package com.nuzar.cloud.saas.service;
import cn.hutool.crypto.SmUtil;
import cn.hutool.crypto.asymmetric.KeyType;
import cn.hutool.crypto.asymmetric.SM2;
import cn.hutool.json.JSONUtil;
import com.baomidou.mybatisplus.core.toolkit.IdWorker;
import com.fasterxml.jackson.core.JsonProcessingException;
import com.fasterxml.jackson.databind.ObjectMapper;
import com.nuzar.cloud.common.utils.StringUtils;
import com.nuzar.cloud.saas.common.authorization.property.SecurityPostModelProperties;
import org.apache.commons.lang3.RandomStringUtils;
import org.bouncycastle.crypto.engines.SM2Engine;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import org.springframework.beans.factory.InitializingBean;
import org.springframework.beans.factory.SmartInitializingSingleton;
import org.springframework.data.redis.core.RedisTemplate;
import org.springframework.stereotype.Component;
import javax.annotation.Resource;
import java.time.Duration;
import java.util.Objects;
/**
* 处理请求model的数据进行加解密处理
*/
@Component
public class SecurityPostModelService implements SmartInitializingSingleton {
private static final Logger logger = LoggerFactory.getLogger(SecurityPostModelService.class);
private SecurityPostModelProperties securityPostModelProperties;
private SM2 sm2 ;
private ObjectMapper objectMapper;
private final String PREFIX = "saas:security:post-model-verifysign:";
private RedisTemplate redisTemplate;
public SecurityPostModelService(SecurityPostModelProperties securityPostModelProperties,
ObjectMapper objectMapper,
RedisTemplate redisTemplate){
this.securityPostModelProperties = securityPostModelProperties;
this.objectMapper = objectMapper;
this.redisTemplate = redisTemplate;
}
/**
* 是否启用安全提交数据模型对象的解密处理
* @return
*/
public Boolean isEnabled(){
return Objects.nonNull(this.securityPostModelProperties) && this.securityPostModelProperties.getEnabled();
}
/**
*
* @param encryptedHex 公钥加密后的hex字符串
* @param clazz 被解密后json序列化为对应的class model
* @return
* @param <T>
*/
public <T> T decrypt(String encryptedHex, Class<T> clazz){
if(Objects.isNull(this.sm2)){
return null;
}
String jsonData = this.sm2.decryptStr(encryptedHex, KeyType.PrivateKey);
if(StringUtils.isBlank(jsonData) || !JSONUtil.isTypeJSON(jsonData)){
return null;
}
try {
return objectMapper.readValue(jsonData, clazz);
} catch (Exception e) {
logger.error(">>>>> SecurityPostModelService-objectMapper.readValue error:", e);
}
return null;
}
/**
* 返回sm2 公钥 hex字符串
* @return
*/
public String getPublicSM2Key(){
return securityPostModelProperties.getPublicKey();
}
public SecurityPkeyVerSign getSecurityPkeyVerSign(){
SecurityPkeyVerSign spks = new SecurityPkeyVerSign();
spks.setPublicKey(securityPostModelProperties.getPublicKey());
spks.setVerifySign(generateVerifySign());
return spks;
}
private String generateVerifySign() {
String verifySign = IdWorker.get32UUID();
// 在验签有效期内缓存
redisTemplate.opsForValue().set(PREFIX+verifySign, String.valueOf(System.currentTimeMillis()), this.securityPostModelProperties.getVerifySignTimeDiff());
return verifySign;
}
/**
* 验证签名串是否有效(不存在或过期删除),一次性验证签名需要立即删除签名避免重放攻击
* @param sign
* @return true
*/
public Boolean isVerifiedSign(String sign){
String signCacheKey = PREFIX+sign;
String timestamp = (String)redisTemplate.opsForValue().get(signCacheKey);
redisTemplate.delete(signCacheKey);
return StringUtils.isNotBlank(timestamp);
}
@Override public void afterSingletonsInstantiated() {
if(securityPostModelProperties.getEnabled()){
this.sm2 = SmUtil.sm2(securityPostModelProperties.getPrivateKey(), securityPostModelProperties.getPublicKey());
this.sm2.setMode(SM2Engine.Mode.C1C3C2);
logger.info(">>>>> SecurityPostModel Service Config Success. VerifySignTimeDiff={}", securityPostModelProperties.getVerifySignTimeDiff().toMillis());
}
}
public static class SecurityPkeyVerSign {
private String publicKey;
private String verifySign;
public String getPublicKey() {
return publicKey;
}
public void setPublicKey(String publicKey) {
this.publicKey = publicKey;
}
public String getVerifySign() {
return verifySign;
}
public void setVerifySign(String verifySign) {
this.verifySign = verifySign;
}
}
}
配置类
package com.nuzar.cloud.saas.common.authorization.property;
import org.springframework.boot.context.properties.ConfigurationProperties;
import java.time.Duration;
@ConfigurationProperties(prefix = "nuzar.cloud.security.saas-post-model")
public class SecurityPostModelProperties {
private Boolean enabled = false;
/**
* SM2 public-key for client eg: web/app
*/
private String publicKey;
/**
* SM2 private-key for server
*/
private String privateKey;
private Duration verifySignTimeDiff = Duration.ofSeconds(5);
public Boolean getEnabled() {
return enabled;
}
public void setEnabled(Boolean enabled) {
this.enabled = enabled;
}
public String getPublicKey() {
return this.publicKey;
}
public void setPublicKey(String publicKey) {
this.publicKey = publicKey;
}
public String getPrivateKey() {
return privateKey;
}
public void setPrivateKey(String privateKey) {
this.privateKey = privateKey;
}
public Duration getVerifySignTimeDiff() {
return verifySignTimeDiff;
}
public void setVerifySignTimeDiff(Duration verifySignTimeDiff) {
this.verifySignTimeDiff = verifySignTimeDiff;
}
}
2240

被折叠的 条评论
为什么被折叠?



