shiro实战(一)

1.使用shiro.ini作为Realm

1.所需依赖包

<dependencies>
    <dependency>
        <groupId>org.apache.shiro</groupId>
        <artifactId>shiro-core</artifactId>
        <version>1.2.4</version>
    </dependency>

    <dependency>
        <groupId>org.slf4j</groupId>
        <artifactId>slf4j-log4j12</artifactId>
        <version>1.7.12</version>
    </dependency>
  </dependencies>

2.主方法

package zx.java.shiro;

import org.apache.shiro.SecurityUtils;
import org.apache.shiro.authc.AuthenticationException;
import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.config.IniSecurityManagerFactory;
import org.apache.shiro.subject.Subject;
import org.apache.shiro.util.Factory;
import org.apache.shiro.mgt.SecurityManager;

public class HelloWorld {

    public static void main(String[] args) {
        //读取配置文件,初始化工厂
        Factory<SecurityManager> factory =
                new IniSecurityManagerFactory("classpath:shiro.ini");
        //创建securityManager
        SecurityManager securityManager = factory.getInstance();
        //将securityManager注入securityUtils
        SecurityUtils.setSecurityManager(securityManager);
        //得到当前用户
        Subject currentUser = SecurityUtils.getSubject();
        //创建认证的token
        UsernamePasswordToken token=new UsernamePasswordToken("java1234","123456");

        try {
            currentUser.login(token);
            System.out.println("身份认证成功!");
        } catch (AuthenticationException e) {
            System.out.println("身份认证失败!");
            e.printStackTrace();
        }
        currentUser.logout();

    }

}

3.shiro.ini

[users]
java1234=123456
jack=123
2.使用jdbc_realm

1.所需依赖包

<dependencies>
    <dependency>
        <groupId>org.apache.shiro</groupId>
        <artifactId>shiro-core</artifactId>
        <version>1.2.4</version>
    </dependency>

    <dependency>
        <groupId>org.slf4j</groupId>
        <artifactId>slf4j-log4j12</artifactId>
        <version>1.7.12</version>
    </dependency>

    <dependency>
        <groupId>c3p0</groupId>
        <artifactId>c3p0</artifactId>
        <version>0.9.1.2</version>
    </dependency>

    <dependency>
        <groupId>commons-logging</groupId>
        <artifactId>commons-logging</artifactId>
        <version>1.2</version>
    </dependency>

    <dependency>
        <groupId>mysql</groupId>
        <artifactId>mysql-connector-java</artifactId>
        <version>5.1.37</version>
    </dependency>
  </dependencies>

2.jdbc_realm.ini

[main]
jdbcRealm=org.apache.shiro.realm.jdbc.JdbcRealm

dataSource=com.mchange.v2.c3p0.ComboPooledDataSource
dataSource.driverClass=com.mysql.jdbc.Driver
dataSource.jdbcUrl=jdbc:mysql://localhost:3306/db_shiro
dataSource.user=root
dataSource.password=root

jdbcRealm.dataSource=$dataSource
securityManager.realms=$jdbcRealm

#默认对应数据库db_shiro中的users表

3.主方法

package zx.java.shiro;

import org.apache.shiro.SecurityUtils;
import org.apache.shiro.authc.AuthenticationException;
import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.config.IniSecurityManagerFactory;
import org.apache.shiro.subject.Subject;
import org.apache.shiro.util.Factory;
import org.apache.shiro.mgt.SecurityManager;

public class HelloWorld {

    public static void main(String[] args) {
        //读取配置文件,初始化工厂
        Factory<SecurityManager> factory =
                new IniSecurityManagerFactory("classpath:jdbc_realm.ini");
        //创建securityManager
        SecurityManager securityManager = factory.getInstance();
        //将securityManager注入securityUtils
        SecurityUtils.setSecurityManager(securityManager);
        //得到当前用户
        Subject currentUser = SecurityUtils.getSubject();
        //创建认证的token
        UsernamePasswordToken token=new UsernamePasswordToken("jack","123");

        try {
            currentUser.login(token);
            System.out.println("身份认证成功!");
        } catch (AuthenticationException e) {
            System.out.println("身份认证失败!");
            e.printStackTrace();
        }
        currentUser.logout();   
    }
}
3.角色验证

