1、前言
本篇文章讲述spring boot 集成 spring security相关操作
2、具体步骤
2.1 maven依赖 以及工具类
依赖获取地址
<!-- spring security -->
<dependency>
<groupId>org.springframework.security.oauth</groupId>
<artifactId>spring-security-oauth2</artifactId>
<version>2.5.2.RELEASE</version>
</dependency>
<!--jwt依赖-->
<dependency>
<groupId>io.jsonwebtoken</groupId>
<artifactId>jjwt</artifactId>
<version>0.9.1</version>
</dependency>
redisService 这里用到redis 存放登录用户得信息,设置token的有效时间
@Service
@Slf4j
@AllArgsConstructor
public class RedisService {
private final RedisTemplate redisTemplate;
private final StringRedisTemplate stringRedisTemplate;
/**
* 指定缓存失效时间
*
* @param key 键
* @param time 时间:秒
* @return 操作是否成功
*/
public boolean expire(String key, long time) {
try {
if (time > 0) {
redisTemplate.expire(key, time, TimeUnit.SECONDS);
}
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 根据key获取过期时间
*
* @param key 键
* @return 时间(秒),返回0代表永久有效
*/
public long getExpireTime(String key) {
return redisTemplate.getExpire(key, TimeUnit.SECONDS);
}
/**
* 判断key是否存在
*
* @param key 键
* @return true存在,false不存在
*/
public boolean hasKey(String key) {
try {
return redisTemplate.hasKey(key);
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* String类型获取值
*
* @param key 键
* @return 值
*/
public String get(String key) {
return key == null ? null : stringRedisTemplate.opsForValue().get(key);
}
public Object getObject(String key) {
return key == null ? null : redisTemplate.opsForValue().get(key);
}
public <T> T getObject(String key, Class<T> tClass) {
if (key != null) {
String data = (String) redisTemplate.opsForValue().get(key);
return JSONObject.parseObject(data, tClass);
}
return null;
}
/**
* 普通缓存放入
*
* @param key 键
* @param value 值
* @return true成功 false失败
*/
public boolean set(String key, String value ) {
try {
stringRedisTemplate.opsForValue().set(key, value);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 添加缓存并设置过期时间
*
* @param key 键
* @param value 值
* @param time 时间(秒)
* @return true 成功 false 失败
*/
public boolean set(String key, String value, long time) {
try {
stringRedisTemplate.opsForValue().set(key, value, time, TimeUnit.SECONDS);
if (time > 0) {
expire(key, time);
}
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
public boolean setObject(String key, Object value, long time) {
try {
redisTemplate.opsForValue().set(key, value, time, TimeUnit.SECONDS);
if (time > 0) {
expire(key, time);
}
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
public boolean setObjectNoTime(String key, Object value, long time) {
try {
redisTemplate.opsForValue().set(key, value);
if (time > 0) {
expire(key, time);
}
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 递增
*
* @param key 键
* @return
*/
public long incr(String key, long delta) {
if (delta < 0) {
throw new RuntimeException("递增因子必须大于0");
}
return redisTemplate.opsForValue().increment(key, delta);
}
/**
* 递减
*
* @param key 键
* @return
*/
public long decr(String key, long delta) {
if (delta < 0) {
throw new RuntimeException("递减因子必须大于0");
}
return redisTemplate.opsForValue().increment(key, -delta);
}
/**
* hash递增 如果不存在,就会创建一个 并把新增后的值返回
*
* @param key 键
* @param item 项
* @param by 要增加几(大于0)
* @return
*/
public double hashIncr(String key, String item, double by) {
return redisTemplate.opsForHash().increment(key, item, by);
}
/**
* hash递减
*
* @param key 键
* @param item 项
* @param by 要减少记(小于0)
* @return
*/
public double hashDecr(String key, String item, double by) {
return redisTemplate.opsForHash().increment(key, item, -by);
}
/**
* hash递增 如果不存在,就会创建一个 并把新增后的值返回
*
* @param key 键
* @param item 项
