CAS客户端开发
此次客户端开发采用cas-server4.0,数据库使用mysql。cas使用数据库验证有两种方式,一种使用cas-server-support-jdbc自带的模块,另一种需要自己写数据库密码验证(推荐)此处使用第二种方式。
1.新建cas_server
为了方便,首先我们现在工作区间新建一个动态Web项目取名为MyCas,然后解压cas4.0的得到的cas-server-webapp-4.0.0.war,放在tomcat下面运行解压,将解压文件中的内容替换到cas_server的WebContent目录下。(也可以导入源码)
导入到项目中以后会有一些报错,但是基本上没什么影响,能运行起来显示登陆主页就表示导入成功了。
2.修改WEB-INF\spring-configuration\applicationContext.xml
将文件中的beansnames属性改为如下,将国际化配置文件切换为汉语:
- <util:list id="basenames">
- <value>classpath:custom_messages</value>
- <value>classpath:messages_zh_CN</value>
- </util:list>
<dependency>
<groupId>com.alibaba</groupId>
<artifactId>druid</artifactId>
<version>1.0.18</version>
</dependency>
<dependency>
<groupId>mysql</groupId>
<artifactId>mysql-connector-java</artifactId>
<version>5.1.38</version>
</dependency>
4.配置数据库连接池(事物可不配置)
- <?xml version="1.0" encoding="UTF-8"?>
- <beans xmlns="http://www.springframework.org/schema/beans"
- xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
- xmlns:tx="http://www.springframework.org/schema/tx"
- xmlns:context="http://www.springframework.org/schema/context"
- xsi:schemaLocation="http://www.springframework.org/schema/beans
- http://www.springframework.org/schema/beans/spring-beans-3.2.xsd
- http://www.springframework.org/schema/tx
- http://www.springframework.org/schema/tx/spring-tx-3.2.xsd
- http://www.springframework.org/schema/context
- http://www.springframework.org/schema/context/spring-context-3.2.xsd">
- <bean id="dataSource" class="com.alibaba.druid.pool.DruidDataSource" init-method="init" destroy-method="close">
- <property name="url" value="${jdbc.url}"/>
- <property name="username" value="${jdbc.username}"/>
- <property name="password" value="${jdbc.password}"/>
- <!-- 配置初始化大小、最小、最大 -->
- <property name="initialSize" value="1"/>
- <property name="minIdle" value="1"/>
- <property name="maxActive" value="20"/>
- <!-- 配置获取连接等待超时的时间 -->
- <property name="maxWait" value="60000"/>
- <!-- 配置间隔多久才进行一次检测,检测需要关闭的空闲连接,单位是毫秒 -->
- <property name="timeBetweenEvictionRunsMillis" value="60000"/>
- <!-- 配置一个连接在池中最小生存的时间,单位是毫秒 -->
- <property name="minEvictableIdleTimeMillis" value="300000"/>
- <property name="validationQuery" value="SELECT 'x'"/>
- <property name="testWhileIdle" value="true"/>
- <property name="testOnBorrow" value="false"/>
- <property name="testOnReturn" value="false"/>
- <!-- 打开PSCache,并且指定每个连接上PSCache的大小 -->
- <!-- PSCache(preparedStatement)对支持游标的数据库性能提升巨大,比如说Oracle/DB2/SQL Server,在mysql下建议关闭 -->
- <property name="poolPreparedStatements" value="false"/>
- <property name="maxPoolPreparedStatementPerConnectionSize" value="-1"/>
- <!-- 配置监控统计拦截的filters -->
- <property name="filters" value="wall,mergeStat"/>
- </bean>
- <bean id="txManager" class="org.springframework.jdbc.datasource.DataSourceTransactionManager">
- <property name="dataSource" ref="dataSource"/>
- </bean>
- <tx:annotation-driven transaction-manager="txManager"/>
- <context:component-scan base-package="com.msxf.sso"/>
- </beans>
5.在cas.properties中配置数据库参数
- #<<数据库元信息>>
- jdbc.url=jdbc:mysql://192.168.2.41:3306/turtle?useUnicode=true&characterEncoding=UTF8
- jdbc.username=turtle
- jdbc.password=turtle
6.将deployerConfigContext.xml中的primaryAuthenticationHandler注释掉(后面会实现一个自己的密码验证类,并给该bean命名为primaryAuthenticationHandler)。
- <!-- 取消默认的用户名和密码,改为我们自己从数据库查询的用户名和密码 -->
- <!--
- <bean id="primaryAuthenticationHandler" class="org.jasig.cas.authentication.AcceptUsersAuthenticationHandler">
- <property name="users">
- <map>
- <entry key="xuanyu" value="xuanyu"/>
- </map>
- </property>
- </bean>
- -->
7.实现自己的认证类
- package com.msxf.sso.authentication;
- import java.security.GeneralSecurityException;
- import javax.annotation.Resource;
- import javax.security.auth.login.FailedLoginException;
- import org.jasig.cas.authentication.HandlerResult;
- import org.jasig.cas.authentication.PreventedException;
- import org.jasig.cas.authentication.UsernamePasswordCredential;
- import org.jasig.cas.authentication.handler.support.AbstractUsernamePasswordAuthenticationHandler;
- import org.jasig.cas.authentication.principal.SimplePrincipal;
- import org.springframework.stereotype.Component;
- /**
- * 自定义的用户登录认证类
- * @create 2015-7-17 下午3:48:44
- * @author 玄玉<http://blog.youkuaiyun.com/jadyer>
- */
- @Component(value="primaryAuthenticationHandler")
- public class UserAuthenticationHandler extends AbstractUsernamePasswordAuthenticationHandler {
- @Resource
- private UserDaoJdbc userDaoJdbc;
- /**
- * 认证用户名和密码是否正确
- * @see UsernamePasswordCredential参数包含了前台页面输入的用户信息
- */
- @Override
- protected HandlerResult authenticateUsernamePasswordInternal(UsernamePasswordCredential transformedCredential) throws GeneralSecurityException, PreventedException {
- String username = transformedCredential.getUsername();
- String password = transformedCredential.getPassword();
- if(userDaoJdbc.verifyAccount(username, password)){
- return createHandlerResult(transformedCredential, new SimplePrincipal(username), null);
- }
- throw new FailedLoginException();
- }
- }
8.实现认证的Dao层
- package com.msxf.sso.authentication;
- import javax.annotation.Resource;
- import javax.sql.DataSource;
- import org.springframework.dao.EmptyResultDataAccessException;
- import org.springframework.jdbc.core.JdbcTemplate;
- import org.springframework.stereotype.Repository;
- @Repository
- public class UserDaoJdbc {
- private static final String SQL_VERIFY_ACCOUNT = "SELECT COUNT(*) FROM permission_operator WHERE operator_login=? AND operator_pwd=MD5(?)";
- private JdbcTemplate jdbcTemplate;
- @Resource
- public void setDataSource(DataSource dataSource){
- this.jdbcTemplate = new JdbcTemplate(dataSource);
- }
- /**
- * 验证用户名和密码是否正确
- * @create 2015-7-17 下午3:56:54
- * @author 玄玉<http://blog.youkuaiyun.com/jadyer>
- */
- public boolean verifyAccount(String username, String password){
- try{
- return 1==this.jdbcTemplate.queryForObject(SQL_VERIFY_ACCOUNT, new Object[]{username, password}, Integer.class);
- }catch(EmptyResultDataAccessException e){
- return false;
- }
- }
- }