1.依赖包

<dependencies>
      <dependency>
        <groupId>org.apache.shiro</groupId>
        <artifactId>shiro-core</artifactId>
        <version>1.2.4</version>
    </dependency>

    <dependency>
        <groupId>org.slf4j</groupId>
        <artifactId>slf4j-log4j12</artifactId>
        <version>1.7.12</version>
    </dependency>

    <dependency>
        <groupId>c3p0</groupId>
        <artifactId>c3p0</artifactId>
        <version>0.9.1.2</version>
    </dependency>

    <dependency>
        <groupId>commons-logging</groupId>
        <artifactId>commons-logging</artifactId>
        <version>1.2</version>
    </dependency>

    <dependency>
        <groupId>mysql</groupId>
        <artifactId>mysql-connector-java</artifactId>
        <version>5.1.37</version>
    </dependency>

    <dependency>
        <groupId>junit</groupId>
        <artifactId>junit</artifactId>
        <version>4.12</version>
    </dependency>
  </dependencies>

2.shiro_role.ini

[users]
java1234=123456,role1,role2,role3
jack=123,role1

3.shiroUtil用于验证用户登录(首先需要通过身份验证才能接着进行角色认证和权限认证)

package zx.java.shiro.common;

import org.apache.shiro.SecurityUtils;
import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.config.IniSecurityManagerFactory;
import org.apache.shiro.subject.Subject;
import org.apache.shiro.util.Factory;
import org.apache.shiro.mgt.SecurityManager;

public class ShiroUtil {

    public static Subject login(String configFile,String username,String password){
        //读取配置文件初始化工厂
        Factory<SecurityManager> factory=
                new IniSecurityManagerFactory(configFile);
        //创建securityManager
        SecurityManager securityManager = factory.getInstance();
        //将securityManager注入securityUtils
        SecurityUtils.setSecurityManager(securityManager);
        //获取subject
        Subject subject = SecurityUtils.getSubject();
        //创建token
        UsernamePasswordToken token = new UsernamePasswordToken(username,password);
        //身份认证
        try{
            subject.login(token);
            System.out.println("身份认证成功!");
        }catch(Exception e){
            e.printStackTrace();
            System.out.println("身份认证失败!");
        }
        return subject;

    }

}

4.roleTest.java

package zx.java.shiro;

import java.util.Arrays;

import org.apache.shiro.subject.Subject;
import org.junit.Test;

import zx.java.shiro.common.ShiroUtil;

public class RoleTest {

    @Test
    public void testHasRole(){
        Subject subject = ShiroUtil.login("classpath:shiro_role.ini", "jack", "123");

        System.out.println(subject.hasRole("role1")?"有role1":"没有role1");
        boolean[] result = subject.hasRoles(Arrays.asList("role1","role2"));
        System.out.println(result[0]?"有role1":"没有role1");
        System.out.println(result[1]?"有role2":"没有role2");

        System.out.println(subject.hasAllRoles(Arrays.asList("role1","role2"))?"role1和role2都有":"role1和role2不都有");

    }
}
4.权限验证

1.依赖包同上
2.shiro_permission.ini

[users]
java1234=123456,role1,role2
jack=123,role1
[roles]
role1=user:select
role2=user:update,user:delete,user:add

3.PermissionTest.java

package zx.java.shiro;

import org.apache.shiro.subject.Subject;
import org.junit.Test;

import zx.java.shiro.common.ShiroUtil;

public class PermissionTest {

    @Test
    public void testIsPermitted(){
        Subject currentUser = ShiroUtil.login("classpath:shiro_permission.ini", "jack", "123");

        System.out.println(currentUser.isPermitted("user:select")?"拥有user:select权限":"没有user:select权限");
        System.out.println(currentUser.isPermitted("user:update")?"拥有user:update权限":"没有user:update权限");
        System.out.println(currentUser.isPermitted("user:add")?"拥有user:add权限":"没有user:add权限");

        boolean[] results = currentUser.isPermitted("user:select","user:update","user:add");
        System.out.println(results[0]?"拥有user:select权限":"没有user:select权限");
        System.out.println(results[1]?"拥有user:update权限":"没有user:update权限");
        System.out.println(results[2]?"拥有user:add权限":"没有user:add权限");

        System.out.println(currentUser.isPermittedAll("user:select","user:update","user:add")?"拥有user:select,updata,add权限":"并不拥有所有的权限");

    }
}
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值