成人在线亚洲_国产日韩视频一区二区三区_久久久国产精品_99国内精品久久久久久久

您的位置:首頁技術文章
文章詳情頁

Spring security 自定義過濾器實現Json參數傳遞并兼容表單參數(實例代碼)

瀏覽:142日期:2023-07-25 09:43:00

依賴

<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.projectlombok</groupId> <artifactId>lombok</artifactId> <optional>true</optional> </dependency> <dependency> <groupId>org.projectlombok</groupId> <artifactId>lombok</artifactId> <optional>true</optional> </dependency>配置安全適配類

基本配置和配置自定義過濾器

package com.study.auth.config.core; import com.study.auth.config.core.authentication.AccountAuthenticationProvider;import com.study.auth.config.core.authentication.MailAuthenticationProvider;import com.study.auth.config.core.authentication.PhoneAuthenticationProvider;import com.study.auth.config.core.filter.CustomerUsernamePasswordAuthenticationFilter;import com.study.auth.config.core.handler.CustomerAuthenticationFailureHandler;import com.study.auth.config.core.handler.CustomerAuthenticationSuccessHandler;import com.study.auth.config.core.handler.CustomerLogoutSuccessHandler;import com.study.auth.config.core.observer.CustomerUserDetailsService;import lombok.extern.slf4j.Slf4j;import org.springframework.beans.factory.annotation.Autowired;import org.springframework.context.annotation.Bean;import org.springframework.security.authentication.AuthenticationManager;import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;import org.springframework.security.config.annotation.web.builders.HttpSecurity;import org.springframework.security.config.annotation.web.builders.WebSecurity;import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;import org.springframework.security.web.authentication.AbstractAuthenticationProcessingFilter;import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter; /** * @Package: com.study.auth.config * @Description: <> * @Author: milla * @CreateDate: 2020/09/04 11:27 * @UpdateUser: milla * @UpdateDate: 2020/09/04 11:27 * @UpdateRemark: <> * @Version: 1.0 */@Slf4j@EnableWebSecuritypublic class WebSecurityConfig extends WebSecurityConfigurerAdapter { @Autowired private AccountAuthenticationProvider provider; @Autowired private MailAuthenticationProvider mailProvider; @Autowired private PhoneAuthenticationProvider phoneProvider; @Autowired private CustomerUserDetailsService userDetailsService; @Autowired private CustomerAuthenticationSuccessHandler successHandler; @Autowired private CustomerAuthenticationFailureHandler failureHandler; @Autowired private CustomerLogoutSuccessHandler logoutSuccessHandler; /** * 配置攔截器保護請求 * * @param http * @throws Exception */ @Override protected void configure(HttpSecurity http) throws Exception { //配置HTTP基本身份驗證//使用自定義過濾器-兼容json和表單登錄 http.addFilterBefore(customAuthenticationFilter(), UsernamePasswordAuthenticationFilter.class).httpBasic().and().authorizeRequests()//表示訪問 /setting 這個接口,需要具備 admin 這個角色.antMatchers('/setting').hasRole('admin')//表示剩余的其他接口,登錄之后就能訪問.anyRequest().authenticated().and().formLogin()//定義登錄頁面,未登錄時,訪問一個需要登錄之后才能訪問的接口,會自動跳轉到該頁面.loginPage('/noToken')//登錄處理接口-登錄時候訪問的接口地址.loginProcessingUrl('/account/login')//定義登錄時,表單中用戶名的 key,默認為 username.usernameParameter('username')//定義登錄時,表單中用戶密碼的 key,默認為 password.passwordParameter('password')////登錄成功的處理器//.successHandler(successHandler)////登錄失敗的處理器//.failureHandler(failureHandler)//允許所有用戶訪問.permitAll().and().logout().logoutUrl('/logout')//登出成功的處理.logoutSuccessHandler(logoutSuccessHandler).permitAll(); //關閉csrf跨域攻擊防御 http.csrf().disable(); } /** * 配置權限認證服務 * * @param auth * @throws Exception */ @Override protected void configure(AuthenticationManagerBuilder auth) throws Exception { //權限校驗-只要有一個認證通過即認為是通過的(有一個認證通過就跳出認證循環)-適用于多登錄方式的系統// auth.authenticationProvider(provider);// auth.authenticationProvider(mailProvider);// auth.authenticationProvider(phoneProvider); //直接使用userDetailsService auth.userDetailsService(userDetailsService).passwordEncoder(new BCryptPasswordEncoder()); } /** * 配置Spring Security的Filter鏈 * * @param web * @throws Exception */ @Override public void configure(WebSecurity web) throws Exception { //忽略攔截的接口 web.ignoring().antMatchers('/noToken'); } /** * 指定驗證manager * * @return * @throws Exception */ @Override @Bean public AuthenticationManager authenticationManagerBean() throws Exception { return super.authenticationManagerBean(); } /** * 注冊自定義的UsernamePasswordAuthenticationFilter * * @return * @throws Exception */ @Bean public AbstractAuthenticationProcessingFilter customAuthenticationFilter() throws Exception { AbstractAuthenticationProcessingFilter filter = new CustomerUsernamePasswordAuthenticationFilter(); filter.setAuthenticationSuccessHandler(successHandler); filter.setAuthenticationFailureHandler(failureHandler); //過濾器攔截的url要和登錄的url一致,否則不生效 filter.setFilterProcessesUrl('/account/login'); //這句很關鍵,重用WebSecurityConfigurerAdapter配置的AuthenticationManager,不然要自己組裝AuthenticationManager filter.setAuthenticationManager(authenticationManagerBean()); return filter; }}自定義過濾器