* @param by 要增加几(大于0)
* @return
*/
public double hashIncrString(String key, String item, double by) {
return stringRedisTemplate.opsForHash().increment(key, item, by);
}
/**
* hash递减
*
* @param key 键
* @param item 项
* @param by 要减少记(小于0)
* @return
*/
public double hashDecrString(String key, String item, double by) {
return stringRedisTemplate.opsForHash().increment(key, item, -by);
}
/**
* 获取hash中对应item的数据
*
* @param key 键 不能为null
* @param item 项 不能为null
* @return 值
*/
public Object getObjectForMap(String key, String item) {
return redisTemplate.opsForHash().get(key, item);
}
/**
* 获取hash中对应item的数据
*
* @param key 键 不能为null
* @param item 项 不能为null
* @return 值
*/
public Object getForMap(String key, String item) {
return stringRedisTemplate.opsForHash().get(key, item);
}
/**
* 获取hashKey对应的所有键值
*
* @param key 键
* @return 对应的多个键值
*/
public Map<String, String> getMap(String key) {
return redisTemplate.opsForHash().entries(key);
}
/**
* 获取hashKey对应的所有键值
*
* @param key 键
* @return 对应的多个键值
*/
public Map<Object, Object> getMapString(String key) {
return stringRedisTemplate.opsForHash().entries(key);
}
public Map<String, Object> getMapObject(String key) {
return redisTemplate.opsForHash().entries(key);
}
/**
* 将map表放入hash缓存
*
* @param key 键
* @param map 对应多个键值
* @return true 成功 false 失败
*/
public boolean setMap(String key, Map<String, String> map) {
try {
stringRedisTemplate.opsForHash().putAll(key, map);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
public boolean setMapObject(String key, Map<String, Object> map) {
try {
redisTemplate.opsForHash().putAll(key, map);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* HashSet 并设置时间
*
* @param key 键
* @param map 对应多个键值
* @param time 时间(秒)
* @return true 成功 false 失败
*/
public boolean setMap(String key, Map<String, String> map, long time) {
try {
stringRedisTemplate.opsForHash().putAll(key, map);
if (time > 0) {
expire(key, time);
}
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
public boolean setMapObject(String key, Map<String, Object> map, long time) {
try {
redisTemplate.opsForHash().putAll(key, map);
if (time > 0) {
expire(key, time);
}
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 向一张hash表中放入数据,如果不存在将创建
*
* @param key 键
* @param item 项
* @param value 值
* @return true 成功 false 失败
*/
public boolean setToMap(String key, String item, String value) {
try {
stringRedisTemplate.opsForHash().put(key, item, value);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
public boolean setMapObject(String key, String item, Object value) {
try {
redisTemplate.opsForHash().put(key, item, value);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 向一张hash表中放入数据,如果不存在将创建
*
* @param key 键
* @param item 项
* @param value 值
* @param time 时间(秒) 注意:如果已存在的hash表有时间,这里将会替换原有的时间
* @return true 成功 false 失败
*/
public boolean setMap(String key, String item, String value, long time) {
try {
stringRedisTemplate.opsForHash().put(key, item, value);
if (time > 0) {
expire(key, time);
}
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
public boolean setMapObject(String key, String item, Object value, long time) {
try {
redisTemplate.opsForHash().put(key, item, value);
if (time > 0) {
expire(key, time);
}
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 删除hash表中的值
*
* @param key 键 不能为null
* @param item 项 可以使多个 不能为null
*/
public void delItemToMap(String key, Object... item) {
redisTemplate.opsForHash().delete(key, item);
}
/**
* 判断hash表中是否有该项的值
*
* @param key 键 不能为null
* @param item 项 不能为null
* @return true 存在 false不存在
*/
