新建springboot项目,导入依赖
<!-- ini整合方式的依赖 -->
<dependency>
<groupId>org.apache.shiro</groupId>
<artifactId>shiro-core</artifactId>
<version>1.9.0</version>
</dependency>
<dependency>
<groupId>commons-logging</groupId>
<artifactId>commons-logging</artifactId>
<version>1.2</version>
</dependency>
在src/main/java文件夹下,新建自定义realm类
package com.shrimpking.method3;
import org.apache.shiro.authc.AuthenticationException;
import org.apache.shiro.authc.AuthenticationInfo;
import org.apache.shiro.authc.AuthenticationToken;
import org.apache.shiro.authc.SimpleAuthenticationInfo;
import org.apache.shiro.authz.AuthorizationInfo;
import org.apache.shiro.authz.SimpleAuthorizationInfo;
import org.apache.shiro.realm.AuthorizingRealm;
import org.apache.shiro.subject.PrincipalCollection;
import org.apache.shiro.util.ByteSource;
/**
* Created by IntelliJ IDEA.
*
* @Author : Shrimpking
* @create 2023/10/2 18:04
* 使用md5加密的自定义realm类
*/
public class CustomerAuthRealm extends AuthorizingRealm
{
//授权
@Override
protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principalCollection)
{
//System.out.println("自定义授权");
//获取身份信息
String principle = principalCollection.getPrimaryPrincipal().toString();
System.out.println("身份信息" + principle);
//模拟从数据库根据用户获取角色和权限
SimpleAuthorizationInfo info = new SimpleAuthorizationInfo();
info.addRole("admin");
info.addRole("users");
//将数据库中的权限名称赋予
info.addStringPermission("user:*:*");
info.addStringPermission("product:*");
return info;
}
//认证
@Override
protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken authenticationToken) throws AuthenticationException
{
//获取身份信息
String principal = authenticationToken.getPrincipal().toString();
//获取凭证,模拟从数据库中获取
String password = "a141c47927929bc2d1fb6d336a256df4";
//加密盐
String salt = "abc";
//判断
if("zhangsan".equals(principal)){
//参数1,身份信息
//参数2,数据库中的密码
//参数3,加密盐
//参数4,realm的类名称
return new SimpleAuthenticationInfo(
principal,
password,
ByteSource.Util.bytes(salt),
getName()
);
}
return null;
}
}
在test目录下,新建测试类
package com.shrimpking;
import com.shrimpking.method3.CustomerAuthRealm;
import org.apache.shiro.SecurityUtils;
import org.apache.shiro.authc.AuthenticationToken;
import org.apache.shiro.authc.IncorrectCredentialsException;
import org.apache.shiro.authc.UnknownAccountException;
import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.authc.credential.HashedCredentialsMatcher;
import org.apache.shiro.mgt.DefaultSecurityManager;
import org.apache.shiro.subject.Subject;
import org.junit.jupiter.api.Test;
import org.springframework.boot.test.context.SpringBootTest;
import java.lang.reflect.Array;
import java.util.Arrays;
/**
* Created by IntelliJ IDEA.
*
* @Author : Shrimpking
* @create 2023/10/2 19:15
*/
@SpringBootTest
public class MethodThreeTest
{
@Test
public void test() {
//创建安全管理器
DefaultSecurityManager securityManager = new DefaultSecurityManager();
//创建自定义realm
CustomerAuthRealm customerAuthRealm = new CustomerAuthRealm();
//创建加密策略
HashedCredentialsMatcher matcher = new HashedCredentialsMatcher();
//设置加密策略
matcher.setHashAlgorithmName("md5");
//设置realm的加密策略
customerAuthRealm.setCredentialsMatcher(matcher);
//设置realm
securityManager.setRealm(customerAuthRealm);
//设置安全管理器
SecurityUtils.setSecurityManager(securityManager);
//获取用户主体
Subject subject = SecurityUtils.getSubject();
//创建令牌token
AuthenticationToken token = new UsernamePasswordToken("zhangsan", "1234");
//登录认证
try
{
System.out.println("认证前状态: " + subject.isAuthenticated());
subject.login(token);
System.out.println("登录成功");
System.out.println("认证后状态: " + subject.isAuthenticated());
}
catch (UnknownAccountException e)
{
e.printStackTrace();
System.out.println("认证结果:用户不存在");
}
catch (IncorrectCredentialsException e){
e.printStackTrace();
System.out.println("认证结果:密码错误");
}
//认证用户进行授权
if(subject.isAuthenticated()){
//基于角色进行控制
System.out.println("---------------------------------");
System.out.println("是否拥有角色admin = " + subject.hasRole("admin"));
//基于多角色
System.out.println("是否拥有多角色 = " + subject.hasAllRoles(Arrays.asList("admin","users")));
//
boolean[] booleans = subject.hasRoles(Arrays.asList("admin", "super", "users"));
for (boolean b : booleans)
{
System.out.println(b);
}
//基于权限字符串的访问控制
System.out.println("============================");
System.out.println("权限 = " + subject.isPermitted("user:update:*"));
System.out.println("权限 = " + subject.isPermitted("order:create"));
//分别具有哪些权限
boolean[] booleans1 = subject.isPermitted("user:*", "order:*");
for (boolean b : booleans1)
{
System.out.println(b);
}
//同时具有哪些权限
boolean permittedAll = subject.isPermittedAll("user:delete", "product:update");
System.out.println("同时权限:" + permittedAll);
}
}
}


305

被折叠的 条评论
为什么被折叠?



