MockMVC登录后测试SpringBoot项目包含Shiro Subject的控制层方法

17 篇文章 1 订阅
2 篇文章 0 订阅

UnavailableSecurityManagerException

在常规SpringBoot项目中,我们往往在单元测试类中直接使用@Autowired注解注入Bean实例,并在Test方法中调用实例方法。但如果该项目加入了Shiro安全框架,并且在某个被测试的实例方法中存在获取当前Shiro Subject对象的方法:

package com.jake.manager.controller;

import com.jake.manager.constant.LoginConstants;
import com.jake.manager.exception.NoEmployeeException;
import io.swagger.annotations.Api;
import io.swagger.annotations.ApiOperation;
import org.apache.commons.lang3.StringUtils;
import org.apache.shiro.SecurityUtils;
import org.apache.shiro.authc.AuthenticationException;
import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.subject.Subject;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;

import static com.jake.manager.constant.ExceptionConstants.*;

@RestController
@Api("登录相关接口")
public class LoginController {

    private static final Logger logger = LoggerFactory.getLogger(LoginController.class);

    @GetMapping("authentication")
    @ApiOperation(value = "用户名密码校验", notes = "基于Shiro")
    public String authenticate(String account, String password, String rememberMe) {
        UsernamePasswordToken token = new UsernamePasswordToken(account, password,
                StringUtils.equals(rememberMe, LoginConstants.REMEMBER_ME));
        Subject subject = SecurityUtils.getSubject();
        try {
            subject.login(token);
        } catch (NoEmployeeException e) {
            logger.error(NO_EMPLOYEE_EXCEPTION);
            return NO_EMPLOYEE_EXCEPTION;
        } catch (AuthenticationException e) {
            logger.error(ERROR_PSWD_EXCEPTION);
            return ERROR_PSWD_EXCEPTION;
        }

        return LoginConstants.REDIRECT_TO_INDEX;
    }

}

那么很有可能会抛出以下异常:
Spring integration test with Shiro cause UnavailableSecurityManagerException

MockMVC先行登录

需要使用JUnit的@Before注解MockMVC的登录方法,即该登录方法在每个单元测试方法执行前都需要执行一遍。

package com.jake.manager.controller;

import org.apache.shiro.SecurityUtils;
import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.mgt.SecurityManager;
import org.apache.shiro.subject.Subject;
import org.apache.shiro.util.ThreadContext;
import org.apache.shiro.web.subject.WebSubject;
import org.junit.Before;
import org.junit.runner.RunWith;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.test.context.SpringBootTest;
import org.springframework.mock.web.MockHttpServletRequest;
import org.springframework.mock.web.MockHttpServletResponse;
import org.springframework.mock.web.MockHttpSession;
import org.springframework.test.context.junit4.SpringRunner;
import org.springframework.test.web.servlet.MockMvc;
import org.springframework.test.web.servlet.request.MockMvcRequestBuilders;
import org.springframework.test.web.servlet.result.MockMvcResultMatchers;
import org.springframework.test.web.servlet.setup.MockMvcBuilders;
import org.springframework.web.context.WebApplicationContext;

import static com.jake.manager.constant.LoginConstants.CORRECT_ACCOUNT;
import static com.jake.manager.constant.LoginConstants.CORRECT_PSWD;

@RunWith(SpringRunner.class)
@SpringBootTest
public abstract class BaseMockBeforeTests {

    @Autowired
    private SecurityManager securityManager;

    @Autowired
    private WebApplicationContext webApplicationContext;

    private MockMvc mockMvc;

    @Before
    public void loginByMock() {
        MockHttpServletRequest mockHttpServletRequest = new MockHttpServletRequest(webApplicationContext.getServletContext());
        MockHttpServletResponse mockHttpServletResponse = new MockHttpServletResponse();
        MockHttpSession mockHttpSession = new MockHttpSession(webApplicationContext.getServletContext());
        mockHttpServletRequest.setSession(mockHttpSession);
        SecurityUtils.setSecurityManager(securityManager);
        mockMvc = MockMvcBuilders.webAppContextSetup(webApplicationContext).build();
        Subject subject = new WebSubject
                .Builder(mockHttpServletRequest, mockHttpServletResponse)
                .buildWebSubject();
        UsernamePasswordToken token = new UsernamePasswordToken(CORRECT_ACCOUNT, CORRECT_PSWD);
        subject.login(token);
        ThreadContext.bind(subject);
    }

    String getReturnValue(String uri) throws Exception {
        return mockMvc.perform(MockMvcRequestBuilders.get(uri))
                .andExpect(MockMvcResultMatchers.status().isOk())
                .andReturn()
                .getResponse()
                .getContentAsString();
    }
}

