摘要认证,使用HttpClient实现HTTP post请求 digest

     第一次用到摘要认证,做个记录

大概流程

 1. POST URL
2: 401 Unauthorized
3: 根据F2 返回的认证信息,带userName、password进行验证
4: 返回 状态 200

第一次客户端请求

  1. GET/POST
  2. 服务器产生一个随机数nonce,服务器将这个随机数放在WWW-Authenticate响应头,与服务器支持的认证算法列表,认证的域realm一起发送给客户端,如下例子:
HTTP /1.1 401 Unauthorized
WWW-Authenticate:Digest
realm= ”test realm”
qop=auth,auth-int”
nonce=”66C4EF58DA7CB956BD04233FBB64E0A4”
opaque=“5ccc069c403ebaf9f0171e9517f40e41”

 ps:

    

•    realm的值是一个简单的字符串
•    qop是认证的(校验)方式
•    nonce是随机数, 可以用GUID
•    opaque是个随机字符串,它只是透传而已,即客户端还会原样返回过来。
•    algorithm 是个字符串,用来指示用来产生分类及校验和的算法对。如果该域没指定,则认为是“MD5“算法。

 3. 客户端发现是401响应,表示需要进行认证,则弹出让用户输入用户名和密码的认证窗口,客户端选择一个算法,计算出密码和其他数据的摘要(response),将摘要放到Authorization的请求头中发送给服务器,如果客户端要对服务器也进行认证,这个时候,可以发送客户端随机数cnonce。如下例子:
 

 GET/cgi-bin/checkout?a=b HTTP/1.1
 Authorization: Digest
 username="Mufasa", 
 realm="realm", 
 nonce="dcd98b7102dd2f0e8b11d0f600bfb0c0",  uri="/xxxx/System/Register",  
 qop=auth,  nc=00000001,  cnonce="0a4f113b",
 response="6629fae49393a05397450978507c4ef1",  
 opaque="5ccc069c403ebaf9f0171e9517f40e41"

4.服务接受摘要,选择算法,获取数据库用户名密码,重新计算新的摘要跟客户端传输的摘要进行比较,验证是否匹配。
200 OK

 

主要代码:


import com.alibaba.fastjson.JSON;
import com.alibaba.fastjson.JSONObject;
import org.apache.commons.codec.digest.DigestUtils;
import org.apache.commons.lang3.StringUtils;
import org.apache.http.Header;
import org.apache.http.HeaderElement;
import org.apache.http.HttpEntity;
import org.apache.http.HttpStatus;
import org.apache.http.client.config.RequestConfig;
import org.apache.http.client.methods.CloseableHttpResponse;
import org.apache.http.client.methods.HttpPost;
import org.apache.http.entity.StringEntity;
import org.apache.http.impl.client.CloseableHttpClient;
import org.apache.http.impl.client.HttpClients;
import org.apache.http.util.EntityUtils;

import java.io.*;
import java.nio.charset.StandardCharsets;


/**
 *
 */
public class HttpRequestUtils {


    public static void main(String[] args) {
        String username = "test";
        String password = "test";
        String json="{\n" +
                "\t\"RegisterObject\":\n" +
                "\t{\n" +
                "\t\t\"DeviceID\":\"10101010101010101010\"\n" +
                "\t}\n" +
                "}";
        doPostDigest( "https://100.200.1008.102:802/VIID/System/Register", username, password,json);

    }

    /**
     * 摘要认证 两次请求
     * @param url
     * @return 返回结果
     */
    public static Boolean doPostDigest(String url, String username, String password, String parms) {
        System.out.println("Post请求url:[{}]"+ url);
        CloseableHttpClient httpClient = null;
        CloseableHttpResponse response = null;
        HttpPost httpPost = null;
        String strResponse = null;
        Boolean flag = false;
        try {
            httpClient = HttpClients.createDefault();
            httpClient = new SSLClient();
            httpPost = new HttpPost(url);
            // 构造请求头
            httpPost.setHeader("Content-type", "application/VIID+JSON;charset=UTF-8");
            httpPost.setHeader("User-Identify", "10101010101010101010");
            httpPost.addHeader("Cache-Control", "no-cache"); //设置缓存
            httpPost.setHeader("Connection", "Close");

