JwtTokenFilter

package com.demo.netty.controller.filter;

import com.alibaba.fastjson.JSON;
import com.alibaba.fastjson.JSONObject;
import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.beans.factory.annotation.Qualifier;
import org.springframework.stereotype.Component;
import org.springframework.util.ObjectUtils;
import org.springframework.web.bind.annotation.CrossOrigin;
import org.springframework.web.filter.OncePerRequestFilter;
import org.springframework.web.servlet.HandlerExceptionResolver;

import javax.servlet.FilterChain;
import javax.servlet.ServletException;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.BufferedReader;
import java.io.IOException;
import java.io.InputStreamReader;
import java.util.Base64;

@Slf4j
@Component
@CrossOrigin
public class JwtTokenFilter extends OncePerRequestFilter {
@Autowired
@Qualifier(“handlerExceptionResolver”)
private HandlerExceptionResolver resolver;

@Override
protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain filterChain) throws IOException, ServletException {

    String header = request.getHeader("Content-Type");
    if (!ObjectUtils.isEmpty(header) && !ObjectUtils.isEmpty(header)){
        if (header.contains("application/json")){
            CustomHttpServletRequestWrapper customHttpServletRequestWrapper = null;
            try {
                customHttpServletRequestWrapper = new CustomHttpServletRequestWrapper(request);
                BufferedReader streamReader = new BufferedReader( new InputStreamReader(customHttpServletRequestWrapper.getInputStream(), "UTF-8"));
                StringBuilder responseStrBuilder = new StringBuilder();
                String inputStr;
                while ((inputStr = streamReader.readLine()) != null){
                    responseStrBuilder.append(inputStr);
                }
                String s2 = responseStrBuilder.toString();
                JSONObject jsonObject = JSON.parseObject(s2);
                String data = jsonObject.getString("data");
                byte[] decode = Base64.getDecoder().decode(data);
                String s = new String(decode);
                customHttpServletRequestWrapper.setBody(s);
            } catch (Exception e) {
                e.printStackTrace();
            }
            filterChain.doFilter(customHttpServletRequestWrapper,response);
            return;
        }
    }
    filterChain.doFilter(request,response);
}

}

  • 5
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
import org.springframework.beans.factory.annotation.Autowired; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.http.HttpMethod; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.builders.WebSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; import org.springframework.security.crypto.password.PasswordEncoder; import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter; @Configuration @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { @Bean public JwtTokenProvider jwtTokenProvider() { return new JwtTokenProvider(); } @Autowired private JwtTokenProvider jwtTokenProvider; @Override protected void configure(HttpSecurity http) throws Exception { http.csrf().disable() .addFilterBefore(new JwtTokenFilter(jwtTokenProvider), UsernamePasswordAuthenticationFilter.class) .authorizeRequests() .antMatchers("/api/").authenticated() .anyRequest().permitAll(); } @Override public void configure(WebSecurity web) throws Exception { web.ignoring().antMatchers(HttpMethod.OPTIONS, "/"); } @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(12); } }报错信息:Cannot resolve symbol 'JwtTokenFilter',如何创建一个JwtTokenFilter类,让代码不报错
05-25
你需要创建一个名为 JwtTokenFilter 的类,代码如下: ``` import io.jsonwebtoken.ExpiredJwtException; import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; import org.springframework.security.core.Authentication; import org.springframework.security.core.context.SecurityContextHolder; import org.springframework.security.web.authentication.WebAuthenticationDetailsSource; import org.springframework.stereotype.Component; import org.springframework.web.filter.OncePerRequestFilter; import javax.servlet.FilterChain; import javax.servlet.ServletException; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletResponse; import java.io.IOException; @Component public class JwtTokenFilter extends OncePerRequestFilter { private final JwtTokenProvider jwtTokenProvider; public JwtTokenFilter(JwtTokenProvider jwtTokenProvider) { this.jwtTokenProvider = jwtTokenProvider; } @Override protected void doFilterInternal(HttpServletRequest httpServletRequest, HttpServletResponse httpServletResponse, FilterChain filterChain) throws ServletException, IOException { String token = jwtTokenProvider.resolveToken(httpServletRequest); try { if (token != null && jwtTokenProvider.validateToken(token)) { Authentication auth = jwtTokenProvider.getAuthentication(token); if (auth != null) { SecurityContextHolder.getContext().setAuthentication(auth); } } } catch (ExpiredJwtException e) { httpServletResponse.setStatus(HttpServletResponse.SC_UNAUTHORIZED); httpServletResponse.sendError(HttpServletResponse.SC_UNAUTHORIZED, "Token已过期"); return; } filterChain.doFilter(httpServletRequest, httpServletResponse); } } ``` 在上面的代码中,我们创建了一个 JwtTokenFilter 类,它继承了 OncePerRequestFilter 类。JwtTokenFilter 类中包含了我们在之前创建的 JwtTokenProvider 对象,以及 doFilterInternal() 方法,该方法是实际执行 JWT 验证的地方。 在 doFilterInternal() 方法中,我们首先从请求中获取 JWT Token,并调用 JwtTokenProvider 对象中的方法来验证 Token 是否有效。如果 Token 有效,我们使用 JwtTokenProvider 对象的 getAuthentication() 方法来获取用户的身份验证对象,然后将其设置为 SecurityContext 中的认证对象。最后,我们调用 FilterChain 对象的 doFilter() 方法,以便请求可以继续进行处理。 请注意,在上面的代码中,我们使用了 @Component 注解将 JwtTokenFilter 类声明为 Spring 组件。这样,Spring 将负责创建 JwtTokenFilter 对象,并将其注入到 SecurityConfig 类中。
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值