import java.util.Date;
import java.util.HashMap;
import java.util.Map;
import java.util.UUID;
import javax.crypto.SecretKey;
import javax.crypto.spec.SecretKeySpec;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import org.apache.commons.lang3.StringUtils;
import org.apache.tomcat.util.codec.binary.Base64;
import com.dominos.cloud.common.enums.ResultMsg;
import com.dominos.cloud.common.exception.DominosRunTimeException;
import com.dominos.cloud.common.helper.RedisManager;
import com.dominos.cloud.common.util.ConstantsUtil;
import io.jsonwebtoken.Claims;
import io.jsonwebtoken.JwtBuilder;
import io.jsonwebtoken.Jwts;
import io.jsonwebtoken.SignatureAlgorithm;
import lombok.extern.slf4j.Slf4j;
@Slf4j
public class JwtUtil {
public static final String JWT_ID = UUID.randomUUID().toString();
/**
* 加密密文
*/
public static final String JWT_SECRET = "XXX";
public static final String JWT_ISSUER = "XXX";
public static final String JWT_SUBJECT= "XXX";
//jwt 的缓存时间
public static final int JWT_TTL = 60 * 1000 ; //millisecond
//老的jwt缓存10秒
public static final int OLD_JWT_TTL = 10;
public static final String OLD_JWT_KEY = "old_";
public static final String NEW_JWT_KEY = "new_";
public static final String USER_JWT_KEY = "user_jwt_";
public static final byte[] bt = new byte[] {};
/**
* 由字符串生成加密key
*
* @return
*/
public static SecretKey generalKey() {
String stringKey = JWT_SECRET;
// 本地的密码解码
byte[] encodedKey = Base64.decodeBase64(stringKey);
// 根据给定的字节数组使用AES加密算法构造一个密钥
SecretKey key = new SecretKeySpec(encodedKey, 0, encodedKey.length, "AES");
return key;
}
/**
* 创建jwt
* @param id
* @param issuer
* @param subject
* @param ttlMillis
* @return
* @throws Exception
*/
public static String createJWT(String id) throws Exception {
return createJWT(id, JWT_ISSUER, JWT_SUBJECT, JWT_TTL);
}
/**
* 创建jwt
* @param id
* @param issuer
* @param subject
* @param ttlMillis
* @return
* @throws Exception
*/
public static String createJWT(RedisManager redisManager,String id) throws Exception {
String jwt = createJWT(id, JWT_ISSUER, JWT_SUBJECT, JWT_TTL);
//每次格局用户id存储最近的一次jwt
String rs = redisManager.set(USER_JWT_KEY+id, jwt);
log.info(" redisManager.set {} 结果:{}",jwt,rs);
return jwt ;
}
/**
* 创建jwt
* @param id
* @param issuer
* @param subject
* @param ttlMillis
* @return
* @throws Exception
*/
public static String createJWT(String id, String issuer, String subject, long ttlMillis) throws Exception {
// 指定签名的时候使用的签名算法,也就是header那部分,jjwt已经将这部分内容封装好了。
SignatureAlgorithm signatureAlgorithm = SignatureAlgorithm.HS256;
// 生成JWT的时间
long nowMillis = System.currentTimeMillis();
Date now = new Date(nowMillis);
// 创建payload的私有声明(根据特定的业务需要添加,如果要拿这个做验证,一般是需要和jwt的接收方提前沟通好验证方式的)
Map<String, Object> claims = new HashMap<>();
//claims.put("uid", "123456");
//claims.put("user_name", "admin");
//claims.put("nick_name", "X-rapido");
// 生成签名的时候使用的秘钥secret,切记这个秘钥不能外露哦。它就是你服务端的私钥,在任何场景都不应该流露出去。
// 一旦客户端得知这个secret, 那就意味着客户端是可以自我签发jwt了。
SecretKey key = generalKey();
// 下面就是在为payload添加各种标准声明和私有声明了
JwtBuilder builder = Jwts.builder() // 这里其实就是new一个JwtBuilder,设置jwt的body
.setClaims(claims) // 如果有私有声明,一定要先设置这个自己创建的私有的声明,这个是给builder的claim赋值,一旦写在标准的声明赋值之后,就是覆盖了那些标准的声明的
.setId(id) // 设置jti(JWT ID):是JWT的唯一标识,根据业务需要,这个可以设置为一个不重复的值,主要用来作为一次性token,从而回避重放攻击。
.setIssuedAt(now) // iat: jwt的签发时间
.setIssuer(issuer) // issuer:jwt签发人
.setSubject(subject) // sub(Subject):代表这个JWT的主体,即它的所有人,这个是一个json格式的字符串,可以存放什么userid,roldid之类的,作为什么用户的唯一标志。
.signWith(signatureAlgorithm, key); // 设置签名使用的签名算法和签名使用的秘钥
// 设置过期时间
if (ttlMillis >= 0) {
long expMillis = nowMillis + ttlMillis;
Date exp = new Date(expMillis);
builder.setExpiration(exp);
}
String jwt = builder.compact();
return jwt ;
}
/**
* 解密jwt
*
* @param jwt
* @return
* @throws Exception
*/
public static Claims parseJWT(String jwt) throws Exception {
SecretKey key = generalKey(); //签名秘钥,和生成的签名的秘钥一模一样
Claims claims = Jwts.parser() //得到DefaultJwtParser
.setSigningKey(key) //设置签名的秘钥
.parseClaimsJws(jwt).getBody(); //设置需要解析的jwt
return claims;
}
/**
* 验证档次请求是否可用, 这里header authorization,是独存,独校验。跟其他无关
* @param redisManager 可替换本地缓存
* @param httpServletRequest
* @param httpServletResponse
* @return
*/
