[9] SecurityContextHolderAwareRequestFilter

Spring Security Principal详解
本文深入探讨Spring Security中SecurityContextHolderAwareRequestFilter的作用,解释其如何处理HttpServletRequest,使其支持Principal参数,以便Controller可以接收并使用。

SecurityContextHolderAwareRequestFilter

介绍

Spring Security TokenEndpoint中获取token的请求,有这样一个参数:Principal。 对于一个普通HttpServletRequest,是没有Principal参数类型的。SecurityContextHolderAwareRequestFilter通过HttpServletRequestFactory将HttpServletRequest请求包装成SecurityContextHolderAwareRequestWrapper,它实现了HttpServletRequest,并进行了扩展,添加一些额外的方法,比如:getPrincipal()方法等。这样就可以那些需要Principal等参数的Controller就可以接收到对应参数了。除了这个地方的应用,在其他地方,也可以直接调用request#getUserPrincipal()获取对应信息。

代码分析

步骤1

SecurityContextHolderAwareRequestFilter#doFilter()方法很简单,主要操作都在requestFactory.create()方法之中。SecurityContextHolderAwareRequestFilter初始化后,通过Bean后置处理器调用updateFactory()方法,该方法以"ROLE_"为参数创建了一个HttpServlet3RequestFactory并设置为过滤器的HttpServletRequestFactory。

private String rolePrefix = "ROLE_";
private HttpServletRequestFactory requestFactory;

public void doFilter(ServletRequest req, ServletResponse res, FilterChain chain)
        throws IOException, ServletException {
    chain.doFilter(this.requestFactory.create((HttpServletRequest) req,
            (HttpServletResponse) res), res);
}

@Override
public void afterPropertiesSet() throws ServletException {
    super.afterPropertiesSet();
    updateFactory();
}

private void updateFactory() {
    String rolePrefix = this.rolePrefix;
    this.requestFactory = createServlet3Factory(rolePrefix);
}

private HttpServletRequestFactory createServlet3Factory(String rolePrefix) {
    HttpServlet3RequestFactory factory = new HttpServlet3RequestFactory(rolePrefix);
    factory.setTrustResolver(this.trustResolver);
    factory.setAuthenticationEntryPoint(this.authenticationEntryPoint);
    factory.setAuthenticationManager(this.authenticationManager);
    factory.setLogoutHandlers(this.logoutHandlers);
    return factory;
}

步骤2

当请求经过过滤器时,requestFactory#create()会把请求进行包装成Servlet3SecurityContextHolderAwareRequestWrapper,它继承自SecurityContextHolderAwareRequestWrapper,用户getUserPrincipal()、getRemoteUser()方法,这2个方法都是从上下文中获取对应的信息,SpringMvc的ServletRequestMethodArgumentResolver方法参数解析中也有用到getUserPrincipal()。当参数类型是Principal时,就会调用request#getUserPrincipal(),这样就可以填充到TokenEndpoint的对应方法里了,代码如下:

@Override
public HttpServletRequest create(HttpServletRequest request,
        HttpServletResponse response) {
    return new Servlet3SecurityContextHolderAwareRequestWrapper(request,
            this.rolePrefix, response);
}
private Authentication getAuthentication() {
    Authentication auth = SecurityContextHolder.getContext().getAuthentication();

    if (!trustResolver.isAnonymous(auth)) {
        return auth;
    }

    return null;
}

@Override
public String getRemoteUser() {
    Authentication auth = getAuthentication();

    if ((auth == null) || (auth.getPrincipal() == null)) {
        return null;
    }

    if (auth.getPrincipal() instanceof UserDetails) {
        return ((UserDetails) auth.getPrincipal()).getUsername();
    }

    return auth.getPrincipal().toString();
}

@Override
public Principal getUserPrincipal() {
    Authentication auth = getAuthentication();

    if ((auth == null) || (auth.getPrincipal() == null)) {
        return null;
    }

