spring-sercurity认证机制的核心组件
以下解释源自Spring | Home
SecurityContextHolder:Spring Security在SecurityContextHolder中存储身份验证者的详细信息。
SecurityContext:从SecurityContextHolder中获得,包含当前已认证用户的身份验证。
Authentication:可以是AuthenticationManager的输入,以提供用户为身份验证或SecurityContext中的当前用户提供的凭据。
GrantedAuthority:在身份验证上授予主体的权限(即角色、范围等)。
AuthenticationManager:定义Spring Security的过滤器如何执行身份验证的API。
ProviderManager:AuthenticationManager最常见的实现。
AuthenticationProvider:由ProviderManager用于执行特定类型的身份验证。
Request Credentials with AuthenticationEntryPoint:用于从客户端请求凭据(即重定向到登录页面,发送WWW-Authenticate响应等)。
AbstractAuthenticationProcessingFilter:用于身份验证的基本过滤器。
认证流程
结合上述内容,可以分析出认证的核心是AuthenticationManager,所以,我们需要自定义jwt的AuthenticationManager并将其注入到认证过滤器里面去。
认证实现
- 自定义认证管理器
- 配置spring-security
JwtAuthorizationManager.java
@Slf4j
@Component
public class JwtAuthorizationManager implements AuthorizationManager<RequestAuthorizationContext> {
@Autowired
private JwtUtil jwtUtil;
@Override
public AuthorizationDecision check(Supplier<Authentication> authentication,
RequestAuthorizationContext object) {
String requestURI = object.getRequest().getRequestURI();
log.info("身份认证:{}", requestURI);
//获取请求头里面的jwt令牌
HttpServletRequest httpServletRequest = object.getRequest();
String jwtToken = httpServletRequest.getHeader("Authorization");
if(StringUtils.isBlank(jwtToken)){
jwtToken = httpServletRequest.getHeader("authorization");
}
if(StringUtils.isBlank(jwtToken)){
return new AuthorizationDecision(false);
}
//检验jwt令牌
jwtToken = jwtToken.replace("bearer ", "");
if(!jwtUtil.checkJwt(jwtToken)){
return new AuthorizationDecision(false);
}
//解析jwt令牌
JwtUserDetails jwtUserDetails = jwtUtil.parseJwt(jwtToken);
if(ObjectUtils.isEmpty(jwtUserDetails)){
return new AuthorizationDecision(false);
}
//校验权限
//此处自由发挥即可
RequestMatcher requestMatcher = new AntPathRequestMatcher("/first/**");
requestMatcher.matches(httpServletRequest);
//构建authentication
BearerTokenAuthenticationToken token = new BearerTokenAuthenticationToken(jwtToken);
token.setDetails(jwtUserDetails);
token.setAuthenticated(true);
//设置securityContext
SecurityContext securityContext = SecurityContextHolder.getContext();
securityContext.setAuthentication(token);
return new AuthorizationDecision(true);
}
}
SecurityConfig.java
@Slf4j
@EnableWebSecurity
public class SecurityConfig {
@Autowired
private JwtAuthorizationManager jwtAuthorizationManager;
/**
* @description: securityFilterChain <br>
* @version: 1.0 <br>
* @create: 2023/3/31 9:39 <br>
* @param: http
* @return org.springframework.security.web.SecurityFilterChain
*/
@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
log.info("初始化自定义【securityFilterChain】配置");
//禁用跨域防护
http.csrf().disable();
//禁用session
http.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS);
//设置不需要身份验证的api
http.authorizeHttpRequests().regexMatchers("/login/*").permitAll();
//设置需要认证的api使用自定义的jwt身份验证管理器进行认证
http.authorizeHttpRequests().anyRequest().access(jwtAuthorizationManager);
return http.build();
}
}