根據ContentType是否為json進行判斷,如果是就從body中讀取參數,進行解析,并生成權限實體,進行權限認證

否則直接使用UsernamePasswordAuthenticationFilter中的方法

package com.study.auth.config.core.filter; import com.fasterxml.jackson.databind.ObjectMapper;import com.study.auth.config.core.util.AuthenticationStoreUtil;import com.study.auth.entity.bo.LoginBO;import lombok.extern.slf4j.Slf4j;import org.springframework.http.MediaType;import org.springframework.security.authentication.UsernamePasswordAuthenticationToken;import org.springframework.security.core.Authentication;import org.springframework.security.core.AuthenticationException;import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter; import javax.servlet.http.HttpServletRequest;import javax.servlet.http.HttpServletResponse;import java.io.IOException;import java.io.InputStream; /** * @Package: com.study.auth.config.core.filter * @Description: <> * @Author: milla * @CreateDate: 2020/09/11 16:04 * @UpdateUser: milla * @UpdateDate: 2020/09/11 16:04 * @UpdateRemark: <> * @Version: 1.0 */@Slf4jpublic class CustomerUsernamePasswordAuthenticationFilter extends UsernamePasswordAuthenticationFilter { /** * 空字符串 */ private final String EMPTY = ''; @Override public Authentication attemptAuthentication(HttpServletRequest request, HttpServletResponse response) throws AuthenticationException { //如果不是json使用自帶的過濾器獲取參數 if (!request.getContentType().equals(MediaType.APPLICATION_JSON_UTF8_VALUE) && !request.getContentType().equals(MediaType.APPLICATION_JSON_VALUE)) { String username = this.obtainUsername(request); String password = this.obtainPassword(request); storeAuthentication(username, password); Authentication authentication = super.attemptAuthentication(request, response); return authentication; } //如果是json請求使用取參數邏輯 ObjectMapper mapper = new ObjectMapper(); UsernamePasswordAuthenticationToken authRequest = null; try (InputStream is = request.getInputStream()) { LoginBO account = mapper.readValue(is, LoginBO.class); storeAuthentication(account.getUsername(), account.getPassword()); authRequest = new UsernamePasswordAuthenticationToken(account.getUsername(), account.getPassword()); } catch (IOException e) { log.error('驗證失敗:{}', e); authRequest = new UsernamePasswordAuthenticationToken(EMPTY, EMPTY); } finally { setDetails(request, authRequest); Authentication authenticate = this.getAuthenticationManager().authenticate(authRequest); return authenticate; } } /** * 保存用戶名和密碼 * * @param username 帳號/郵箱/手機號 * @param password 密碼/驗證碼 */ private void storeAuthentication(String username, String password) { AuthenticationStoreUtil.setUsername(username); AuthenticationStoreUtil.setPassword(password); }}

