shiro 用ajax方式登录

Xml代码   收藏代码
  1. <property name="filterChainDefinitions">  
  2.             <value>  
  3.                 /login/** = anon  
  4.             </value>  
  5. </property>  
 
 

 下马是java代码中要增加:

 

Java代码   收藏代码
  1. @RequestMapping(value = "/login")  
  2.     @ResponseBody  
  3.     public Object ajaxLogin(@RequestParam String username,  
  4.             @RequestParam String password, @RequestParam boolean rememberMe) {  
  5.         String ret="";  
  6.         Subject currentUser = SecurityUtils.getSubject();  
  7.         if (!currentUser.isAuthenticated()) {  
  8.             UsernamePasswordToken token = new UsernamePasswordToken(username,  
  9.                     password);  
  10.             token.setRememberMe(rememberMe);  
  11.             try {  
  12.                 currentUser.login(token);  
  13.                 ret = "{success:true,message:'登陆成功'}";  
  14.             } catch (UnknownAccountException ex) {  
  15.                 ret = "{success:false,message:'账号错误'}";  
  16.                 logger.debug(ret);  
  17.             } catch (IncorrectCredentialsException ex) {  
  18.                 ret = "{success:false,message:'密码错误'}";  
  19.                 logger.debug(ret);  
  20.             } catch (LockedAccountException ex) {  
  21.                 ret = "{success:false,message:'账号已被锁定,请与管理员联系'}";  
  22.                 logger.debug(ret);  
  23.             } catch (AuthenticationException ex) {  
  24.                 ret = "{success:false,message:'您没有授权'}";  
  25.                 logger.debug(ret);  
  26.             }  
  27.         }  
  28.         // 返回json数据  
  29.         return ret;  
  30.     }  
 

 

如果是html通过ajax请求,还需要加上跨域支持:

Xml代码   收藏代码
  1. <filter>  
  2.         <filter-name>accessFilter</filter-name>  
  3.         <filter-class>com.hotice.shequ.filter.AccessFilter</filter-class>  
  4.     </filter>  
  5.     <filter-mapping>  
  6.         <filter-name>accessFilter</filter-name>  
  7.         <url-pattern>/*</url-pattern>  
  8.     </filter-mapping>  

 

Java代码   收藏代码
  1. @Override  
  2.     public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse,    
  3.             FilterChain chain) throws IOException, ServletException {    
  4.             HttpServletResponse response = (HttpServletResponse) servletResponse;    
  5.             response.setHeader("Access-Control-Allow-Origin","*");  
  6.             response.setHeader("Access-Control-Allow-Headers""Origin, X-Requested-With, Content-Type, Accept");  
  7.             chain.doFilter(servletRequest, servletResponse);    
  8.                 
  9.     }    

 

使用 Shiro 进行 Ajax 登录需要在登录请求中添加一个特殊的请求头 `X-Requested-With: XMLHttpRequest`,以便服务器能够识别这是一个 Ajax 请求。在 Shiro 的配置文件中,需要配置一个自定义的 filter,用于处理 Ajax 请求的登录。 以下是一个示例代码,用于实现 Shiro Ajax 登录: 1. 配置 Shiro 的自定义 filter ``` public class AjaxLoginFilter extends FormAuthenticationFilter { @Override protected boolean isAccessAllowed(ServletRequest request, ServletResponse response, Object mappedValue) { if (request.getHeader("X-Requested-With") != null && request.getHeader("X-Requested-With").equals("XMLHttpRequest")) { return true; } return super.isAccessAllowed(request, response, mappedValue); } @Override protected boolean onAccessDenied(ServletRequest request, ServletResponse response) throws Exception { HttpServletResponse httpServletResponse = (HttpServletResponse) response; httpServletResponse.setStatus(HttpStatus.UNAUTHORIZED.value()); return false; } } ``` 2. 配置 Shiro 的过滤器链 ``` @Bean public ShiroFilterFactoryBean shiroFilterFactoryBean(SecurityManager securityManager) { ShiroFilterFactoryBean shiroFilterFactoryBean = new ShiroFilterFactoryBean(); shiroFilterFactoryBean.setSecurityManager(securityManager); Map<String, String> filterChainDefinitionMap = new LinkedHashMap<>(); filterChainDefinitionMap.put("/login", "anon"); filterChainDefinitionMap.put("/logout", "logout"); filterChainDefinitionMap.put("/**", "authc"); shiroFilterFactoryBean.setFilterChainDefinitionMap(filterChainDefinitionMap); Map<String, Filter> filters = new HashMap<>(); filters.put("authc", new AjaxLoginFilter()); shiroFilterFactoryBean.setFilters(filters); return shiroFilterFactoryBean; } ``` 3. 在前端发送 Ajax 请求时添加特殊请求头,以便服务器能够识别这是一个 Ajax 请求 ``` $.ajax({ type: 'POST', url: '/login', beforeSend: function(xhr) { xhr.setRequestHeader('X-Requested-With', 'XMLHttpRequest'); }, data: {username: 'admin', password: 'admin'}, success: function(data) { console.log(data); }, error: function(xhr, status, error) { console.log(xhr); } }); ```
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值