spring整合Shiro实现用户登录和菜单权限

本文详细介绍了如何在项目中配置和使用Apache Shiro进行权限管理,包括添加Shiro相关依赖,配置过滤器,自定义Realm,实现登录、权限检查及会话管理等功能。

1,添加shiro相关jar包

2,在web.xml配置文件中配置shiroFilter过滤器:            

 <context-param>
    <param-name>contextConfigLocation</param-name>
    <param-value>classpath:applicationContext.xml</param-value>
  </context-param>
  <listener>
    <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class>
  </listener>
  
  <!-- 配置shiroFilter通过代理来配置,对象由spring容器来创建的,但是交由servlet容器来管理 -->
  <filter>
  	<filter-name>shiroFilter</filter-name>
  	<filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
  	<init-param>
  		<!-- 表示bean的生命周期由servlet来管理 -->
  		<param-name>targetFilterLifecycle</param-name>
  		<param-value>true</param-value>
  	</init-param>
  	<init-param>
  		<!-- 表示在spring容器中bean的id,如果不配置该属性,那么默认和filter的name一致 -->
  		<param-name>targetBeanName</param-name>
  		<param-value>shiroFilter</param-value>
  	</init-param>
  </filter>
  <filter-mapping>
  	<filter-name>shiroFilter</filter-name>
  	<url-pattern>/*</url-pattern>
  </filter-mapping>
  
  
  <filter>
    <filter-name>encoding</filter-name>
    <filter-class>org.springframework.web.filter.CharacterEncodingFilter</filter-class>
    <init-param>
      <param-name>encoding</param-name>
      <param-value>UTF-8</param-value>
    </init-param>
    <init-param>
      <param-name>forceEncoding</param-name>
      <param-value>true</param-value>
    </init-param>
  </filter>
  <filter-mapping>
    <filter-name>encoding</filter-name>
    <url-pattern>/*</url-pattern>
  </filter-mapping>
  <servlet>
    <servlet-name>springmvc</servlet-name>
    <servlet-class>org.springframework.web.servlet.DispatcherServlet</servlet-class>
    <init-param>
      <param-name>contextConfigLocation</param-name>
      <param-value>classpath:mvc.xml</param-value>
    </init-param>
    <load-on-startup>1</load-on-startup>
  </servlet>
  <servlet-mapping>
    <servlet-name>springmvc</servlet-name>
    <url-pattern>/</url-pattern>
  </servlet-mapping>
  

3,spring-shiro.xml配置:             

  <!-- shiroFilter配置 -->                    
	<bean id="shiroFilter" class="org.apache.shiro.spring.web.ShiroFilterFactoryBean">
		<!-- securityManager配置 -->
		<property name="securityManager" ref="securityManager"/>
		<!-- 当访问需要认证的资源时,那么将自动跳转到该url 
			 如果不配做该属性,默认情况下会到根路径下的login.jsp
		-->
		<property name="loginUrl" value="/login"/>
		<!-- 配置认证成功后跳转到哪个Url上,通常不配做;如果不配置,那么默认认证成功后跳转到上一个url -->
		<property name="successUrl" value="/index.jsp"/>
		<!-- 配置用户没有权限访问资源时跳转的页面 -->
		<property name="unauthorizedUrl" value="/refuse.jsp" />
		<!-- 配置shiro的过滤器链 -->
		<property name="filterChainDefinitions">
			<value>
				/toLogin=anon
				/login=authc
				/logout=logout
				/index.jsp=user
				/js/**=anon
				/css/**=anon
				/images/**=anon
				/jQery/**=anon
				/**=anon			
			</value>
		</property>
	</bean>
	
	<!-- 配置authc,不是必须配置,如果不配置,表单的用户名和密码必须是:username,password -->
	<bean id="authc" class="org.apache.shiro.web.filter.authc.FormAuthenticationFilter">
		<property name="usernameParam" value="name"></property>
		<property name="passwordParam" value="pwd"></property>
	</bean>
	<!-- 配置logout -->                            
	<bean id="logout" class="org.apache.shiro.web.filter.authc.LogoutFilter" >
		<property name="redirectUrl" value="toLogin"/>
	</bean>
	