public boolean hasItemToMap(String key, String item) {
return redisTemplate.opsForHash().hasKey(key, item);
}
/**
* 根据key获取Set中的所有值
*
* @param key 键
* @return
*/
public Set<String> getSet(String key) {
try {
return stringRedisTemplate.opsForSet().members(key);
} catch (Exception e) {
e.printStackTrace();
return null;
}
}
public Set<Object> getSetObject(Object key) {
try {
return redisTemplate.opsForSet().members(key);
} catch (Exception e) {
e.printStackTrace();
return null;
}
}
/**
* 根据value从一个set中查询,是否存在
*
* @param key 键
* @param value 值
* @return true 存在 false不存在
*/
public boolean hasValueToSet(String key, Object value) {
try {
return redisTemplate.opsForSet().isMember(key, value);
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 将数据放入set缓存
*
* @param key 键
* @param values 值 可以是多个
* @return 成功个数
*/
public long addSet(String key, String... values) {
try {
return stringRedisTemplate.opsForSet().add(key, values);
} catch (Exception e) {
e.printStackTrace();
return 0;
}
}
public long addSetObject(String key, Object... values) {
try {
return redisTemplate.opsForSet().add(key, values);
} catch (Exception e) {
e.printStackTrace();
return 0;
}
}
/**
* 将set数据放入缓存
*
* @param key 键
* @param time 时间(秒)
* @param values 值 可以是多个
* @return 成功个数
*/
public long addSet(String key, long time, String... values) {
try {
Long count = stringRedisTemplate.opsForSet().add(key, values);
if (time > 0) expire(key, time);
return count;
} catch (Exception e) {
e.printStackTrace();
return 0;
}
}
public long addSetObject(String key, long time, Object... values) {
try {
Long count = redisTemplate.opsForSet().add(key, values);
if (time > 0) expire(key, time);
return count;
} catch (Exception e) {
e.printStackTrace();
return 0;
}
}
/**
* 获取set缓存的长度
*
* @param key 键
* @return
*/
public long getSetSize(String key) {
try {
return redisTemplate.opsForSet().size(key);
} catch (Exception e) {
e.printStackTrace();
return 0;
}
}
/**
* 移除值为value的
*
* @param key 键
* @param values 值 可以是多个
* @return 移除的个数
*/
public long delSetObject(String key, Object... values) {
try {
Long count = redisTemplate.opsForSet().remove(key, values);
return count;
} catch (Exception e) {
e.printStackTrace();
return 0;
}
}
public long deleteKey(String... key) {
if (key != null && key.length > 0) {
redisTemplate.delete(key);
}
return 0;
}
public long deleteKeyStr(String... key) {
if (key != null && key.length > 0) {
stringRedisTemplate.delete(Arrays.asList(key));
}
return 0;
}
/* list */
/**
* 获取list缓存的所有内容
*
* @param key 键
* @return
*/
public List<String> getList(String key) {
try {
return stringRedisTemplate.opsForList().range(key, 0, -1);
} catch (Exception e) {
e.printStackTrace();
return null;
}
}
public List<Object> getListObject(String key) {
try {
return redisTemplate.opsForList().range(key, 0, -1);
} catch (Exception e) {
e.printStackTrace();
return null;
}
}
/**
* 获取list缓存的内容
*
* @param key 键
* @param start 开始
* @param end 结束 0 到 -1代表所有值
* @return
*/
public List<String> getList(String key, long start, long end) {
try {
return stringRedisTemplate.opsForList().range(key, start, end);
} catch (Exception e) {
e.printStackTrace();
return null;
}
}
public List<Object> getListObject(String key, long start, long end) {
try {
return redisTemplate.opsForList().range(key, start, end);
} catch (Exception e) {
e.printStackTrace();
return null;
}
}
/**
* 获取list缓存的长度
*
* @param key 键
* @return
*/
public long getListSize(String key) {
try {
return redisTemplate.opsForList().size(key);
} catch (Exception e) {
e.printStackTrace();
return 0;
}
}
/**
* 通过索引 获取list中的值
*
