webservice 安全性 对外_WebService开发笔记 3 -- 增强访问 WebService 的安全性

本文介绍了如何通过在服务端和客户端添加passwordCallbackClass回调类来加强WebService的安全性,实现用户口令验证,确保只有授权用户才能访问WebService。详细步骤包括修改配置文件、实现回调类以及JUnit测试。
摘要由CSDN通过智能技术生成

WebService开发笔记 1中我们创建了一个WebService简单实例,下面我们通过一个简单的用户口令验证机制来加强一下WebService的安全性:

1.修改WebService 服务端 spring 配置文件 ws-context.xml

xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xmlns:jaxws="http://cxf.apache.org/jaxws"

xsi:schemaLocation="http://cxf.apache.org/jaxws http://cxf.apache.org/schemas/jaxws.xsd http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd"

default-autowire="byName" default-lazy-init="true">

address="/WebServiceSample" implementor="cn.org.coral.biz.examples.webservice.WebServiceSampleImpl">

2.服务端添加passwordCallbackClass回调类,该类进行用户口令验证:

package cn.org.coral.biz.examples.webservice.handler;

import java.io.IOException;

import javax.security.auth.callback.Callback;

import javax.security.auth.callback.CallbackHandler;

import javax.security.auth.callback.UnsupportedCallbackException;

import org.apache.ws.security.WSPasswordCallback;

public class WsAuthHandler implements CallbackHandler{

public void handle(Callback[] callbacks) throws IOException, UnsupportedCallbackException {

WSPasswordCallback pc = (WSPasswordCallback) callbacks[0];

if (pc.getIdentifer().equals("ws-client")){

if (!pc.getPassword().equals("admin")) {

throw new SecurityException("wrong password");

}

}else{

throw new SecurityException("wrong username");

}

}

}

3.客户端修改spring 配置文件 wsclient-context.xml 如下:

xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xmlns:jaxws="http://cxf.apache.org/jaxws"

xsi:schemaLocation="http://cxf.apache.org/jaxws http://cxf.apache.org/schemas/jaxws.xsd http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd"

default-autowire="byName" default-lazy-init="true">

factory-bean="webServiceSampleClientFactory" factory-method="create" />

class="org.apache.cxf.jaxws.JaxWsProxyFactoryBean">

value="cn.org.coral.biz.examples.webservice.WebServiceSample" />

value="http://88.148.29.54:8080/aio/services/WebServiceSample" />

class="org.apache.cxf.binding.soap.saaj.SAAJOutInterceptor" />

class="org.apache.cxf.ws.security.wss4j.WSS4JOutInterceptor">

passwordCallbackRef

class="cn.org.coral.biz.examples.webservice.handler.WsClinetAuthHandler">

4.客户端添加passwordCallback类,通过该类设置访问口令

package cn.org.coral.biz.examples.webservice.handler;

import java.io.IOException;

import javax.security.auth.callback.Callback;

import javax.security.auth.callback.CallbackHandler;

import javax.security.auth.callback.UnsupportedCallbackException;

import org.apache.ws.security.WSPasswordCallback;

public class WsClinetAuthHandler implements CallbackHandler{

public void handle(Callback[] callbacks) throws IOException,

UnsupportedCallbackException {

for (int i = 0; i < callbacks.length; i++) {

WSPasswordCallback pc = (WSPasswordCallback) callbacks[0];

int usage = pc.getUsage();

System.out.println("identifier: " + pc.getIdentifer());

System.out.println("usage: " + pc.getUsage());

if (usage == WSPasswordCallback.USERNAME_TOKEN) {

// username token pwd...

pc.setPassword("admin");

} else if (usage == WSPasswordCallback.SIGNATURE) {

// set the password for client's keystore.keyPassword

pc.setPassword("keyPassword");