            RequestConfig.Builder builder = RequestConfig.custom();
            builder.setSocketTimeout(3000); //设置请求时间
            builder.setConnectTimeout(5000); //设置超时时间
            builder.setRedirectsEnabled(false);//设置是否跳转链接(反向代理)
            // 设置 连接 属性
            httpPost.setConfig(builder.build());
            StringEntity entityss = new StringEntity(parms, "utf-8");
            httpPost.setEntity(entityss);
            // 执行请求
            response = httpClient.execute(httpPost);
            HttpEntity responseEntity = response.getEntity();
            // 检验返回码
            int statusCode = response.getStatusLine().getStatusCode();
            System.out.println("第一次发送摘要认证 Post请求 返回码:{}"+ statusCode);
            if (401 == statusCode) {
                strResponse = EntityUtils.toString(responseEntity, "utf-8");
                System.out.println("Post请求401返回结果:{}"+strResponse);

                // 组织参数,发起第二次请求
                Header[] headers = response.getHeaders("WWW-Authenticate");
                HeaderElement[] elements = headers[0].getElements();
                String realm = null;
                String qop = null;
                String nonce = null;
                String opaque = null;
                String method = "POST";
                String uri = "/VIID/System/Register";
                for (HeaderElement element : elements) {
                    if (element.getName().equals("Digest realm")) {
                        realm = element.getValue();
                    } else if (element.getName().equals("qop")) {
                        qop = element.getValue();
                    } else if (element.getName().equals("nonce")) {
                        nonce = element.getValue();
                    } else if (element.getName().equals("opaque")) {
                        opaque = element.getValue();
                    }
                }
                // 以上为 获取第一次请求后返回的 数据
                String nc = "00000001";
                String cnonce = "uniview";
                // 后期变成可配置
                String a1 = username + ":" + realm + ":" + password;
                String a2 = method + ":" + uri;
                String response1 = null;
                // 获取 Digest 这个字符串
                String backString = response.getFirstHeader("WWW-Authenticate").getValue();
                try {
                    response1 = DigestUtils.md5Hex((DigestUtils.md5Hex(a1.getBytes("UTF-8")) + ":" + nonce + ":" + nc
                            + ":" + "uniview" + ":" + qop + ":" + DigestUtils.md5Hex(a2.getBytes("UTF-8"))).getBytes("UTF-8"));
                } catch (UnsupportedEncodingException e) {
                    System.out.println("MD5异常:{}"+ e.getLocalizedMessage());
                }
                httpPost.addHeader("Authorization", backString + ",username=\"" + username + "\"" + ",realm=\"" + realm + "\""
                        + ",nonce=\"" + nonce + "\"" + ",uri=\"" + uri + "\"" + ",qop=\"" + qop + "\"" + ",nc=\"" + nc + "\""
                        + ",cnonce=\"" + cnonce + "\"" + ",response=\"" + response1 + "\"" + ",opaque=\"" + opaque);

                // 发送第二次请求
                response = httpClient.execute(httpPost);
                HttpEntity entity = response.getEntity();
                int statusCode1 = response.getStatusLine().getStatusCode();
                System.out.println("第二次发送摘要认证 Post请求 返回码:{}"+statusCode1);
               /** if (HttpStatus.SC_OK == statusCode1) {
                    strResponse = EntityUtils.toString(entity, StandardCharsets.UTF_8);
                    System.out.println("第二次发送strResponse"+strResponse);

                    flag = true;
                    return flag;
                } else {
                    strResponse = EntityUtils.toString(entity, StandardCharsets.UTF_8);
                    System.out.println("第二次鉴权认证请求非 200 返回结果:{}"+ strResponse);
                    return flag;
                }**/
            } else {
                strResponse = EntityUtils.toString(responseEntity, StandardCharsets.UTF_8);
                System.out.println("第一次鉴权认证请求非401 返回结果:{}"+ strResponse);
            }
        } catch (Exception e) {
            System.out.println("摘要认证 发送请求失败"+e.getLocalizedMessage());
        } finally {
            if (null != httpPost) {
                httpPost.releaseConnection();
            }
            if (null != response) {
                try {
                    response.close();
                } catch (IOException e) {
                    System.out.println("httpResponse流关闭异常:"+e);
                }
            }
            if (null != httpClient) {
                try {
                    httpClient.close();
                } catch (IOException e) {
                    System.out.println("httpClient 流关闭异常:"+e);
                }
            }
        }
        return flag;
    }