* @param key 键
* @param index 索引 index>=0时, 0 表头,1 第二个元素,依次类推;index<0时,-1,表尾,-2倒数第二个元素,依次类推
* @return
*/
public String getList(String key, long index) {
try {
return stringRedisTemplate.opsForList().index(key, index);
} catch (Exception e) {
e.printStackTrace();
return null;
}
}
public Object getListObject(String key, long index) {
try {
return redisTemplate.opsForList().index(key, index);
} catch (Exception e) {
e.printStackTrace();
return null;
}
}
/**
* 将list放入缓存
*
* @param key 键
* @param value 值
* @return
*/
public boolean addList(String key, String value) {
try {
stringRedisTemplate.opsForList().rightPush(key, value);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 将list放入缓存
*
* @param key 键
* @param value 值
* @return
*/
public boolean addListObject(String key, Object value) {
try {
redisTemplate.opsForList().rightPush(key, value);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 将list放入缓存
*
* @param key 键
* @param value 值
* @param time 时间(秒)
* @return
*/
public boolean addList(String key, String value, long time) {
try {
redisTemplate.opsForList().rightPush(key, value);
if (time > 0) expire(key, time);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 将list放入缓存
*
* @param key 键
* @param value 值
* @param time 时间(秒)
* @return
*/
public boolean addListObject(String key, Object value, long time) {
try {
redisTemplate.opsForList().rightPush(key, value);
if (time > 0) expire(key, time);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 将list放入缓存
*
* @param key 键
* @param value 值
* @return
*/
public boolean addList(String key, List<String> value) {
try {
stringRedisTemplate.opsForList().rightPushAll(key, value);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
public boolean addListObject(String key, List<Object> value) {
try {
redisTemplate.opsForList().rightPushAll(key, value);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 将list放入缓存
*
* @param key 键
* @param value 值
* @param time 时间(秒)
* @return
*/
public boolean addList(String key, List<String> value, long time) {
try {
stringRedisTemplate.opsForList().rightPushAll(key, value);
if (time > 0) expire(key, time);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
public boolean addListObject(String key, List<Object> value, long time) {
try {
redisTemplate.opsForList().rightPushAll(key, value);
if (time > 0) expire(key, time);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 根据索引修改list中的某条数据
*
* @param key 键
* @param index 索引
* @param value 值
* @return
*/
public boolean addListByIndex(String key, long index, Object value) {
try {
redisTemplate.opsForList().set(key, index, value);
return true;
} catch (Exception e) {
e.printStackTrace();
return false;
}
}
/**
* 移除N个值为value
*
* @param key 键
* @param count 移除多少个
* @param value 值
* @return 移除的个数
*/
public long delListObject(String key, long count, Object value) {
try {
Long remove = redisTemplate.opsForList().remove(key, count, value);
return remove;
} catch (Exception e) {
e.printStackTrace();
return 0;
}
}
}
JwtUtil 根据用户信息生成token 令牌 这里是我从网络上找的工具类,具体忘记来路了,莫怪
public class JwtUtil {
// 设置有效期为60 * 60 *1000 一个小时
public static final Long JWT_TTL = 60 * 60 * 1000L;
//设置秘钥明文
public static final String JWT_KEY = "bootbase";
public static String getUUID() {
String token = UUID.randomUUID().toString().replaceAll("-", "");
return token;
}
/**
* 生成jtw
* @param subject token中要存放的数据(json格式)
*/
public static String createJWT(String subject) {
JwtBuilder builder = getJwtBuilder(subject, null, getUUID());// 设置过期时间
return builder.compact();
}
/**
* 生成jwt
