shiro和springboot整合配置

ShiroConfig

@Configuration
public class ShiroConfig {


    //shiro和spring整合
    @Bean
    public ShiroFilterFactoryBean shiroFilterFactoryBean(@Qualifier("defaultWebSecurityManager")DefaultWebSecurityManager defaultWebSecurityManager ){
        ShiroFilterFactoryBean shiroFilterFactoryBean = new ShiroFilterFactoryBean();

        shiroFilterFactoryBean.setSecurityManager(defaultWebSecurityManager);

        return shiroFilterFactoryBean;
    }

    //securityManager对象
    @Bean
    public DefaultWebSecurityManager defaultWebSecurityManager(@Qualifier("MyRealm")MyRealm myRealm){

        DefaultWebSecurityManager defaultWebSecurityManager = new DefaultWebSecurityManager();
        //myRealm设置到securityManager中
        defaultWebSecurityManager.setRealm(myRealm);

        return defaultWebSecurityManager;

    }
    //开启shiro注解
    @Bean
    public DefaultAdvisorAutoProxyCreator defaultAdvisorAutoProxyCreator(){
        DefaultAdvisorAutoProxyCreator defaultAdvisorAutoProxyCreator = new DefaultAdvisorAutoProxyCreator();

        defaultAdvisorAutoProxyCreator.setProxyTargetClass(true);

        return defaultAdvisorAutoProxyCreator;
    }
//设置aop进行扫描
    @Bean
    public AuthorizationAttributeSourceAdvisor authorizationAttributeSourceAdvisor(@Qualifier("defaultWebSecurityManager")DefaultWebSecurityManager defaultWebSecurityManager){

        AuthorizationAttributeSourceAdvisor authorizationAttributeSourceAdvisor = new AuthorizationAttributeSourceAdvisor();

        authorizationAttributeSourceAdvisor.setSecurityManager(defaultWebSecurityManager);
        return authorizationAttributeSourceAdvisor;
    }
    
    //设置自定义加密
    @Bean("hashedCredentialsMatcher")
    public HashedCredentialsMatcher hashedCredentialsMatcher() {
        HashedCredentialsMatcher credentialsMatcher = new HashedCredentialsMatcher();
        //指定加密方式为MD5
        credentialsMatcher.setHashAlgorithmName("MD5");
        //加密次数
        credentialsMatcher.setHashIterations(1024);
        credentialsMatcher.setStoredCredentialsHexEncoded(true);
        return credentialsMatcher;
    }

	//
    @Bean
    public MyRealm MyRealm(@Qualifier("hashedCredentialsMatcher") HashedCredentialsMatcher hashedCredentialsMatcher){

        MyRealm myRealm = new MyRealm();
        //关闭默认加密方式
        myRealm.setAuthorizationCachingEnabled(false);
        myRealm.setCredentialsMatcher(hashedCredentialsMatcher);
        return myRealm;
    }

MyRealm

public class MyRealm extends AuthorizingRealm {

    @Autowired
    UserRepository userRepository;

    @Autowired
    UserDao userDao;
	//赋权
    @Override
    protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principalCollection) {
        //获取用户名
        String userName = (String)principalCollection.getPrimaryPrincipal();
		//查询用户的权限表
        List<Permission> permission = userDao.findPermissionByName(userName);
        Set set = new HashSet<>();
        for (Permission p:permission
             ) {
            set.add(p.getPermissionName());
        }
        SimpleAuthorizationInfo simpleAuthorizationInfo = new SimpleAuthorizationInfo();
        //给与权限
        simpleAuthorizationInfo.addStringPermissions(set);
        return simpleAuthorizationInfo;
    }
	
	//认证
    @Override
    protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken authenticationToken) throws AuthenticationException {
		//获取用户名
        String username = (String) authenticationToken.getPrincipal();
		//查询数据库密码
        List<User> userList = userRepository.findByUserName(username);
		
        if (userList.size()>0) {
        	//使用用户名作为言
            ByteSource byteSource = ByteSource.Util.bytes(username);
            SimpleAuthenticationInfo simpleAuthenticationInfo = new SimpleAuthenticationInfo(username, userList.get(0).getPassword(),byteSource, this.getName());
            return simpleAuthenticationInfo;
        }
        return null;
    }


service层

@Override
    public BaseResult login(User user) {
        BaseResult baseResult = new BaseResult();
        Subject subject = SecurityUtils.getSubject();
        //将用户名封装到usernamePasswordToken 
        UsernamePasswordToken usernamePasswordToken = new UsernamePasswordToken(user.getUserName(),user.getPassword());

		
        subject.login(usernamePasswordToken);

        if (subject.isAuthenticated()) {
            baseResult.setCode(1);
            baseResult.setMsg("登录成功");
        }
        return baseResult;
        }
 
## controller层
接口上使用注解    @RequiresPermissions(value = {"findAll"})

Md5加密
public class Md5Utils {

    public String CreateMd5(String username,String password){
        String hashAlgorithName = "MD5";//加密算法
        int hashIterations =1024;//加密次数
        ByteSource credentialsSalt = ByteSource.Util.bytes(username);//使用登录名做为salt
        SimpleHash simpleHash = new SimpleHash(hashAlgorithName, password, credentialsSalt, hashIterations);
        return simpleHash.toString();
    }

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值