SpringBoot(23)Shiro的授权

1.设置权限

参考shiro的快速入门

	1.filterMap.put("/user/add","perms[user:add]");
    2.filterMap.put("/user/update","perms[user:update]");
 @Bean
    public ShiroFilterFactoryBean getShiroFilterFactoryBean(@Qualifier("securityManager") DefaultWebSecurityManager securityManager){
        ShiroFilterFactoryBean shiroFilterFactoryBean = new ShiroFilterFactoryBean();

        //设置安全管理器
        shiroFilterFactoryBean.setSecurityManager(securityManager);

        /**
         * 添加shiro的内置过滤器:
         * anon:无需认证
         * authc:必须要认证
         * user:必须拥有记住我功能
         * perms: 拥有对某个资源权限才能访问
         * role:拥有某个角色权限才能访问
         *
         */

        Map<String, String> filterMap = new LinkedHashMap<>();
        filterMap.put("/user/add","perms[user:add]");
        filterMap.put("/user/update","perms[user:update]");
        filterMap.put("/user/*","authc");

        shiroFilterFactoryBean.setFilterChainDefinitionMap(filterMap);

        //设置请求登录
        shiroFilterFactoryBean.setLoginUrl("/tologin");

        return  shiroFilterFactoryBean;
    }

2.加入无权限的页面

1.无权限请求路径


    @RequestMapping("/unauth")
    @ResponseBody
    public String unauth(){
        return "未经授权无法访问";
    }

2.添加无权限页面

 1.shiroFilterFactoryBean.setUnauthorizedUrl("/unauth");
  @Bean
    public ShiroFilterFactoryBean getShiroFilterFactoryBean(@Qualifier("securityManager") DefaultWebSecurityManager securityManager){
        ShiroFilterFactoryBean shiroFilterFactoryBean = new ShiroFilterFactoryBean();

        //设置安全管理器
        shiroFilterFactoryBean.setSecurityManager(securityManager);

        /**
         * 添加shiro的内置过滤器:
         * anon:无需认证
         * authc:必须要认证
         * user:必须拥有记住我功能
         * perms: 拥有对某个资源权限才能访问
         * role:拥有某个角色权限才能访问
         *
         */

        Map<String, String> filterMap = new LinkedHashMap<>();
        filterMap.put("/user/add","perms[user:add]");
        filterMap.put("/user/update","perms[user:update]");
        filterMap.put("/user/*","authc");

        shiroFilterFactoryBean.setFilterChainDefinitionMap(filterMap);

        //设置请求登录
        shiroFilterFactoryBean.setLoginUrl("/tologin");
        shiroFilterFactoryBean.setUnauthorizedUrl("/unauth");

        return  shiroFilterFactoryBean;
    }

3.授权
当前用户在授权的方法中获取不了,只能在认证中获取,可以在认证时将用户传入

认证时将用户传入
return new SimpleAuthenticationInfo(user,user.getPwd(),"");
通过suject将用户取出
User currentUser = (User) subject.getPrincipal();
  @Override
    protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principalCollection) {
        System.out.println("授权");
        //获取令牌
        SimpleAuthorizationInfo info = new SimpleAuthorizationInfo();
        //拿到当前用户
        Subject subject = SecurityUtils.getSubject();
        User currentUser = (User) subject.getPrincipal();
        //授权:从数据库中获取权限信息并设置上去
        info.addStringPermission(currentUser.getPerms());
        return info;

    }
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值