* @param subject token中要存放的数据(json格式)
* @param ttlMillis token超时时间
*/
public static String createJWT(String subject, Long ttlMillis) {
JwtBuilder builder = getJwtBuilder(subject, ttlMillis, getUUID());// 设置过期时间
return builder.compact();
}
private static JwtBuilder getJwtBuilder(String subject, Long ttlMillis, String uuid) {
SignatureAlgorithm signatureAlgorithm = SignatureAlgorithm.HS256;
SecretKey secretKey = generalKey();
long nowMillis = System.currentTimeMillis();
Date now = new Date(nowMillis);
if (ttlMillis == null) {
ttlMillis = JwtUtil.JWT_TTL;
}
long expMillis = nowMillis + ttlMillis;
Date expDate = new Date(expMillis);
return Jwts.builder()
.setId(uuid) //唯一的ID
.setSubject(subject) // 主题 可以是JSON数据
.setIssuer("sheep") // 签发者
.setIssuedAt(now) // 签发时间
.signWith(signatureAlgorithm, secretKey) //使用HS256对称加密算法签名, 第二个参数为秘钥
.setExpiration(expDate);
}
/**
* 创建token
*/
public static String createJWT(String id, String subject, Long ttlMillis) {
JwtBuilder builder = getJwtBuilder(subject, ttlMillis, id);// 设置过期时间
return builder.compact();
}
/**
* 生成加密后的秘钥 secretKey
*/
public static SecretKey generalKey() {
byte[] encodedKey = Base64.getDecoder().decode(JwtUtil.JWT_KEY);
SecretKey key = new SecretKeySpec(encodedKey, 0, encodedKey.length, "AES");
return key;
}
/**
* 解析
* @throws Exception
*/
public static Claims parseJWT(String jwt) throws Exception {
SecretKey secretKey = generalKey();
return Jwts.parser()
.setSigningKey(secretKey)
.parseClaimsJws(jwt)
.getBody();
}
}
2.2 用户实体类
class SysUser 需要实现 security UserDetails 接口
/**
* @Author lixingshun
* @Date 2023/04/10
**/
/**
* 用户表
*/
@Data
@Builder
@AllArgsConstructor
@NoArgsConstructor
@TableName(value = "sys_user")
public class SysUser implements UserDetails {
/**
* 主键ID
*/
@TableId(value = "user_id", type = IdType.AUTO)
private Integer userId;
/**
* 创建时间
*/
@TableField(value = "create_time")
private Date createTime;
/**
* 修改时间
*/
@TableField(value = "update_time")
private Date updateTime;
/**
* 逻辑删除标记(0:显示;1:隐藏)
*/
@TableField(value = "del_flag")
private String delFlag;
/**
* 用户姓名
*/
@TableField(value = "name")
private String name;
/**
* 用户名
*/
@TableField(value = "username")
private String username;
/**
* 密码
*/
@TableField(value = "password")
private String password;
/**
* 手机号
*/
@TableField(value = "phone")
private String phone;
/**
* 盐
*/
@TableField(value = "salt")
private String salt;
@TableField(exist = false)
private List<SysRole> sysRoleList;
@Override
public Collection<? extends GrantedAuthority> getAuthorities() {
List<GrantedAuthority> grantedAuthorities = new ArrayList<>();
sysRoleList.forEach(v -> {
grantedAuthorities.add(new SimpleGrantedAuthority("ROLE_"+v.getRoleCode()));
});
return grantedAuthorities;
}
@Override
public boolean isAccountNonExpired() {
return true;
}
@Override
public boolean isAccountNonLocked() {
return true;
}
@Override
public boolean isCredentialsNonExpired() {
return true;
}
@Override
public boolean isEnabled() {
return true;
}
}
class SysRole
/**
*@Author lixingshun
* @Date 2023/04/10
**/
/**
* 系统角色表
*/
@Data
@Builder
@AllArgsConstructor
@NoArgsConstructor
@TableName(value = "sys_role")
public class SysRole implements Serializable {
@TableId(value = "role_id", type = IdType.AUTO)
private Integer roleId;
@TableField(value = "create_time")
private Date createTime;
@TableField(value = "update_time")
private Date updateTime;
/**
* 逻辑删除标记(0:显示;1:隐藏)
*/
@TableLogic(value = "0", delval = "1")
private String delFlag;
@TableField(value = "role_name")
private String roleName;
@TableField(value = "role_code")
private String roleCode;