	<!-- securityManager配置 -->
	<bean id="securityManager" class="org.apache.shiro.web.mgt.DefaultWebSecurityManager">
		<property name="realm" ref="userRealm"/>
        <!-- cacheManager,sessionManager,rememberMeManager不是必须配置 -->
		<property name="cacheManager" ref="cacheManager"></property>
		<property name="sessionManager" ref="sessionManager"></property>
		<property name="rememberMeManager" ref="rememberMeManager"></property>
	</bean>
	<!-- ehcache配置缓存,如果你配置了ehcache缓存,在src目录下需要ehcache.xml配置 -->
	<bean id="cacheManager" class="org.apache.shiro.cache.ehcache.EhCacheManager">
		<property name="cacheManagerConfigFile" value="classpath:ehcache.xml"></property>
	</bean>
	<!-- 配置会话管理 -->
	<bean id="sessionManager" class="org.apache.shiro.web.session.mgt.DefaultWebSessionManager">
		<!-- session超时时间,单位毫秒 -->
		<property name="globalSessionTimeout" value="1800000"/>
		<!-- 清理无效的session -->
		<property name="deleteInvalidSessions" value="true"/>
	</bean>
	<!-- 配置记住我 -->
	<bean id="rememberMeManager" class="org.apache.shiro.web.mgt.CookieRememberMeManager">
		<property name="cookie" ref="rememberMeCookie"/>
	</bean>
	<bean id="rememberMeCookie" class="org.apache.shiro.web.servlet.SimpleCookie">
		<!-- 设置cookie的存活时间 -->
		<property name="maxAge" value="604800"/>
		<property name="name" value="rememberMe"></property>
	</bean>
	<!-- 自定义realm -->	
	<bean id="userRealm" class="com.reyco.core.realm.UserRealm">
		<property name="credentialsMatcher" ref="credentialsMatcher"/>
	</bean>
    <!-- 凭证匹配器 -->
    <bean id="credentialsMatcher" class="org.apache.shiro.authc.credential.HashedCredentialsMatcher">
    	<property name="hashAlgorithmName" value="md5"/>
    	<property name="hashIterations" value="2"/>
    </bean>   	  

4,spring-mvc.xml配置中shiro的配置:
                 

 <!-- 开启aop注解 -->
     <aop:config proxy-target-class="true"></aop:config>    	
     <!-- 开启shiro注解支持 -->
     <bean class="org.apache.shiro.spring.security.interceptor.AuthorizationAttributeSourceAdvisor">
     	<property name="securityManager" ref="securityManager"/>
     </bean>  

5,如果你配置了ehcache缓存,在src目录下需要ehcache.xml配置

<ehcache>
    <diskStore path="java.io.tmpdir"/>
    <defaultCache
        maxElementsInMemory="10000"
        eternal="false"
        timeToIdleSeconds="120"
        timeToLiveSeconds="120"
        overflowToDisk="true"
        />
</ehcache>

6,自定义    UserRealm.java 

/**
 * 自定义realm
 * @author reyco
 *
 */
public class UserRealm extends AuthorizingRealm{
	
	@Autowired
	private AccountService accountService;
	@Autowired
	private PermissionService permissionService;
	
	@Override
	public String getName() {
		return "UserRealm";
	}
	/**
	 * 验证
	 * @param arg0
	 * @return
	 * @throws AuthenticationException
	 */
	@Override
	protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken token) throws AuthenticationException {
		String username = token.getPrincipal().toString();
		System.out.println("----------认证-----------------username="+username);
		Account account = accountService.searchUserByUserName(username);
		SimpleAuthenticationInfo simpleAuthenticationInfo = new SimpleAuthenticationInfo(account, account.getPassword(),ByteSource.Util.bytes(account.getSalt()),getName());
		return simpleAuthenticationInfo;
	}
	/**
	 * 授权
	 * @param principal
	 * @return
	 */
	@Override
	protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principal) {
		Account account = (Account) principal.getPrimaryPrincipal();
		System.out.println("----------凭证-----------------username="+account);
		List<Permission> permissions = permissionService.searchPermissionByUserId(account.getId());
		if(null == permissions || permissions.size()==0) {
			return null;
		}
		SimpleAuthorizationInfo info = new SimpleAuthorizationInfo();
		System.out.println("----------info-----------------info="+info);
		for (Permission permission : permissions) {
			String percode = permission.getPercode();
			if(null!=percode) {
				info.addStringPermission(percode);
			}
		}
		return info;
	}
	/**
	 * 清理缓存
	 */
	protected void clearCache() {
		Subject subject = SecurityUtils.getSubject();
		super.clearCache(subject.getPrincipals());
	}
}