其中會有body中的傳參問題,所以使用ThreadLocal傳遞參數

PS:枚舉類具備線程安全性

package com.study.auth.config.core.util; /** * @Package: com.study.auth.config.core.util * @Description: <使用枚舉可以保證線程安全> * @Author: milla * @CreateDate: 2020/09/11 17:48 * @UpdateUser: milla * @UpdateDate: 2020/09/11 17:48 * @UpdateRemark: <> * @Version: 1.0 */public enum AuthenticationStoreUtil { AUTHENTICATION; /** * 登錄認證之后的token */ private final ThreadLocal<String> tokenStore = new ThreadLocal<>(); /** * 需要驗證用戶名 */ private final ThreadLocal<String> usernameStore = new ThreadLocal<>(); /** * 需要驗證的密碼 */ private final ThreadLocal<String> passwordStore = new ThreadLocal<>(); public static String getUsername() { return AUTHENTICATION.usernameStore.get(); } public static void setUsername(String username) { AUTHENTICATION.usernameStore.set(username); } public static String getPassword() { return AUTHENTICATION.passwordStore.get(); } public static void setPassword(String password) { AUTHENTICATION.passwordStore.set(password); } public static String getToken() { return AUTHENTICATION.tokenStore.get(); } public static void setToken(String token) { AUTHENTICATION.tokenStore.set(token); } public static void clear() { AUTHENTICATION.tokenStore.remove(); AUTHENTICATION.passwordStore.remove(); AUTHENTICATION.usernameStore.remove(); }}實現UserDetailsService接口

package com.study.auth.config.core.observer; import lombok.extern.slf4j.Slf4j;import org.springframework.beans.factory.annotation.Autowired;import org.springframework.security.core.userdetails.User;import org.springframework.security.core.userdetails.UserDetails;import org.springframework.security.core.userdetails.UserDetailsService;import org.springframework.security.core.userdetails.UsernameNotFoundException;import org.springframework.security.crypto.password.PasswordEncoder;import org.springframework.stereotype.Component; /** * @Package: com.study.auth.config.core * @Description: <自定義用戶處理類> * @Author: milla * @CreateDate: 2020/09/04 13:53 * @UpdateUser: milla * @UpdateDate: 2020/09/04 13:53 * @UpdateRemark: <> * @Version: 1.0 */@Slf4j@Componentpublic class CustomerUserDetailsService implements UserDetailsService { @Autowired private PasswordEncoder passwordEncoder; @Override public UserDetails loadUserByUsername(String username) throws UsernameNotFoundException { //測試直接使用固定賬戶代替 return User.withUsername('admin').password(passwordEncoder.encode('admin')).roles('admin', 'user').build(); }} 登錄成功類

package com.study.auth.config.core.handler; import org.springframework.security.core.Authentication;import org.springframework.security.web.authentication.AuthenticationSuccessHandler;import org.springframework.stereotype.Component; import javax.servlet.ServletException;import javax.servlet.http.HttpServletRequest;import javax.servlet.http.HttpServletResponse;import java.io.IOException; /** * @Package: com.study.auth.config.core.handler * @Description: <登錄成功處理類> * @Author: milla * @CreateDate: 2020/09/08 17:39 * @UpdateUser: milla * @UpdateDate: 2020/09/08 17:39 * @UpdateRemark: <> * @Version: 1.0 */@Componentpublic class CustomerAuthenticationSuccessHandler implements AuthenticationSuccessHandler { @Override public void onAuthenticationSuccess(HttpServletRequest request, HttpServletResponse response, Authentication authentication) throws IOException, ServletException { HttpServletResponseUtil.loginSuccess(response); }} 登錄失敗

package com.study.auth.config.core.handler; import org.springframework.security.core.AuthenticationException;import org.springframework.security.web.authentication.AuthenticationFailureHandler;import org.springframework.stereotype.Component; import javax.servlet.ServletException;import javax.servlet.http.HttpServletRequest;import javax.servlet.http.HttpServletResponse;import java.io.IOException; /** * @Package: com.study.auth.config.core.handler * @Description: <登錄失敗操作類> * @Author: milla * @CreateDate: 2020/09/08 17:42 * @UpdateUser: milla * @UpdateDate: 2020/09/08 17:42 * @UpdateRemark: <> * @Version: 1.0 */@Componentpublic class CustomerAuthenticationFailureHandler implements AuthenticationFailureHandler { @Override public void onAuthenticationFailure(HttpServletRequest request, HttpServletResponse response, AuthenticationException exception) throws IOException, ServletException { HttpServletResponseUtil.loginFailure(response, exception); }} 登出成功類

package com.study.auth.config.core.handler; import org.springframework.security.core.Authentication;import org.springframework.security.web.authentication.logout.LogoutSuccessHandler;import org.springframework.stereotype.Component; import javax.servlet.ServletException;import javax.servlet.http.HttpServletRequest;import javax.servlet.http.HttpServletResponse;import java.io.IOException; /** * @Package: com.study.auth.config.core.handler * @Description: <登出成功> * @Author: milla * @CreateDate: 2020/09/08 17:44 * @UpdateUser: milla * @UpdateDate: 2020/09/08 17:44 * @UpdateRemark: <> * @Version: 1.0 */@Componentpublic class CustomerLogoutSuccessHandler implements LogoutSuccessHandler { @Override public void onLogoutSuccess(HttpServletRequest request, HttpServletResponse response, Authentication authentication) throws IOException, ServletException { HttpServletResponseUtil.logoutSuccess(response); }}返回值工具類

