1,添加shiro相关jar包
2,在web.xml配置文件中配置shiroFilter过滤器:
<context-param>
<param-name>contextConfigLocation</param-name>
<param-value>classpath:applicationContext.xml</param-value>
</context-param>
<listener>
<listener-class>org.springframework.web.context.ContextLoaderListener</listener-class>
</listener>
<!-- 配置shiroFilter通过代理来配置,对象由spring容器来创建的,但是交由servlet容器来管理 -->
<filter>
<filter-name>shiroFilter</filter-name>
<filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
<init-param>
<!-- 表示bean的生命周期由servlet来管理 -->
<param-name>targetFilterLifecycle</param-name>
<param-value>true</param-value>
</init-param>
<init-param>
<!-- 表示在spring容器中bean的id,如果不配置该属性,那么默认和filter的name一致 -->
<param-name>targetBeanName</param-name>
<param-value>shiroFilter</param-value>
</init-param>
</filter>
<filter-mapping>
<filter-name>shiroFilter</filter-name>
<url-pattern>/*</url-pattern>
</filter-mapping>
<filter>
<filter-name>encoding</filter-name>
<filter-class>org.springframework.web.filter.CharacterEncodingFilter</filter-class>
<init-param>
<param-name>encoding</param-name>
<param-value>UTF-8</param-value>
</init-param>
<init-param>
<param-name>forceEncoding</param-name>
<param-value>true</param-value>
</init-param>
</filter>
<filter-mapping>
<filter-name>encoding</filter-name>
<url-pattern>/*</url-pattern>
</filter-mapping>
<servlet>
<servlet-name>springmvc</servlet-name>
<servlet-class>org.springframework.web.servlet.DispatcherServlet</servlet-class>
<init-param>
<param-name>contextConfigLocation</param-name>
<param-value>classpath:mvc.xml</param-value>
</init-param>
<load-on-startup>1</load-on-startup>
</servlet>
<servlet-mapping>
<servlet-name>springmvc</servlet-name>
<url-pattern>/</url-pattern>
</servlet-mapping>
3,spring-shiro.xml配置:
<!-- shiroFilter配置 -->
<bean id="shiroFilter" class="org.apache.shiro.spring.web.ShiroFilterFactoryBean">
<!-- securityManager配置 -->
<property name="securityManager" ref="securityManager"/>
<!-- 当访问需要认证的资源时,那么将自动跳转到该url
如果不配做该属性,默认情况下会到根路径下的login.jsp
-->
<property name="loginUrl" value="/login"/>
<!-- 配置认证成功后跳转到哪个Url上,通常不配做;如果不配置,那么默认认证成功后跳转到上一个url -->
<property name="successUrl" value="/index.jsp"/>
<!-- 配置用户没有权限访问资源时跳转的页面 -->
<property name="unauthorizedUrl" value="/refuse.jsp" />
<!-- 配置shiro的过滤器链 -->
<property name="filterChainDefinitions">
<value>
/toLogin=anon
/login=authc
/logout=logout
/index.jsp=user
/js/**=anon
/css/**=anon
/images/**=anon
/jQery/**=anon
/**=anon
</value>
</property>
</bean>
<!-- 配置authc,不是必须配置,如果不配置,表单的用户名和密码必须是:username,password -->
<bean id="authc" class="org.apache.shiro.web.filter.authc.FormAuthenticationFilter">
<property name="usernameParam" value="name"></property>
<property name="passwordParam" value="pwd"></property>
</bean>
<!-- 配置logout -->
<bean id="logout" class="org.apache.shiro.web.filter.authc.LogoutFilter" >
<property name="redirectUrl" value="toLogin"/>
</bean>
<!-- securityManager配置 -->
<bean id="securityManager" class="org.apache.shiro.web.mgt.DefaultWebSecurityManager">
<property name="realm" ref="userRealm"/>
<!-- cacheManager,sessionManager,rememberMeManager不是必须配置 -->
<property name="cacheManager" ref="cacheManager"></property>
<property name="sessionManager" ref="sessionManager"></property>
<property name="rememberMeManager" ref="rememberMeManager"></property>
</bean>
<!-- ehcache配置缓存,如果你配置了ehcache缓存,在src目录下需要ehcache.xml配置 -->
<bean id="cacheManager" class="org.apache.shiro.cache.ehcache.EhCacheManager">
<property name="cacheManagerConfigFile" value="classpath:ehcache.xml"></property>
</bean>
<!-- 配置会话管理 -->
<bean id="sessionManager" class="org.apache.shiro.web.session.mgt.DefaultWebSessionManager">
<!-- session超时时间,单位毫秒 -->
<property name="globalSessionTimeout" value="1800000"/>
<!-- 清理无效的session -->
<property name="deleteInvalidSessions" value="true"/>
</bean>
<!-- 配置记住我 -->
<bean id="rememberMeManager" class="org.apache.shiro.web.mgt.CookieRememberMeManager">
<property name="cookie" ref="rememberMeCookie"/>
</bean>
<bean id="rememberMeCookie" class="org.apache.shiro.web.servlet.SimpleCookie">
<!-- 设置cookie的存活时间 -->
<property name="maxAge" value="604800"/>
<property name="name" value="rememberMe"></property>
</bean>
<!-- 自定义realm -->
<bean id="userRealm" class="com.reyco.core.realm.UserRealm">
<property name="credentialsMatcher" ref="credentialsMatcher"/>
</bean>
<!-- 凭证匹配器 -->
<bean id="credentialsMatcher" class="org.apache.shiro.authc.credential.HashedCredentialsMatcher">
<property name="hashAlgorithmName" value="md5"/>
