shiro 用户权限管理(2)-----注册md5加密,登录验证

register.jsp注册页面:

 <body>
    <form action="<%=basePath%>/main/add" method="post">
    <ul>
        <li>姓 名:<input type="text" name="account" /> </li>
        <li>密 码:<input type="text" name="password" /> </li>
        <li>昵 称:<input type="text" name="nickname" /> </li>
        <li><input type="submit" value="注册" /> </li>
    </ul>
    </form>
  </body>

注册页面controller:

@RequestMapping("main")
@Controller
public class RegisterController {

    @Autowired
    private UserService userService;
    @RequestMapping("register")
    public String registerUser(){
        return "system/user/register";
    }

    /**
     * 注册方法,注册时对密码进行 MD5算法加密
     * @param user
     * @return
     */
    @RequestMapping(value = "add",method= RequestMethod.POST)
    @ResponseBody
    public boolean register(User user){
        String password=new SimpleHash("MD5",user.getPassword(),user.getAccount(),2).toHex();
        user.setPassword(password);
        Role role=new Role();
        role.setId((long) 2);
        Set<Role> roles=new HashSet<Role>();
        roles.add(role);
        user.setRoles(roles) ;
        return userService.insert(user);
    }
}

login.jsp页面:

<body>
<form action="<%=basePath%>/login" method="post">
<ul>
 <li>姓 名:<input type="text" name="account" /> </li>
 <li>密 码:<input type="text" name="password" /> </li>
 <li>验证码:<input type="text" name="validateCode" /> 
  <img id="validateCodeImg" src=<%=basePath%>/validateCode"/> 
     <a href="#" onclick="javascript:reloadValidateCode();">看不清?</a></li>
        <li><input type="submit" value="确认" /> </li>
    </ul>
    </form>
  </body>

登录页面controller:

@Controller
public class LoginController {

@RequestMapping(value = "/login" ,method=RequestMethod.POST,
        produces={"application/json;charset=UTF-8"})
public String login(User currUser,HttpSession session, HttpServletRequest request){
    String code = (String) session.getAttribute("validateCode");
    String submitCode = WebUtils.getCleanParam(request, "validateCode");
    if (StringUtils.isEmpty(submitCode) || !StringUtils.equals(code,submitCode.toLowerCase())) {
        return "redirect:/";
    }
    Subject user = SecurityUtils.getSubject();
    UsernamePasswordToken token = new UsernamePasswordToken(currUser.getAccount(),
            currUser.getPassword());
    token.setRememberMe(true);
    try {
        user.login(token);
        return "/system/main";
    }catch (AuthenticationException e) {
        token.clear();
        return "redirect:/";
    }
}

/**
 * 生成验证码
 * @param request
 * @param response
 * @throws IOException
 */
@RequestMapping(value = "/validateCode")
public void validateCode(HttpServletRequest request, HttpServletResponse response)
        throws IOException {
    response.setHeader("Cache-Control", "no-cache");
    String verifyCode = ValidateCode.generateTextCode(ValidateCode.TYPE_NUM_ONLY,4,null);
    request.getSession().setAttribute("validateCode", verifyCode);
    response.setContentType("image/jpeg");
    BufferedImage bim = ValidateCode.generateImageCode(verifyCode, 90, 30, 3, true,
            Color.WHITE, Color.BLACK, null);
    ImageIO.write(bim, "JPEG", response.getOutputStream());
}
}

登录验证:自定义ShiroDbRealm类

public class ShiroDbRealm extends AuthorizingRealm{
    @Resource(name="userService")
    private IUserService userService;
    protected AuthorizationInfo doGetAuthorizationInfo(
            PrincipalCollection principals) {
        SimpleAuthorizationInfo info = new SimpleAuthorizationInfo();
        //获取当前登录的用户名
        String account = (String) super.getAvailablePrincipal(principals);

        List<String> roles = new ArrayList<String>();  
        List<String> permissions = new ArrayList<String>();
        User user = userService.getByAccount(account);
        if(user != null){
            if (user.getRoles() != null && user.getRoles().size() > 0) {
        for (Role role : user.getRoles()) {
        roles.add(role.getName());
        if (role.getPmss() != null && role.getPmss().size() > 0) {
        for (Permission pmss : role.getPmss()) {
        if(!StringUtils.isEmpty(pmss.getPermission())){
    permissions.add(pmss.getPermission());
                            }
                        }
                    }
                }
            }
        }else{
            throw new AuthorizationException();
        }
        //给当前用户设置角色
        info.addRoles(roles);
        //给当前用户设置权限
        info.addStringPermissions(permissions); 
        return info;

    }
/**
     *  认证回调函数,登录时调用.
     */
    protected AuthenticationInfo doGetAuthenticationInfo(
            AuthenticationToken authcToken) throws AuthenticationException {
        UsernamePasswordToken token = (UsernamePasswordToken) authcToken;
    User user = userService.getByAccount(token.getUsername());
    if (user != null) {
    Object principal=token.getUsername();
    String credentials=user.getPassword();
    String realName=getName();//暂时不太明白这个什么意思
    ByteSource credentialsSalt=ByteSource.Util.bytes(user.getAccount());
        SimpleAuthenticationInfo info=new SimpleAuthenticationInfo(principal,credentials,
                    credentialsSalt,realName);
            return info;
        } else {
            return null;
        }
    }
  • 2
    点赞
  • 7
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值