       权限实体类:

         

/**
 * 权限实体类
 * @author reyco
 *
 */
public class Permission implements Serializable{
    /**
     * 用户id
     */
	private Integer id;
    /**
     * 权限: 如:account:add
     */
	private String percode;
    /**
     * 权限名字: 如:账号添加
     */
	private String name;
	public Permission() {
	}
	public Permission(Integer id, String percode, String name) {
		super();
		this.id = id;
		this.percode = percode;
		this.name = name;
	}
	public Integer getId() {
		return id;
	}
	public void setId(Integer id) {
		this.id = id;
	}
	public String getPercode() {
		return percode;
	}
	public void setPercode(String percode) {
		this.percode = percode;
	}
	public String getName() {
		return name;
	}
	public void setName(String name) {
		this.name = name;
	}
	@Override
	public String toString() {
		return "Permission [id=" + id + ", percode=" + percode + ", name=" + name + "]";
	}
}

          用户实体类:Account.java

                   

@SuppressWarnings("all")
public class Account implements Serializable {
	/**
	 * 用户id
	 */
	private Integer id;
	/**
	 * 用户名
	 */
	private String username;
	/**
	 * 用户密码
	 */
	private String password;
	/**
	 * 盐值
	 */
	private String salt;
	/**
	 * 角色id
	 */
	private Integer rid;
	public Account() {
	}
	public Account(Integer id, String username, String password, String salt, Integer rid) {
		super();
		this.id = id;
		this.username = username;
		this.password = password;
		this.salt = salt;
		this.rid = rid;
	}
	public Integer getId() {
		return id;
	}
	public void setId(Integer id) {
		this.id = id;
	}
	public String getUsername() {
		return username;
	}
	public void setUsername(String username) {
		this.username = username;
	}
	public String getPassword() {
		return password;
	}
	public void setPassword(String password) {
		this.password = password;
	}
	public String getSalt() {
		return salt;
	}
	public void setSalt(String salt) {
		this.salt = salt;
	}
	public Integer getRid() {
		return rid;
	}
	public void setRid(Integer rid) {
		this.rid = rid;
	}
	@Override
	public String toString() {
		return "Account [id=" + id + ", username=" + username + ", password=" + password + ", salt=" + salt + ", rid="
				+ rid + "]";
	}
}

                  accountMapper.xml              

<!-- 登录 -->
	<select id="searchUserByUserName" resultType="Account">
		select id,username,password,salt,rid from `account` where `username`=#{username}
	</select>

                  permissionMapper.xml

<select id="searchPermissionByUserId" resultType="Permission">
		select id,name,percode from user_permission_view where id=#{id}
	</select>

             AccountDao.java

public interface AccountDao {
	
	public Account searchUserByUserName(String username);
	
}

           PermissionDao.java

public interface PermissionDao {
	
	public List<Permission> searchPermissionByUserId(Integer id);
	
}

          AccountService.java

public interface AccountService {
	
	public Account searchUserByUserName(String username);
	
}

        PermissionService.java

public interface PermissionService {
	
	public List<Permission> searchPermissionByUserId(Integer id);
	
}
 AccountServiceImpl.java    

@Service("accountService")
public class AccountServiceImpl implements AccountService {
	@Autowired
	private AccountDao accountDao;
	
	public void setAccountDao(AccountDao accountDao) {
		this.accountDao = accountDao;
	}

	@Override
	public Account searchUserByUserName(String username) {
		return accountDao.searchUserByUserName(username);
	}

}

PermissionServiceImpl.java

@Service("permissionService")
public class PermissionServiceImpl implements PermissionService{
	