<property name="hashIterations" value="2"/>
</bean>
4,spring-mvc.xml配置中shiro的配置:
<!-- 开启aop注解 -->
<aop:config proxy-target-class="true"></aop:config>
<!-- 开启shiro注解支持 -->
<bean class="org.apache.shiro.spring.security.interceptor.AuthorizationAttributeSourceAdvisor">
<property name="securityManager" ref="securityManager"/>
</bean>
5,如果你配置了ehcache缓存,在src目录下需要ehcache.xml配置
<ehcache>
<diskStore path="java.io.tmpdir"/>
<defaultCache
maxElementsInMemory="10000"
eternal="false"
timeToIdleSeconds="120"
timeToLiveSeconds="120"
overflowToDisk="true"
/>
</ehcache>
6,自定义 UserRealm.java
/**
* 自定义realm
* @author reyco
*
*/
public class UserRealm extends AuthorizingRealm{
@Autowired
private AccountService accountService;
@Autowired
private PermissionService permissionService;
@Override
public String getName() {
return "UserRealm";
}
/**
* 验证
* @param arg0
* @return
* @throws AuthenticationException
*/
@Override
protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken token) throws AuthenticationException {
String username = token.getPrincipal().toString();
System.out.println("----------认证-----------------username="+username);
Account account = accountService.searchUserByUserName(username);
SimpleAuthenticationInfo simpleAuthenticationInfo = new SimpleAuthenticationInfo(account, account.getPassword(),ByteSource.Util.bytes(account.getSalt()),getName());
return simpleAuthenticationInfo;
}
/**
* 授权
* @param principal
* @return
*/
@Override
protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principal) {
Account account = (Account) principal.getPrimaryPrincipal();
System.out.println("----------凭证-----------------username="+account);
List<Permission> permissions = permissionService.searchPermissionByUserId(account.getId());
if(null == permissions || permissions.size()==0) {
return null;
}
SimpleAuthorizationInfo info = new SimpleAuthorizationInfo();
System.out.println("----------info-----------------info="+info);
for (Permission permission : permissions) {
String percode = permission.getPercode();
if(null!=percode) {
info.addStringPermission(percode);
}
}
return info;
}
/**
* 清理缓存
*/
protected void clearCache() {
Subject subject = SecurityUtils.getSubject();
super.clearCache(subject.getPrincipals());
}
}
权限实体类:
/**
* 权限实体类
* @author reyco
*
*/
public class Permission implements Serializable{
/**
* 用户id
*/
private Integer id;
/**
* 权限: 如:account:add
*/
private String percode;
/**
* 权限名字: 如:账号添加
*/
private String name;
public Permission() {
}
public Permission(Integer id, String percode, String name) {
super();
this.id = id;
this.percode = percode;
this.name = name;
}
public Integer getId() {
return id;
}
public void setId(Integer id) {
this.id = id;
}
public String getPercode() {
return percode;
}
public void setPercode(String percode) {
this.percode = percode;
}
public String getName() {
return name;
}
public void setName(String name) {
this.name = name;
}
@Override
public String toString() {
return "Permission [id=" + id + ", percode=" + percode + ", name=" + name + "]";
}
}
用户实体类:Account.java
@SuppressWarnings("all")
public class Account implements Serializable {
/**
* 用户id
*/
private Integer id;
/**
* 用户名
*/
private String username;
/**
* 用户密码
*/
private String password;
/**
* 盐值
*/
private String salt;
/**
* 角色id
*/
private Integer rid;
public Account() {
}
public Account(Integer id, String username, String password, String salt, Integer rid) {
super();
this.id = id;
this.username = username;
this.password = password;
this.salt = salt;
this.rid = rid;
}
public Integer getId() {
return id;
}
public void setId(Integer id) {
this.id = id;
}
public String getUsername() {
return username;
}
public void setUsername(String username) {
this.username = username;
}
public String getPassword() {
return password;
}
public void setPassword(String password) {
this.password = password;
}
public String getSalt() {
return salt;
}
public void setSalt(String salt) {
this.salt = salt;
}
public Integer getRid() {
return rid;
}
public void setRid(Integer rid) {
this.rid = rid;
}
@Override
public String toString() {
return "Account [id=" + id + ", username=" + username + ", password=" + password + ", salt=" + salt + ", rid="
+ rid + "]";
}
}
accountMapper.xml
<!-- 登录 -->
<select id="searchUserByUserName" resultType="Account">
select id,username,password,salt,rid from `account` where `username`=#{username}
</select>
permissionMapper.xml
<select id="searchPermissionByUserId" resultType="Permission">