此处将Mock登录类抽取为一个基类,注意需要将该类声明为抽象类。否则会报“No Runnable Methods”,这是因为BaseMockBeforeTests中没有单元测试方法,所以产生异常:已加载至SpringBootTest容器中的单元测试类中没有可运行的单元测试方法。若将该类声明为抽象类,则该类不会被加载进SpringBootTest容器,而是根据多态,加载其子类对象。
登录代码完成后,对LoginController的单元测试类代码如下:

package com.jake.manager.controller;

import org.junit.Test;

import static com.jake.manager.constant.ExceptionConstants.*;
import static com.jake.manager.constant.LoginConstants.*;
import static org.junit.Assert.*;

public class LoginControllerTests extends BaseMockBeforeTests {

    @Test
    public void authenticateByCorrectAccountAndPassword() throws Exception {
        assertEquals(REDIRECT_TO_INDEX,
                getReturnValue(getBuiltUri(CORRECT_ACCOUNT, CORRECT_PSWD)));
    }

    @Test
    public void authenticateByWrongAccount() throws Exception {
        assertEquals(NO_EMPLOYEE_EXCEPTION,
                getReturnValue(getBuiltUri(WRONG_ACCOUNT, CORRECT_PSWD)));
    }

    @Test
    public void authenticateByWrongPassword() throws Exception {
        assertEquals(ERROR_PSWD_EXCEPTION,
                getReturnValue(getBuiltUri(CORRECT_ACCOUNT, WRONG_PSWD)));
    }

    private String getBuiltUri(String account, String password) {
        return "/authentication?account=" + account + "&password=" + password;
    }

}
  • 6
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
要在Spring Boot项目中使用Shiro实现接口授权,需要进行以下步骤: 1. 添加Shiro依赖 在pom.xml文件中添加Shiro依赖: ``` <dependency> <groupId>org.apache.shiro</groupId> <artifactId>shiro-spring</artifactId> <version>1.5.0</version> </dependency> ``` 2. 配置Shiro 在Spring Boot的配置文件中添加Shiro的配置,如下所示: ``` shiro: filter-chain-definitions: /** = anon /login = anon /logout = logout /api/** = authc security-manager: realm: type: org.apache.shiro.realm.jdbc.JdbcRealm authentication-query: SELECT password FROM users WHERE username = ? user-roles-query: SELECT role_name FROM user_roles WHERE username = ? permissions-query: SELECT permission FROM roles_permissions WHERE role_name = ? ``` 该配置文件中配置了Shiro的过滤链,以及Shiro的安全管理器和Realm。 3. 编写Shiro Realm 编写一个继承自JdbcRealm的Realm类,并实现doGetAuthenticationInfo()和doGetAuthorizationInfo()两个方法,如下所示: ``` public class MyRealm extends JdbcRealm { @Override protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken token) throws AuthenticationException { UsernamePasswordToken upToken = (UsernamePasswordToken) token; String username = upToken.getUsername(); String password = new String(upToken.getPassword()); // 根据用户名和密码查询数据库,如果查询到了用户,则返回一个封装了该用户信息的AuthenticationInfo对象 // 如果没有查询到用户,则返回null } @Override protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principals) { SimpleAuthorizationInfo authorizationInfo = new SimpleAuthorizationInfo(); String username = (String) principals.getPrimaryPrincipal(); // 根据用户名查询用户的角色和权限信息,并将其添加到authorizationInfo中 return authorizationInfo; } } ``` 4. 配置ShiroFilterFactoryBean 在Spring Boot的配置文件中配置ShiroFilterFactoryBean,如下所示: ``` @Bean public ShiroFilterFactoryBean shiroFilterFactoryBean(@Autowired MyRealm myRealm) { ShiroFilterFactoryBean shiroFilterFactoryBean = new ShiroFilterFactoryBean(); shiroFilterFactoryBean.setSecurityManager(new DefaultWebSecurityManager(myRealm)); Map<String, String> filterChainDefinitionMap = new LinkedHashMap<>(); filterChainDefinitionMap.put("/login", "anon"); filterChainDefinitionMap.put("/logout", "logout"); filterChainDefinitionMap.put("/api/**", "authc"); shiroFilterFactoryBean.setFilterChainDefinitionMap(filterChainDefinitionMap); return shiroFilterFactoryBean; } ``` 该配置文件中配置了一个ShiroFilterFactoryBean,并将其与安全管理器和过滤链绑定在一起。 5. 编写接口控制器 编写一个接口控制器,并在该控制器中添加需要授权的接口方法,如下所示: ``` @RestController public class ApiController { @GetMapping("/api/hello") public String hello() { return "Hello, world!"; } @RequiresRoles("admin") @PostMapping("/api/admin") public String admin() { return "Hello, admin!"; } } ``` 上述代码中,hello()方法不需要授权,而admin()方法需要授予admin角色才能访问。 6. 测试接口授权 启动Spring Boot应用程序,并使用curl或Postman等工具测试接口授权。例如,可以使用以下命令测试admin接口: ``` curl -X POST http://localhost:8080/api/admin -H 'Authorization: Basic YWRtaW46YWRtaW4=' ``` 其中,Authorization头中的值是用户名和密码的Base64编码,上述例子中的用户名和密码都是admin。如果授权成功,服务器将返回"Hello, admin!"。如果授权失败,则返回401 Unauthorized错误。
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值