@TableField(value = "role_desc")
private String roleDesc;
}
2.3 service
interface SysUserService 需要 继承 security UserDetailsService 重写 loadUserByUsername 方法,这里得接口里面新加了一个login 方法是为了获取jwt 令牌
/**
*@Author lixingshun
* @Date 2023/04/10
**/
public interface SysUserService extends CrudService<SysUser>, UserDetailsService {
R login(SysUser sysUser);
}
impl 实现类
/**
* @Author lixingshun
* @Date 2023/04/10
**/
@Service
@AllArgsConstructor
@Slf4j
public class SysUserServiceImpl extends CrudServiceImpl<SysUserMapper, SysUser> implements SysUserService {
private static final PasswordEncoder ENCODER = new BCryptPasswordEncoder();
private final RedisService redisService;
/** 获取认证入口 */
private final AuthenticationManager authenticationManager;
private final SysUserRoleService sysUserRoleService;
@Override
public UserDetails loadUserByUsername(String username) throws UsernameNotFoundException {
SysUser sysUser = baseMapper.selectUser(username);
if (sysUser == null) {
throw new UsernameNotFoundException(SecurityConstants.USER_NOT_FOUND);
}
return sysUser;
}
@Override
public R login(SysUser sysUser) {
// 在没认证之前principal, credentials两个参数分别存放用户名和密码
UsernamePasswordAuthenticationToken authenticationToken = new UsernamePasswordAuthenticationToken(sysUser.getUsername(),sysUser.getPassword());
// 通过AuthenticationManager的authenticate方法来进行用户认证
Authentication authenticate = authenticationManager.authenticate(authenticationToken);
// 判断是否验证成功
if(Objects.isNull(authenticate)){
return R.failed("用户名或密码错误");
}
// 在认证信息authenticate中获取登录成功后的用户信息
SysUser loginUser = (SysUser) authenticate.getPrincipal();
// 使用userid生成token
String userId = loginUser.getUserId().toString();
String jwt = JwtUtil.createJWT(userId);
// userId用作key,将用户信息存入redis,并设置30分钟过期
redisService.set(CommonConstants.BIZ_REDIS_PRE+"login:" + userId, JSONObject.toJSONString(loginUser), 30*60);
// 把token响应给前端
HashMap<String,String> map = new HashMap<>();
map.put("token",jwt);
return R.ok(map,"登录成功");
}
}
2.4 配置类config
SecurityConfig 继承 WebSecurityConfigurerAdapter
@Configuration
@AllArgsConstructor
@EnableWebSecurity //开启springSecurity默认行为
@EnableGlobalMethodSecurity(securedEnabled=true,prePostEnabled = true,jsr250Enabled = true)//开启注解功能,默认禁用注解
public class SecurityConfig extends WebSecurityConfigurerAdapter {
/**
* 认证失败处理类
*/
private final AuthenticationEntryPointImpl unauthorizedHandler;
private final JwtAuthenticationTokenFilter authenticationTokenFilter;
private final SecurityAccessDeniedHandler securityAccessDeniedHandler;
/**
* 这里使用了数组当作下方可变参数列表的参数
*/
private final String[] staticMatchers = new String[]{
"/webjars/**",
"/swagger-resources/**",
"/v2/**",
"/swagger-ui/**",
"/swagger-ui/index.html",
"/v3/api-docs"
};
/**
* 这里使用了数组当作下方可变参数列表的参数
*/
private final String[] urlMatchers = new String[]{
"/user/login",
"/api/**"
};
@Override
public void configure(WebSecurity web) throws Exception {
web.ignoring().antMatchers(staticMatchers);
}
@Bean
public PasswordEncoder passwordEncoder() {
return new BCryptPasswordEncoder();
}
/**
* 授权中心管理器
*
* @return AuthenticationManager
* @throws Exception 异常
*/
@Bean
@Override
public AuthenticationManager authenticationManagerBean() throws Exception {
return super.authenticationManagerBean();
}
/**
* 拦截所有请求,使用httpBasic方式登陆
*
* @param http 请求
* @throws Exception 异常
*/
@Override
protected void configure(HttpSecurity http) throws Exception {
http
//关闭csrf
.csrf().disable()
//不通过Session获取SecurityContext
.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS)
.and()
.authorizeRequests()
// 对于登录接口和其他接口允许匿名访问
