Shiro加密

shiro配置加密的两种方式,这里以MD5算法作为演示。

1.重写自实现的Realm类的setCredentialsMatcher()方法

public class MyRealm extends AuthorizingRealm {
	...
	@Override
    public void setCredentialsMatcher(CredentialsMatcher credentialsMatcher) {
        HashedCredentialsMatcher hashedCredentialsMatcher = new HashedCredentialsMatcher();
        // 设置加密算法
        hashedCredentialsMatcher.setHashAlgorithmName("MD5");
        // 设置加密次数
        hashedCredentialsMatcher.setHashIterations(1024);
        super.setCredentialsMatcher(hashedCredentialsMatcher);
    }
}

2.在shiroConfig配置类中

/**
     * 创建Realm,注入加密
     */
    @Bean(name = "myRealm")
    public MyRealm getRealm(@Qualifier("credentialsMatcher") HashedCredentialsMatcher credentialsMatcher) {
        MyRealm myRealm = new MyRealm();
        myRealm.setCredentialsMatcher(credentialsMatcher);
        return myRealm;
    }

    /**
     * 设置加密
     */
    @Bean(name = "credentialsMatcher")
    public HashedCredentialsMatcher hashedCredentialsMatcher() {
        HashedCredentialsMatcher hashedCredentialsMatcher = new HashedCredentialsMatcher();
        // 设置加密算法
        hashedCredentialsMatcher.setHashAlgorithmName("MD5");
        // 设置加密次数
        hashedCredentialsMatcher.setHashIterations(1024);
        return hashedCredentialsMatcher;
    }

注意:在认证方法中要做对应的修改,即

public class MyRealm extends AuthorizingRealm {
    @Autowired
    IUserService userService;
    @Override
    protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken authenticationToken) throws AuthenticationException {
        UsernamePasswordToken token = (UsernamePasswordToken) authenticationToken;
        User user = userService.queryUserByName(token.getUsername());
        // 判断用户名
        if (user == null) {
            return null;
        }
        // 判断密码
        // return new SimpleAuthenticationInfo(user, token.getPassword(), getName());
        return new SimpleAuthenticationInfo(user,new SimpleHash("MD5", token.getPassword(), token.getUsername(), 1024), 
        									ByteSource.Util.bytes(user.getName()), getName());
    }
    ......
}

否则验证时原密码比对库中的加密后的密码,会java.lang.IllegalArgumentException: Odd number of characters

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值