package com.study.auth.config.core.handler; import com.alibaba.fastjson.JSON;import com.study.auth.comm.ResponseData;import com.study.auth.constant.CommonConstant;import org.springframework.http.MediaType;import org.springframework.security.core.AuthenticationException; import javax.servlet.http.HttpServletResponse;import java.io.IOException;import java.io.PrintWriter; /** * @Package: com.study.auth.config.core.handler * @Description: <> * @Author: milla * @CreateDate: 2020/09/08 17:45 * @UpdateUser: milla * @UpdateDate: 2020/09/08 17:45 * @UpdateRemark: <> * @Version: 1.0 */public final class HttpServletResponseUtil { public static void loginSuccess(HttpServletResponse resp) throws IOException { ResponseData success = ResponseData.success(); success.setMsg('login success'); response(resp, success); } public static void logoutSuccess(HttpServletResponse resp) throws IOException { ResponseData success = ResponseData.success(); success.setMsg('logout success'); response(resp, success); } public static void loginFailure(HttpServletResponse resp, AuthenticationException exception) throws IOException { ResponseData failure = ResponseData.error(CommonConstant.EX_RUN_TIME_EXCEPTION, exception.getMessage()); response(resp, failure); } private static void response(HttpServletResponse resp, ResponseData data) throws IOException { //直接輸出的時候還是需要使用UTF-8字符集 resp.setContentType(MediaType.APPLICATION_JSON_UTF8_VALUE); PrintWriter out = resp.getWriter(); out.write(JSON.toJSONString(data)); out.flush(); }}

其他對象見Controller 層返回值的公共包裝類-避免每次都包裝一次返回-InitializingBean增強

至此,就可以傳遞Json參數了

Spring security 自定義過濾器實現Json參數傳遞并兼容表單參數(實例代碼)

到此這篇關于Spring security 自定義過濾器實現Json參數傳遞并兼容表單參數的文章就介紹到這了,更多相關Spring security 自定義過濾器內容請搜索好吧啦網以前的文章或繼續瀏覽下面的相關文章希望大家以后多多支持好吧啦網!