	@Autowired
	private PermissionDao permissionDao;
	public void setPermissionDao(PermissionDao permissionDao) {
		this.permissionDao = permissionDao;
	}
	
	@Override
	public List<Permission> searchPermissionByUserId(Integer id) {
		return permissionDao.searchPermissionByUserId(id);
	}
}

AccountController.java       

@Controller("accountController")
public class AccountController {
	protected Logger logger = LoggerFactory.getLogger(getClass());
	@Autowired
	private AccountService accountService;
	public void setAccountService(AccountService accountService) {
		this.accountService = accountService;
	}
	@RequestMapping("/index")
	public ModelAndView index(HttpSession session) {
		Subject subject = SecurityUtils.getSubject();
		Account account = (Account)subject.getPrincipal();
		session.setAttribute("crruentUser", account.getUsername());
		return new ModelAndView("login");
	}
	/**
	 * 访问toLogin,然后访问login
	 * @return
	 */
	@RequestMapping(value= {"/","/toLogin"})
	public ModelAndView toLogin() {
		System.out.println("---toLogin---");
		return new ModelAndView("login");
	}
	/**
	 *   登录,验证不成功,则跳转到login.jsp页面;验证成功则跳转到配置的页面
	 * @param req
	 * @return
	 */
	@RequestMapping("/login")
	public ModelAndView login(HttpServletRequest req){
		System.out.println("---login---");
		ModelAndView mv = new ModelAndView("login.jsp");
		String exceptionClassName = (String)req.getAttribute("shiroLoginFailure");
		String error = "用户名/密码错误";
		if(UnknownAccountException.class.getName().equals(exceptionClassName)) {
			mv.addObject("msg", error);
		} else if(IncorrectCredentialsException.class.getName().equals(exceptionClassName)){
			mv.addObject("msg", error);
		} else {
			mv.addObject("msg", exceptionClassName);
		}
		return mv;
	}
	/**
	 * 访问refuse,然后访问refuse.jsp
	 * @return
	 */
	@RequestMapping("/refuse")
	public ModelAndView refuse() {
		System.out.println("---refuse---");
		return new ModelAndView("refuse.jsp");
	}
	
	@ResponseBody
	@RequestMapping("/role/list")
	@RequiresPermissions("role:list")
	public String list() {
		return JSONResult.create("role:list").toJSON();
	}
	@ResponseBody
	@RequestMapping("/role/delete")
	@RequiresPermissions("role:delete")
	public String delete() {
		return JSONResult.create("role:delete").toJSON();
	}
	@ResponseBody
	@RequestMapping("/role/update")
	@RequiresPermissions("role:update")
	public String update() {
		return JSONResult.create("role:update").toJSON();
	}
	@ResponseBody
	@RequestMapping("/role/add")
	@RequiresPermissions("role:add")
	public String add() {
		return JSONResult.create("role:add").toJSON();
	}
}

   jsp页面: index.jsp   login.jsp  list.jsp  refuse.jsp

               login.jsp          

<form action="login" method="post">
		<input type="text" name="name" placeholder="用户名"/><br>
		<input type="text" name="pwd" placeholder="密码"/><br>
		<input type="checkbox" name="rememberMe"/><p>记住我</p><br>
		<input type="submit" value="login"/>
	</form>

        list.jsp      

<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<%@ taglib prefix="shiro" uri="http://shiro.apache.org/tags"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Insert title here</title>
</head>
<body>

	list<a href="logout">退出</a>
	<%
	String username = (String) session.getAttribute("crruentUser");
	%>
	用户:<%=username %>
	 <shiro:hasPermission name="role:add">
		 <a href="">添加</a>
	 </shiro:hasPermission>
	 <shiro:hasPermission name="role:delete">
		 <a href="">删除</a>
	 </shiro:hasPermission>
	 <shiro:hasPermission name="role:update">
		 <a href="">编辑</a>
	 </shiro:hasPermission>
	 <shiro:hasPermission name="role:list">
		 <a href="">查询</a>
	 </shiro:hasPermission>
</body>
</html>

index.jsp和refuse.jsp都是空的

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

java的艺术

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值