    return auth;
}
else if (Principal.class.isAssignableFrom(paramType)) {
    Principal userPrincipal = request.getUserPrincipal();
    if (userPrincipal != null && !paramType.isInstance(userPrincipal)) {
        throw new IllegalStateException(
                "Current user principal is not of type [" + paramType.getName() + "]: " + userPrincipal);
    }
    return userPrincipal;
}
"C:\Program Files\Java\jdk-17\bin\java.exe" -XX:TieredStopAtLevel=1 -Dspring.output.ansi.enabled=always -Dcom.sun.management.jmxremote -Dspring.jmx.enabled=true -Dspring.liveBeansView.mbeanDomain -Dspring.application.admin.enabled=true "-Dmanagement.endpoints.jmx.exposure.include=*" "-javaagent:E:\IDEA\软件\IntelliJ IDEA 2024.1\lib\idea_rt.jar=58599:E:\IDEA\软件\IntelliJ IDEA 2024.1\bin" -Dfile.encoding=UTF-8 -classpath "C:\Users\南兮\Desktop\大三下\Front_(3)(2)\target\classes;E:\IDEA\apache-maven-3.9.9\org\springframework\boot\spring-boot-starter-web\2.7.5\spring-boot-starter-web-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\boot\spring-boot-starter\2.7.5\spring-boot-starter-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\boot\spring-boot\2.7.5\spring-boot-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\boot\spring-boot-starter-logging\2.7.5\spring-boot-starter-logging-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\ch\qos\logback\logback-classic\1.2.11\logback-classic-1.2.11.jar;E:\IDEA\apache-maven-3.9.9\ch\qos\logback\logback-core\1.2.11\logback-core-1.2.11.jar;E:\IDEA\apache-maven-3.9.9\org\apache\logging\log4j\log4j-to-slf4j\2.17.2\log4j-to-slf4j-2.17.2.jar;E:\IDEA\apache-maven-3.9.9\org\apache\logging\log4j\log4j-api\2.17.2\log4j-api-2.17.2.jar;E:\IDEA\apache-maven-3.9.9\org\slf4j\jul-to-slf4j\1.7.36\jul-to-slf4j-1.7.36.jar;E:\IDEA\apache-maven-3.9.9\jakarta\annotation\jakarta.annotation-api\1.3.5\jakarta.annotation-api-1.3.5.jar;E:\IDEA\apache-maven-3.9.9\org\yaml\snakeyaml\1.30\snakeyaml-1.30.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\boot\spring-boot-starter-json\2.7.5\spring-boot-starter-json-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\com\fasterxml\jackson\datatype\jackson-datatype-jdk8\2.13.4\jackson-datatype-jdk8-2.13.4.jar;E:\IDEA\apache-maven-3.9.9\com\fasterxml\jackson\datatype\jackson-datatype-jsr310\2.13.4\jackson-datatype-jsr310-2.13.4.jar;E:\IDEA\apache-maven-3.9.9\com\fasterxml\jackson\module\jackson-module-parameter-names\2.13.4\jackson-module-parameter-names-2.13.4.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\boot\spring-boot-starter-tomcat\2.7.5\spring-boot-starter-tomcat-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\org\apache\tomcat\embed\tomcat-embed-core\9.0.68\tomcat-embed-core-9.0.68.jar;E:\IDEA\apache-maven-3.9.9\org\apache\tomcat\embed\tomcat-embed-websocket\9.0.68\tomcat-embed-websocket-9.0.68.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\spring-web\5.3.23\spring-web-5.3.23.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\spring-beans\5.3.23\spring-beans-5.3.23.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\spring-webmvc\5.3.23\spring-webmvc-5.3.23.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\spring-context\5.3.23\spring-context-5.3.23.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\spring-expression\5.3.23\spring-expression-5.3.23.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\boot\spring-boot-starter-security\2.7.5\spring-boot-starter-security-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\spring-aop\5.3.23\spring-aop-5.3.23.