public static boolean jwtValidate(RedisManager redisManager,HttpServletRequest httpServletRequest,HttpServletResponse httpServletResponse) {
String jwtKey = ConstantsUtil.Common.AUTHORIZATION;
//jwt Id
String jwt = httpServletRequest.getHeader(jwtKey);
//老的
String oldJwtKey = OLD_JWT_KEY+jwt;
if(StringUtils.isBlank(jwt)) {
return false;
}
try {
Claims parseJWT = JwtUtil.parseJWT(jwt);
if(parseJWT != null) {
return true;
}
} catch (io.jsonwebtoken.ExpiredJwtException e) {
/**
* 分几种情况
* 1.正常超时(服务端token时间到):重新生成一个新的token给前端,下次带新的token过来
* 2.非正常超时(用户隔了很长时间没有时间):重新生成一个新的token给前端,下次带新的token过来
* 3.并发情况考虑(当超时,第一个请求,第二个请求会同时过来)
* 4.同一用户多方登陆:目前只允许同一个用户一方登陆。多方登陆支持。这里只校验jwt失效问题。
*
*
*/
try {
Claims c = e.getClaims();
String id = c.getId();
String subject = c.getSubject();
String issuer = c.getIssuer();
String lastJwtKey = USER_JWT_KEY+id;
//先判断是否是最近的一次jwt,如果不是最新的jwt,返回false
String redisLastJwtVal = redisManager.get(lastJwtKey, String.class);
if(!jwt.equals(redisLastJwtVal)) {
log.error("当前访问的jwt不是最新的:{}",redisLastJwtVal);
return false;
}
log.info("jwt 超时 {}",jwt);
//当存在鬓发请求时 如果老的jwtId存在.解决同一页面并发请求
if(redisManager.setnx(oldJwtKey, "", OLD_JWT_TTL) != 1) {
return true;
}
//从新生成jwt id
String sessionId = JwtUtil.createJWT(id.toString(), issuer,subject, JwtUtil.JWT_TTL);
//TODO设置新的 sessionId 到httpServletResponse, Header 中 返回给前端用
//TODO设置新的 sessionId 到 httpServletRequest 给后面的程序用
httpServletResponse.setHeader(jwtKey, sessionId);
//记录最后一次jwt
redisManager.set(lastJwtKey,sessionId);
return true;
}
catch (Exception e1) {
log.error(e1.getMessage(),e1);
}
}catch (Exception e) {
log.error(e.getMessage(),e);
throw new DominosRunTimeException(ResultMsg.USER_LOGIN_INVALID);
}
return false;
}
/*
public static void main(String[] args) {
try {
String jwt = createJWT(JWT_ID, "userName", "userName", JWT_TTL);
System.out.println("JWT:" + jwt);
System.out.println("\n解密\n");
Claims c = parseJWT(jwt);
System.out.println(c.getId());
System.out.println(c.getIssuedAt());
System.out.println(c.getSubject());
System.out.println(c.getIssuer());
System.out.println(c.get("uid", String.class));
}catch (ExpiredJwtException ee) {
System.out.println("超时了>>>>>>>>>>>>>>");
Claims c = ee.getClaims();
System.out.println(c.getId());
System.out.println(c.getIssuedAt());
System.out.println(c.getSubject());
System.out.println(c.getIssuer());
System.out.println(c.get("uid", String.class));
}
catch (Exception e) {
e.printStackTrace();
}
}*/
}
if(!JwtUtil.jwtValidate(httpServletRequest, httpServletResponse)) {
Log.error("url : {} jwt 解析失败 >>>>>>>>>>>>>>>",url);
return false;
}
public class JwtInterceptor implements HandlerInterceptor {
@Autowired
private RedisManager redisManager;
/**
* 处理请求之前拦截
*
* @param httpServletRequest
* @param httpServletResponse
* @param o
* @return
* @throws Exception
*/
@Override
public boolean preHandle(HttpServletRequest httpServletRequest, HttpServletResponse httpServletResponse, Object o) {
return JwtUtil.jwtValidate(redisManager,httpServletRequest, httpServletResponse);
}
@Override
public void postHandle(HttpServletRequest httpServletRequest, HttpServletResponse httpServletResponse, Object o, ModelAndView modelAndView) {
}
@Override
public void afterCompletion(HttpServletRequest httpServletRequest, HttpServletResponse httpServletResponse, Object o, Exception e) {
}
}
public class JwtFilter implements javax.servlet.Filter {
@Autowired
private RedisManager redisManager;
@Override
public void destroy() {
}
@Override
public void doFilter(ServletRequest request, ServletResponse response,
FilterChain chain) throws IOException, ServletException {
HttpServletRequest httpServletRequest = (HttpServletRequest) request;
HttpServletResponse httpServletResponse = (HttpServletResponse) request;
MutableHttpServletRequestWrapper mutableRequest = new MutableHttpServletRequestWrapper(httpServletRequest);
JwtUtil.jwtValidate(redisManager,httpServletRequest, httpServletResponse);
chain.doFilter(mutableRequest, response);
}
@Override
public void init(FilterConfig filterConfig) throws ServletException {
}
}
登陆成功后
try {
String authorization = JwtUtil.createJWT(redisManager,user.getId().toString());
response.setHeader(ConstantsUtil.Common.AUTHORIZATION, authorization);
} catch (Exception e) {
log.error(e.getMessage(), e);
}