.antMatchers(urlMatchers).anonymous()
// 除上面外的所有请求全部需要鉴权认证
.anyRequest().authenticated();
//默认过滤器之前,先走jwt过滤器
http.addFilterBefore(authenticationTokenFilter, UsernamePasswordAuthenticationFilter.class);
//配置异常处理器
http.exceptionHandling()
//配置认证失败处理器
.authenticationEntryPoint(unauthorizedHandler)
//认证通过,且没有权限访问
.accessDeniedHandler(securityAccessDeniedHandler);
//允许跨域
http.cors();
}
}
JwtAuthenticationTokenFilter HttpSecurity 类addFilterBefore()方法
@Component
@Slf4j
@AllArgsConstructor
public class JwtAuthenticationTokenFilter extends OncePerRequestFilter {
private final RedisService redisService;
@Override
protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain filterChain) throws ServletException, IOException {
//获取token
String token = request.getHeader("token");
if (!StringUtils.hasText(token)) {
log.info("无token");
//放行
filterChain.doFilter(request, response);
return;
}
//解析token
String userId;
try {
Claims claims = JwtUtil.parseJWT(token);
userId = claims.getSubject();
} catch (Exception e) {
e.printStackTrace();
throw new RuntimeException("token非法");
}
//从redis中获取用户信息
String redisKey = CommonConstants.BIZ_REDIS_PRE+"login:" + userId;
String jsonStr = redisService.get(redisKey);
JSONObject jsonObject = JSONObject.parseObject(jsonStr);
SysUser loginUser = JSONObject.toJavaObject(jsonObject,SysUser.class);
if(Objects.isNull(loginUser)){
throw new RuntimeException("账号登录已超时,请重新登录");
}
//存入SecurityContextHolder,把用户和权限传给spring
UsernamePasswordAuthenticationToken authenticationToken =
new UsernamePasswordAuthenticationToken(loginUser,null,loginUser.getAuthorities());
SecurityContextHolder.getContext().setAuthentication(authenticationToken);
//放行
filterChain.doFilter(request, response);
}
}
AuthenticationEntryPointImpl 未认证 认证失败异常处理 也可以配置全局异常处理
/**
* 认证失败处理类 返回未授权
*
*/
@Component
@Slf4j
public class AuthenticationEntryPointImpl implements AuthenticationEntryPoint, Serializable {
private static final long serialVersionUID = -8970718410437077606L;
@Override
public void commence(HttpServletRequest request, HttpServletResponse response, AuthenticationException authException) throws IOException, ServletException {
// 跨域处理
response.setHeader("Access-Control-Allow-Origin", "*");
// 允许的请求方法
response.setHeader("Access-Control-Allow-Methods", "GET,POST,OPTIONS,PUT,DELETE");
// 允许的请求头
response.setHeader("Access-Control-Allow-Headers", request.getHeader("Access-Control-Request-Headers"));
// 设置响应头
response.setContentType("application/json;charset=utf-8");
int code = HttpStatus.FORBIDDEN.value();
String msg = String.format("请求访问:%s,认证失败,无法访问系统资源", request.getRequestURI());
ServletUtils.renderString(response, JSON.toJSONString(new R<>(code,msg,null)));
}
}
SecurityAccessDeniedHandler 认证通过但是权限不住的异常处理
@Component
public class SecurityAccessDeniedHandler implements AccessDeniedHandler {
@Override
public void handle(HttpServletRequest request, HttpServletResponse response, AccessDeniedException e) throws IOException, ServletException {
// 跨域处理
response.setHeader("Access-Control-Allow-Origin", "*");
// 允许的请求方法
response.setHeader("Access-Control-Allow-Methods", "GET,POST,OPTIONS,PUT,DELETE");
// 允许的请求头
response.setHeader("Access-Control-Allow-Headers", request.getHeader("Access-Control-Request-Headers"));
// 设置响应头
response.setContentType("application/json;charset=utf-8");
//通过httpServletRepsonse返回给前台
int code = HttpStatus.UNAUTHORIZED.value();
String msg = String.format("请求访问:%s,权限不足,无法访问系统资源", request.getRequestURI());
ServletUtils.renderString(response, JSON.toJSONString(new R<>(code,msg,null)));
}
}
1781