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\security\spring-security-config\5.7.4\spring-security-config-5.7.4.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\security\spring-security-core\5.7.4\spring-security-core-5.7.4.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\security\spring-security-crypto\5.7.4\spring-security-crypto-5.7.4.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\security\spring-security-web\5.7.4\spring-security-web-5.7.4.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\boot\spring-boot-starter-data-redis\2.7.5\spring-boot-starter-data-redis-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\data\spring-data-redis\2.7.5\spring-data-redis-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\data\spring-data-keyvalue\2.7.5\spring-data-keyvalue-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\data\spring-data-commons\2.7.5\spring-data-commons-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\spring-tx\5.3.23\spring-tx-5.3.23.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\spring-oxm\5.3.23\spring-oxm-5.3.23.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\spring-context-support\5.3.23\spring-context-support-5.3.23.jar;E:\IDEA\apache-maven-3.9.9\org\slf4j\slf4j-api\1.7.36\slf4j-api-1.7.36.jar;E:\IDEA\apache-maven-3.9.9\io\lettuce\lettuce-core\6.1.10.RELEASE\lettuce-core-6.1.10.RELEASE.jar;E:\IDEA\apache-maven-3.9.9\io\netty\netty-common\4.1.84.Final\netty-common-4.1.84.Final.jar;E:\IDEA\apache-maven-3.9.9\io\netty\netty-handler\4.1.84.Final\netty-handler-4.1.84.Final.jar;E:\IDEA\apache-maven-3.9.9\io\netty\netty-resolver\4.1.84.Final\netty-resolver-4.1.84.Final.jar;E:\IDEA\apache-maven-3.9.9\io\netty\netty-buffer\4.1.84.Final\netty-buffer-4.1.84.Final.jar;E:\IDEA\apache-maven-3.9.9\io\netty\netty-transport-native-unix-common\4.1.84.Final\netty-transport-native-unix-common-4.1.84.Final.jar;E:\IDEA\apache-maven-3.9.9\io\netty\netty-codec\4.1.84.Final\netty-codec-4.1.84.Final.jar;E:\IDEA\apache-maven-3.9.9\io\netty\netty-transport\4.1.84.Final\netty-transport-4.1.84.Final.jar;E:\IDEA\apache-maven-3.9.9\io\projectreactor\reactor-core\3.4.24\reactor-core-3.4.24.jar;E:\IDEA\apache-maven-3.9.9\org\reactivestreams\reactive-streams\1.0.4\reactive-streams-1.0.4.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\boot\spring-boot-starter-validation\2.7.5\spring-boot-starter-validation-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\org\apache\tomcat\embed\tomcat-embed-el\9.0.68\tomcat-embed-el-9.0.68.jar;E:\IDEA\apache-maven-3.9.9\org\hibernate\validator\hibernate-validator\6.2.5.Final\hibernate-validator-6.2.5.Final.jar;E:\IDEA\apache-maven-3.9.9\jakarta\validation\jakarta.validation-api\2.0.2\jakarta.validation-api-2.0.2.jar;E:\IDEA\apache-maven-3.9.9\org\jboss\logging\jboss-logging\3.4.3.Final\jboss-logging-3.4.3.Final.jar;E:\IDEA\apache-maven-3.9.9\com\fasterxml\classmate\1.5.1\classmate-1.5.1.jar;E:\IDEA\apache-maven-3.9.9\com\mysql\mysql-connector-j\8.0.31\mysql-connector-j-8.0.31.jar;E:\IDEA\apache-maven-3.9.9\com\baomidou\mybatis-plus-boot-starter\3.5.2\mybatis-plus-boot-starter-3.5.2.jar;E:\IDEA\apache-maven-3.9.9\com\baomidou\mybatis-plus\3.5.2\mybatis-plus-3.5.2.jar;E:\IDEA\apache-maven-3.9.9\com\baomidou\mybatis-plus-extension\3.5.2\mybatis-plus-extension-3.5.2.jar;E:\IDEA\apache-maven-3.9.9\com\baomidou\mybatis-plus-core