標簽: Spring
相關文章:
成人在线亚洲_国产日韩视频一区二区三区_久久久国产精品_99国内精品久久久久久久
欧美精品亚洲二区| 亚洲综合精品自拍| 日韩视频免费观看高清完整版在线观看 | 亚洲欧美偷拍三级| 亚洲国产精品激情在线观看| 国产调教视频一区| 国产亚洲视频系列| 国产精品欧美精品| 日韩一区日韩二区| 亚洲一区二区三区国产| 一区二区三区在线免费| 亚洲精品视频免费观看| 亚洲综合色自拍一区| 亚洲bt欧美bt精品| 日本欧美一区二区三区| 精品亚洲国内自在自线福利| 国产一区二区三区蝌蚪| 高清日韩电视剧大全免费| 成人免费黄色大片| 牛夜精品久久久久久久99黑人 | 欧美日韩aaaaaa| 欧美亚洲国产怡红院影院| 欧美日韩一区二区三区免费看| 欧美亚洲一区二区在线| 91精品国产黑色紧身裤美女| 2020国产精品久久精品美国| 国产精品美女一区二区三区| 亚洲人一二三区| 五月婷婷另类国产| 国产福利91精品一区二区三区| av在线不卡观看免费观看| 欧美视频官网| 色呦呦国产精品| 日韩欧美中文一区| 欧美国产禁国产网站cc| 国产黄人亚洲片| 91丨porny丨国产| 99久久久精品免费观看国产蜜| 国产综合欧美| 欧美91大片| 色婷婷亚洲精品| 日韩女优电影在线观看| 亚洲视频免费在线| 精品国内片67194| 亚洲日本在线天堂| 精品亚洲国内自在自线福利| 欧美一区二视频在线免费观看| 久久精品一区| 精品国产成人在线影院| 亚洲综合视频在线观看| 成人午夜碰碰视频| 在线一区亚洲| 日韩欧美在线123| 一区二区三区小说| 国产一区视频在线观看免费| 国产欧美一区二区三区另类精品 | 日韩亚洲欧美中文三级| 亚洲三级在线观看| 精品一区二区免费看| 欧美粗暴jizz性欧美20| 色成人在线视频| 精品成人一区二区三区| 青青青伊人色综合久久| 91浏览器入口在线观看| 久久综合伊人| 国产日韩欧美精品电影三级在线| 午夜影院在线观看欧美| youjizz久久| 久久五月天婷婷| 国产精品久久久一区麻豆最新章节| 美女一区二区视频| 亚洲国产精品一区二区第一页| 欧美日韩高清在线| 国产精品福利在线播放| 国产精品一级在线| 久久在线精品| 一区二区三区在线视频播放| 欧美阿v一级看视频| 欧美日韩激情在线| 亚洲不卡av一区二区三区| 成人国产精品免费观看视频| 欧美日韩在线播放| 石原莉奈在线亚洲三区| 亚洲大胆视频| 国产亚洲一区二区在线观看| 国产a区久久久| 欧美三级乱人伦电影| 亚洲永久免费视频| 在线观看一区视频| 久久―日本道色综合久久| 黑人巨大精品欧美一区| 久久午夜影视| 午夜精品久久久久久久久| 一区二区三区国产在线| 日韩美女视频19| 欧美午夜a级限制福利片| 欧美精品视频www在线观看 | 亚洲黄色免费| 国产精品传媒在线| 亚洲午夜精品久久| 日韩美女视频一区二区| 亚洲国产精品视频一区| 亚洲图片欧美激情| 色综合天天做天天爱| 久久天天做天天爱综合色| 成人av资源在线观看| 欧美v亚洲v综合ⅴ国产v| 久国产精品韩国三级视频| 精品视频1区2区| 日韩国产在线一| 欧美亚洲国产一卡| 久草中文综合在线| 欧美一区二区三区在| 国产成人免费xxxxxxxx| 日韩精品一区二区三区四区视频| 成人久久18免费网站麻豆| 精品久久久久久久久久久久包黑料 | jlzzjlzz欧美大全| 久久九九久久九九| 欧美午夜免费影院| 亚洲啪啪综合av一区二区三区| 伊人狠狠色j香婷婷综合| 一区二区激情小说| 色婷婷综合久久久中文一区二区| 午夜精品久久久久久久久| 欧美视频在线一区| 国产成人综合在线观看| 2019国产精品| 在线欧美三区| 热久久久久久久| 日韩欧美亚洲国产另类| 欧美在线三区| 亚洲精品久久7777| 欧美亚洲自拍偷拍| 成人一区在线看| 成人欧美一区二区三区小说| 亚洲免费在线| 国产一区二区三区电影在线观看| 欧美va亚洲va在线观看蝴蝶网| 亚洲欧美综合国产精品一区| 亚洲色图视频网站| 色婷婷久久综合| 成人av午夜影院| 亚洲码国产岛国毛片在线| 欧美性欧美巨大黑白大战| 99久久99精品久久久久久| 亚洲欧美aⅴ...| 欧美日韩一区二区欧美激情| 91网页版在线| 日韩综合小视频| 精品日韩在线一区| 99热免费精品在线观看| 成人在线视频首页| 亚洲国产成人av好男人在线观看| 制服丝袜av成人在线看| 在线播放不卡| 国产美女av一区二区三区| 成人app在线观看| 亚洲va中文字幕| 日韩av电影免费观看高清完整版在线观看| 欧美亚洲日本一区| 欧美三级不卡| 国产一区福利在线| 亚洲精品久久嫩草网站秘色| 日韩免费高清av| 一本色道久久综合亚洲91| 欧美日韩天堂| 国产真实乱子伦精品视频| 亚洲精品视频在线| 精品sm在线观看| 在线一区二区观看| 一区二区视频欧美| 成人av网站免费| 久久精品国产一区二区| 1024成人网| 精品久久久久久亚洲综合网| 在线观看网站黄不卡| 99视频+国产日韩欧美| 色综合天天天天做夜夜夜夜做| 精品一区二区免费| 亚洲图片欧美视频| 成人免费一区二区三区视频| 精品久久国产老人久久综合| 在线欧美小视频| 色综合激情五月| 99精品热视频只有精品10| 91麻豆6部合集magnet| 懂色av一区二区在线播放| 久久99久久久久久久久久久| 亚洲一区二区在线观看视频| 国产精品青草久久| 久久精品水蜜桃av综合天堂| 日韩视频免费观看高清完整版在线观看 | 亚洲国产视频在线| 亚洲乱码中文字幕| 亚洲欧美在线aaa| 国产精品日日摸夜夜摸av| 欧美xingq一区二区| 日韩欧美国产综合| 欧美大片免费久久精品三p|