureHandler(ajaxAuthenticationFailureHandler());
//
// return filter;
// }
//
//
// /**
// * 密码编码器(必须配置)
// * 使用BCrypt强哈希算法加密
// */
// @Bean
// public PasswordEncoder passwordEncoder() {
// return new BCryptPasswordEncoder();
// }
//
//
// @Bean
// public AccessDeniedHandler accessDeniedHandler() {
// System.out.println("0000");
// return (request, response, ex) -> {
// if (!response.isCommitted()) {
// response.sendRedirect("/error/403");
// }
// };
// }
//
//
//}
//
//
//
//
//
//
//class JsonUsernamePasswordAuthenticationFilter extends UsernamePasswordAuthenticationFilter {
// private final ObjectMapper objectMapper = new ObjectMapper();
//
// @Override
// public Authentication attemptAuthentication(HttpServletRequest request,
// HttpServletResponse response)
// throws AuthenticationException {
// System.out.println("收到认证请求,路径:" + request.getRequestURI());
// System.out.println("请求方法:" + request.getMethod());
// System.out.println("Content-Type:" + request.getContentType());
// if (request.getContentType() != null &&
// request.getContentType().startsWith(MediaType.APPLICATION_JSON_VALUE)) {
//
// try (InputStream is = request.getInputStream()) {
// Map<String, String> authMap = objectMapper.readValue(is, Map.class);
//
// String username = authMap.getOrDefault(getUsernameParameter(), "");
// String password = authMap.getOrDefault(getPasswordParameter(), "");
//
// // 调试日志
// System.out.println("Authentication attempt with: " + username+'_'+ password);
//
// UsernamePasswordAuthenticationToken authRequest =
// new UsernamePasswordAuthenticationToken(username, password);
//
// setDetails(request, authRequest);
// return this.getAuthenticationManager().authenticate(authRequest);
// } catch (IOException e) {
// throw new AuthenticationServiceException("认证请求解析失败", e);
// }
// }
// Authentication aut= super.attemptAuthentication(request, response);
// System.out.println("结果:"+aut.isAuthenticated());
//
// return aut;
// }
}
package com.kucun.Config;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Service;
import com.kucun.Config.Role.RoleConverter;
import com.kucun.Config.user.CustomUserDetails;
import com.kucun.data.entity.User;
import com.kucun.dataDo.UserRepository;
/**
* 获取数据
* @author Administrator
*
*/
@Service
public class CustomUserDetailsService/* implements UserDetailsService */{
//
// @Autowired
// private UserRepository userRepository;
//
// @Autowired
// private RoleConverter roleConverter;
//
// public CustomUserDetailsService() {
//
// super();
// System.out.println("11111");
// }
///**
// * 获取数据库中用户信息
// * @param andy 账号
// *
// * @return
// *
// */
// @Override
// public UserDetails loadUserByUsername(String andy) {
// System.out.println(andy);
// User user = userRepository.findByAndy(andy);
// System.out.println(user);
// return new CustomUserDetails(user,
// roleConverter.convert(user.getRole()) // 关键转换点[^1]
// );
// }
}
不加安全类的情况下解决重定向问题
}