\3.5.2\mybatis-plus-core-3.5.2.jar;E:\IDEA\apache-maven-3.9.9\com\baomidou\mybatis-plus-annotation\3.5.2\mybatis-plus-annotation-3.5.2.jar;E:\IDEA\apache-maven-3.9.9\com\github\jsqlparser\jsqlparser\4.4\jsqlparser-4.4.jar;E:\IDEA\apache-maven-3.9.9\org\mybatis\mybatis\3.5.10\mybatis-3.5.10.jar;E:\IDEA\apache-maven-3.9.9\org\mybatis\mybatis-spring\2.0.7\mybatis-spring-2.0.7.jar;E:\IDEA\apache-maven-3.9.9\org\jetbrains\kotlin\kotlin-stdlib-jdk8\1.6.21\kotlin-stdlib-jdk8-1.6.21.jar;E:\IDEA\apache-maven-3.9.9\org\jetbrains\kotlin\kotlin-stdlib\1.6.21\kotlin-stdlib-1.6.21.jar;E:\IDEA\apache-maven-3.9.9\org\jetbrains\kotlin\kotlin-stdlib-common\1.6.21\kotlin-stdlib-common-1.6.21.jar;E:\IDEA\apache-maven-3.9.9\org\jetbrains\annotations\13.0\annotations-13.0.jar;E:\IDEA\apache-maven-3.9.9\org\jetbrains\kotlin\kotlin-stdlib-jdk7\1.6.21\kotlin-stdlib-jdk7-1.6.21.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\boot\spring-boot-autoconfigure\2.7.5\spring-boot-autoconfigure-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\boot\spring-boot-starter-jdbc\2.7.5\spring-boot-starter-jdbc-2.7.5.jar;E:\IDEA\apache-maven-3.9.9\com\zaxxer\HikariCP\4.0.3\HikariCP-4.0.3.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\spring-jdbc\5.3.23\spring-jdbc-5.3.23.jar;E:\IDEA\apache-maven-3.9.9\io\jsonwebtoken\jjwt\0.9.1\jjwt-0.9.1.jar;E:\IDEA\apache-maven-3.9.9\com\fasterxml\jackson\core\jackson-databind\2.13.4.2\jackson-databind-2.13.4.2.jar;E:\IDEA\apache-maven-3.9.9\com\fasterxml\jackson\core\jackson-annotations\2.13.4\jackson-annotations-2.13.4.jar;E:\IDEA\apache-maven-3.9.9\com\fasterxml\jackson\core\jackson-core\2.13.4\jackson-core-2.13.4.jar;E:\IDEA\apache-maven-3.9.9\org\projectlombok\lombok\1.18.24\lombok-1.18.24.jar;E:\IDEA\apache-maven-3.9.9\cn\hutool\hutool-all\5.8.10\hutool-all-5.8.10.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\spring-core\5.3.23\spring-core-5.3.23.jar;E:\IDEA\apache-maven-3.9.9\org\springframework\spring-jcl\5.3.23\spring-jcl-5.3.23.jar" com.hanfu.mall.HanfuMallApplication . ____ _ __ _ _ /\\ / ___'_ __ _ _(_)_ __ __ _ \ \ \ \ ( ( )\___ | '_ | '_| | '_ \/ _` | \ \ \ \ \\/ ___)| |_)| | | | | || (_| | ) ) ) ) ' |____| .__|_| |_|_| |_\__, | / / / / =========|_|==============|___/=/_/_/_/ :: Spring Boot :: (v2.7.5) 2025-06-18 15:47:43.423 INFO 35360 --- [ main] com.hanfu.mall.HanfuMallApplication : Starting HanfuMallApplication using Java 17.0.11 on LAPTOP-FEHG0BK5 with PID 35360 (C:\Users\南兮\Desktop\大三下\Front_(3)(2)\target\classes started by 南兮 in C:\Users\南兮\Desktop\大三下\Front_(3)(2)) 2025-06-18 15:47:43.425 INFO 35360 --- [ main] com.hanfu.mall.HanfuMallApplication : No active profile set, falling back to 1 default profile: "default" 2025-06-18 15:47:44.022 INFO 35360 --- [ main] .s.d.r.c.RepositoryConfigurationDelegate : Multiple Spring Data modules found, entering strict repository configuration mode 2025-06-18 15:47:44.025 INFO 35360 --- [ main] .s.d.r.c.RepositoryConfigurationDelegate : Bootstrapping Spring Data Redis repositories in DEFAULT mode. 2025-06-18 15:47:44.055 INFO 35360 --- [ main] .s.d.r.c.RepositoryConfigurationDelegate : Finished Spring Data repository scanning in 11 ms. Found 0 Redis repository interfaces. 2025-06-18 15:47:44.675 INFO 35360 --- [ main] o.s.b.w.embedded.tomcat.TomcatWebServer : Tomcat initialized with port(s): 8080 (http) 2025-06-18 15:47:44.684 INFO 35360 --- [ main] o.apache.catalina.core.StandardService : Starting service [Tomcat] 2025-06-18 15:47:44.684 INFO 35360 --- [ main] org.apache.catalina.core.StandardEngine : Starting Servlet engine: [Apache Tomcat/9.0.68] 2025-06-18 15:47:44.781 INFO 35360 --- [ main] o.a.c.c.C.