第四步:整合SpringSecurity和JWT(实现认证和授权)

1 添加依赖
<!--SpringSecurity依赖配置-->
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>
<!--Hutool Java工具包-->
<dependency>
    <groupId>cn.hutool</groupId>
    <artifactId>hutool-all</artifactId>
    <version>4.5.7</version>
</dependency>
<!--JWT(Json Web Token)登录支持-->
<dependency>
    <groupId>io.jsonwebtoken</groupId>
    <artifactId>jjwt</artifactId>
    <version>0.9.0</version>
</dependency>
2 添加JWT常用操作的工具类
package com.hzf.mymall.common;

import io.jsonwebtoken.Claims;
import io.jsonwebtoken.Jwts;
import io.jsonwebtoken.SignatureAlgorithm;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import org.springframework.beans.factory.annotation.Value;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.stereotype.Component;

import java.util.Date;
import java.util.HashMap;
import java.util.Map;

/**
 * @author:010980380
 * @date:2020-10-28
 * @verison:1.0.0
 * @description:JwtToken生成的工具类
 */
@Component
public class JwtTokenUtils {
   

    private static final Logger LOGGER = LoggerFactory.getLogger(JwtTokenUtils.class);
    private static final String CLAIM_KEY_USERNAME = "sub";
    private static final String CLAIM_KEY_CREATED = "create";

    @Value("${jwt.secret}")
    private String secret;

    @Value("${jwt.expiration}")
    private Long expiration;

    /**
     * 根据负载生成JWT的token
     * @param claims 负载
     * @return String
     * @author huangzifan
     * @since 2020-10-28 9:13
     */
    private String generateToken(Map<String,Object> claims){
   
        return Jwts.builder()
                .setClaims(claims)
                .setExpiration(generateExpirationDate())
                .signWith(SignatureAlgorithm.HS512,secret)
                .compact();
    }

    /**
     * 从token中获取JWT的负载
     * @param token
     * @return Claims
     * @author huangzifan
     * @since 2020-10-28 9:16
     */
    private Claims getClaimsFromToken(String token){
   
        Claims claims = null;
        try{
   
            claims = Jwts.parser()
                    .setSigningKey(secret)
                    .parseClaimsJws(token)
                    .getBody();
        }catch (Exception e){
   
            LOGGER.info("JWT格式验证失败:{}",token);
        }
        return claims;
    }

    /**
     * 生成token的过期时间
     * @return Date
     * @author huangzifan
     * @since 2020-10-28 9:18
     */
    private Date generateExpirationDate(){
   
        return new Date(System.currentTimeMillis()+expiration*1000);
    }

    /**
     * 从token中获取登录用户名
     * @param token 客户端传入的token
     * @return String
     * @author huangzifan
     * @since 2020-10-28 9:21
     */
    private String getUserNameFromToken(String token){
   
        String username;
        try{
   
            Claims claims = getClaimsFromToken(token);
            username = claims.getSubject();
        }catch (Exception e){
   
            username = null;
        }
        return username;
    }

    /**
     * 验证token是否还有效
     * @param token 客户端传入的token
     * @param userDetails 从数据库查询出的用户信息
     * @return boolean
     * @author huangzifan
     * @since 2020-10-28 9:22
     */
    private boolean validateToken(String token, UserDetails userDetails){
   
        String username = getUserNameFromToken(token);
        return username.equals(userDetails.getUsername()) && !isTokenExpired(token);
    }

    /**
     * 判断token是否已经失效
     * @param token  
     * @return boolean
     * @author huangzifan
     * @since 2020-10-28 9:23
     */
    private boolean isTokenExpired(String token){
   
        Date expiredDate = getExpiredDateFromToken(token);
        return expiredDate.before(new Date());
    }

    /**
     * 从token中获取过期时间
     * @param token 客户端传入的token
     * @return java.util.Date
     * @author huangzifan
     * @since 2020-10-28 9:23
     */
    private Date getExpiredDateFromToken(String token){
   
        Claims claims = getClaimsFromToken(token);
        return claims.getExpiration();
    }

    /**
     * 根据用户信息生成token
     * @param userDetails 从数据库查询出的用户信息
     * @return String
     * @author huangzifan
     * @since 2020-10-28 9:24
     */
    private String generateToken(UserDetails userDetails){
   
        Map<String,Object> claims = new HashMap<>();
        claims.put(CLAIM_KEY_USERNAME,userDetails.getUsername());
        claims.put(CLAIM_KEY_CREATED,new Date());
        return generateToken(claims);
    }

    /**
     * 判断token是否可以被刷新
     * @param token  
     * @return boolean
     * @author huangzifan
     * @since 2020-10-28 9:25
     */
    private boolean canRefresh(String token){
   
        return !isTokenExpired(token);
    }

    /**
     * 刷新token
     * @param token  
     * @return java.lang.String
     * @author huangzifan
     * @since 2020-10-28 9:25
     */
    private String refreshToken(String token){
   
        Claims claims = getClaimsFromToken(token);
        claims.put(CLAIM_KEY_CREATED,new Date());
        return generateToken(claims);
    }


}
3 添加SpringSecurity配置类
package com.hzf.mymall.config;

import com.hzf.mymall.component.JwtAuthenticationTokenFilter;
import com.hzf.mymall.component.RestAuthenticationEntryPoint;
import com.hzf.mymall.component.RestfulAccessDeniedHandler;
import com.hzf.mymall.dto.AdminUserDetails;
import com.hzf.mymall.model.UmsAdmin;
import com.hzf.mymall.model.UmsPermission;
import com.hzf.mymall.service.UmsAdminService;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.http.HttpMethod;
import org.springframework.security.authentication.AuthenticationManager;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity
  • 0
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值