}

忽略SLL证书认证

import org.apache.http.conn.ClientConnectionManager;
import org.apache.http.conn.scheme.Scheme;
import org.apache.http.conn.scheme.SchemeRegistry;
import org.apache.http.conn.ssl.SSLSocketFactory;
import org.apache.http.impl.client.DefaultHttpClient;

import javax.net.ssl.SSLContext;
import javax.net.ssl.TrustManager;
import javax.net.ssl.X509TrustManager;
import java.security.cert.CertificateException;
import java.security.cert.X509Certificate;

public class SSLClient extends DefaultHttpClient {
    public SSLClient() throws Exception {
        super();
        SSLContext ctx = SSLContext.getInstance( "TLS" );
        X509TrustManager tm = new X509TrustManager() {
            @Override
            public void checkClientTrusted(X509Certificate[] chain,
                                           String authType) throws CertificateException {
            }

            @Override
            public void checkServerTrusted(X509Certificate[] chain,
                                           String authType) throws CertificateException {
            }

            @Override
            public X509Certificate[] getAcceptedIssuers() {
                return null;
            }
        };
        ctx.init( null, new TrustManager[]{tm}, null );
        SSLSocketFactory ssf = new SSLSocketFactory( ctx, SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER );
        ClientConnectionManager ccm = this.getConnectionManager();
        SchemeRegistry sr = ccm.getSchemeRegistry();
        sr.register( new Scheme( "https", 443, ssf ) );
    }

}

jar:

 <dependency>
      <groupId>org.apache.httpcomponents</groupId>
      <artifactId>httpclient</artifactId>
      <version>4.5.6</version>
    </dependency>
    <!-- https://mvnrepository.com/artifact/digest/digest -->
    <dependency>
      <groupId>digest</groupId>
      <artifactId>digest</artifactId>
      <version>1.4.4</version>
    </dependency>

  • 1
    点赞
  • 6
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论
HttpClient Digest 是 Apache HttpComponents 项目中提供的一个模块,用于处理 HTTP 身份验证的 Digest 认证机制。Digest 认证是一种安全性较高的身份验证机制,其与基本身份验证不同的是,Digest 认证使用一个随机值(nonce)和加密算法来保护用户凭证,从而增强了安全性。 在使用 HttpClient Digest 进行认证时,需要先创建一个 HttpPost 请求,并设置请求的 URI、请求头和请求体。接着,需要使用 HttpDigestAuth 类创建一个 Digest 认证对象,并将其添加到 HttpClient 的上下文中。最后,通过执行 HttpPost 请求,即可完成 Digest 认证过程。 以下是使用 HttpClient Digest 进行认证的示例代码: ``` CloseableHttpClient httpClient = HttpClients.createDefault(); HttpPost httpPost = new HttpPost("http://www.example.com/login"); // 设置请求httpPost.setHeader("Content-Type", "application/x-www-form-urlencoded"); // 设置请求体 List<NameValuePair> params = new ArrayList<>(); params.add(new BasicNameValuePair("username", "user")); params.add(new BasicNameValuePair("password", "password")); httpPost.setEntity(new UrlEncodedFormEntity(params)); // 创建 Digest 认证对象 HttpHost targetHost = new HttpHost("www.example.com", 80, "http"); CredentialsProvider credentialsProvider = new BasicCredentialsProvider(); credentialsProvider.setCredentials( new AuthScope(targetHost.getHostName(), targetHost.getPort()), new UsernamePasswordCredentials("user", "password")); AuthCache authCache = new BasicAuthCache(); DigestScheme digestScheme = new DigestScheme(); authCache.put(targetHost, digestScheme); HttpClientContext context = HttpClientContext.create(); context.setCredentialsProvider(credentialsProvider); context.setAuthCache(authCache); // 执行请求 CloseableHttpResponse response = httpClient.execute(httpPost, context); ``` 在以上代码中,我们首先创建了一个 HttpPost 请求,并设置了请求头和请求体。接着,我们创建了一个 Digest 认证对象,并将其添加到 HttpClient 的上下文中。最后,通过执行 HttpPost 请求,即可完成 Digest 认证过程。
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

南大白

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值