[Tomcat].[localhost].[/api] : Initializing Spring embedded WebApplicationContext 2025-06-18 15:47:44.781 INFO 35360 --- [ main] w.s.c.ServletWebServerApplicationContext : Root WebApplicationContext: initialization completed in 1313 ms Logging initialized using 'class org.apache.ibatis.logging.stdout.StdOutImpl' adapter. Property 'mapperLocations' was not specified. _ _ |_ _ _|_. ___ _ | _ | | |\/|_)(_| | |_\ |_)||_|_\ / | 3.5.2 2025-06-18 15:47:45.759 WARN 35360 --- [ main] .s.s.UserDetailsServiceAutoConfiguration : Using generated security password: 6d604da4-da14-4435-a2d0-8c721a538517 This generated password is for development use only. Your security configuration must be updated before running your application in production. 2025-06-18 15:47:45.868 INFO 35360 --- [ main] o.s.s.web.DefaultSecurityFilterChain : Will secure any request with [org.springframework.security.web.session.DisableEncodeUrlFilter@7d977a20, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@35ab4260, org.springframework.security.web.context.SecurityContextPersistenceFilter@7221539, org.springframework.security.web.header.HeaderWriterFilter@32ba5c65, org.springframework.security.web.csrf.CsrfFilter@704c3bdf, org.springframework.security.web.authentication.logout.LogoutFilter@342a1f84, org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter@2d38db6f, org.springframework.security.web.authentication.ui.DefaultLoginPageGeneratingFilter@286a4c52, org.springframework.security.web.authentication.ui.DefaultLogoutPageGeneratingFilter@76134b9b, org.springframework.security.web.authentication.www.BasicAuthenticationFilter@629cbb1, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@15be68b, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@22ff1372, org.springframework.security.web.authentication.AnonymousAuthenticationFilter@38667005, org.springframework.security.web.session.SessionManagementFilter@47797401, org.springframework.security.web.access.ExceptionTranslationFilter@5a90fcaa, org.springframework.security.web.access.intercept.FilterSecurityInterceptor@25d0b918] 2025-06-18 15:47:45.906 WARN 35360 --- [ main] ConfigServletWebServerApplicationContext : Exception encountered during context initialization - cancelling refresh attempt: org.springframework.context.ApplicationContextException: Failed to start bean 'webServerStartStop'; nested exception is org.springframework.boot.web.server.PortInUseException: Port 8080 is already in use 2025-06-18 15:47:45.922 INFO 35360 --- [ main] o.apache.catalina.core.StandardService : Stopping service [Tomcat] 2025-06-18 15:47:45.930 INFO 35360 --- [ main] ConditionEvaluationReportLoggingListener : Error starting ApplicationContext. To display the conditions report re-run your application with 'debug' enabled. 2025-06-18 15:47:45.944 ERROR 35360 --- [ main] o.s.b.d.LoggingFailureAnalysisReporter : *************************** APPLICATION FAILED TO START *************************** Description: Web server failed to start. Port 8080 was already in use. Action: Identify and stop the process that's listening on port 8080 or configure this application to listen on another port. 进程已结束,退出代码为 1
06-19
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值