select id,name,percode from user_permission_view where id=#{id}
</select>
AccountDao.java
public interface AccountDao {
public Account searchUserByUserName(String username);
}
PermissionDao.java
public interface PermissionDao {
public List<Permission> searchPermissionByUserId(Integer id);
}
AccountService.java
public interface AccountService {
public Account searchUserByUserName(String username);
}
PermissionService.java
public interface PermissionService {
public List<Permission> searchPermissionByUserId(Integer id);
}
AccountServiceImpl.java
@Service("accountService")
public class AccountServiceImpl implements AccountService {
@Autowired
private AccountDao accountDao;
public void setAccountDao(AccountDao accountDao) {
this.accountDao = accountDao;
}
@Override
public Account searchUserByUserName(String username) {
return accountDao.searchUserByUserName(username);
}
}
PermissionServiceImpl.java
@Service("permissionService")
public class PermissionServiceImpl implements PermissionService{
@Autowired
private PermissionDao permissionDao;
public void setPermissionDao(PermissionDao permissionDao) {
this.permissionDao = permissionDao;
}
@Override
public List<Permission> searchPermissionByUserId(Integer id) {
return permissionDao.searchPermissionByUserId(id);
}
}
AccountController.java
@Controller("accountController")
public class AccountController {
protected Logger logger = LoggerFactory.getLogger(getClass());
@Autowired
private AccountService accountService;
public void setAccountService(AccountService accountService) {
this.accountService = accountService;
}
@RequestMapping("/index")
public ModelAndView index(HttpSession session) {
Subject subject = SecurityUtils.getSubject();
Account account = (Account)subject.getPrincipal();
session.setAttribute("crruentUser", account.getUsername());
return new ModelAndView("login");
}
/**
* 访问toLogin,然后访问login
* @return
*/
@RequestMapping(value= {"/","/toLogin"})
public ModelAndView toLogin() {
System.out.println("---toLogin---");
return new ModelAndView("login");
}
/**
* 登录,验证不成功,则跳转到login.jsp页面;验证成功则跳转到配置的页面
* @param req
* @return
*/
@RequestMapping("/login")
public ModelAndView login(HttpServletRequest req){
System.out.println("---login---");
ModelAndView mv = new ModelAndView("login.jsp");
String exceptionClassName = (String)req.getAttribute("shiroLoginFailure");
String error = "用户名/密码错误";
if(UnknownAccountException.class.getName().equals(exceptionClassName)) {
mv.addObject("msg", error);
} else if(IncorrectCredentialsException.class.getName().equals(exceptionClassName)){
mv.addObject("msg", error);
} else {
mv.addObject("msg", exceptionClassName);
}
return mv;
}
/**
* 访问refuse,然后访问refuse.jsp
* @return
*/
@RequestMapping("/refuse")
public ModelAndView refuse() {
System.out.println("---refuse---");
return new ModelAndView("refuse.jsp");
}
@ResponseBody
@RequestMapping("/role/list")
@RequiresPermissions("role:list")
public String list() {
return JSONResult.create("role:list").toJSON();
}
@ResponseBody
@RequestMapping("/role/delete")
@RequiresPermissions("role:delete")
public String delete() {
return JSONResult.create("role:delete").toJSON();
}
@ResponseBody
@RequestMapping("/role/update")
@RequiresPermissions("role:update")
public String update() {
return JSONResult.create("role:update").toJSON();
}
@ResponseBody
@RequestMapping("/role/add")
@RequiresPermissions("role:add")
public String add() {
return JSONResult.create("role:add").toJSON();
}
}
jsp页面: index.jsp login.jsp list.jsp refuse.jsp
login.jsp
<form action="login" method="post">
<input type="text" name="name" placeholder="用户名"/><br>
<input type="text" name="pwd" placeholder="密码"/><br>
<input type="checkbox" name="rememberMe"/><p>记住我</p><br>
<input type="submit" value="login"/>
</form>
list.jsp
<%@ page language="java" contentType="text/html; charset=UTF-8"
pageEncoding="UTF-8"%>
<%@ taglib prefix="shiro" uri="http://shiro.apache.org/tags"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Insert title here</title>
</head>
<body>
list<a href="logout">退出</a>
<%
String username = (String) session.getAttribute("crruentUser");
%>
用户:<%=username %>
<shiro:hasPermission name="role:add">
<a href="">添加</a>
</shiro:hasPermission>
<shiro:hasPermission name="role:delete">
<a href="">删除</a>
</shiro:hasPermission>
<shiro:hasPermission name="role:update">
<a href="">编辑</a>
</shiro:hasPermission>
<shiro:hasPermission name="role:list">
<a href="">查询</a>
</shiro:hasPermission>
</body>
</html>
index.jsp和refuse.jsp都是空的