}

}

}

}

5.junit单元测试程序:

package cn.org.coral.biz.examples.webservice;

import org.springframework.test.AbstractDependencyInjectionSpringContextTests;

import org.springframework.util.Assert;

public class TestWebService extends AbstractDependencyInjectionSpringContextTests {

WebServiceSample webServiceSampleClient;

@Override

protected String[] getConfigLocations() {

setAutowireMode(AUTOWIRE_BY_NAME);

return new String[] { "classpath:/cn/org/coral/biz/examples/webservice/wsclient-context.xml" };

}

/**

* @param webServiceSampleClient the webServiceSampleClient to set

*/

public void setWebServiceSampleClient(WebServiceSample webServiceSampleClient) {

this.webServiceSampleClient = webServiceSampleClient;

}

public void testSay(){

String result = webServiceSampleClient.say(" world");

Assert.hasText(result);

}

}

19

5

分享到:

18e900b8666ce6f233d25ec02f95ee59.png

72dd548719f0ace4d5f9bca64e1d7715.png

2008-03-19 09:50

浏览 21406

评论

8 楼

chxiaowu

2011-11-25

从头到尾没发现 那里有 cxf bean配置啊。。。。

7 楼

chxiaowu

2011-11-25

严重: StandardWrapper.Throwable

org.springframework.beans.factory.NoSuchBeanDefinitionException: No bean named 'cxf' is defined

at org.springframework.beans.factory.support.DefaultListableBeanFactory.getBeanDefinition(DefaultListableBeanFactory.java:387)

at org.springframework.beans.factory.support.AbstractBeanFactory.getMergedLocalBeanDefinition(AbstractBeanFactory.java:971)

at org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:246)

at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:185)

at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:168)

at org.springframework.context.support.AbstractApplicationContext.getBean(AbstractApplicationContext.java:884)

at org.apache.cxf.transport.servlet.CXFServlet.loadBus(CXFServlet.java:60)

at org.apache.cxf.transport.servlet.CXFNonSpringServlet.init(CXFNonSpringServlet.java:56)

at org.apache.catalina.core.StandardWrapper.initServlet(StandardWrapper.java:1228)

at org.apache.catalina.core.StandardWrapper.loadServlet(StandardWrapper.java:1147)

at org.apache.catalina.core.StandardWrapper.allocate(StandardWrapper.java:836)

at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:135)

at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:169)

at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:472)

at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:168)

at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:100)

at org.apache.catalina.valves.AccessLogValve.invoke(AccessLogValve.java:929)

at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:118)

at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:405)

at org.apache.coyote.http11.AbstractHttp11Processor.process(AbstractHttp11Processor.java:964)

at org.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process(AbstractProtocol.java:515)

at org.apache.tomcat.util.net.AprEndpoint$SocketProcessor.run(AprEndpoint.java:1824)

at java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java:886)

at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:908)

at java.lang.Thread.run(Thread.java:662)

2011-11-25 16:09:45 org.apache.catalina.core.StandardWrapperValve invoke

6 楼

chxiaowu

2011-11-25

No bean named 'cxf' is defined

??????????

5 楼

冰火人

2011-08-31

请问楼主这个是你自己的还是转的别人的,你自己测试了没有!

服务端 passwordCallbackClass中:pc.getPassword()这里有值???

…………

如果能加点注释,解释下就好了

是啊,我想知道你是怎么学的~~~

2 楼

sskhnje

2008-08-20

你好, 我的是cxf2.1.1 出现了以下异常, 谢谢啊!

org.apache.cxf.binding.soap.SoapFault: Problems creating SAAJ object model

at org.apache.cxf.binding.soap.saaj.SAAJInInterceptor.handleMessage(SAAJInInterceptor.java:117)

at org.apache.cxf.binding.soap.saaj.SAAJInInterceptor.handleMessage(SAAJInInterceptor.java:63)

at org.apache.cxf.phase.PhaseInterceptorChain.doIntercept(PhaseInterceptorChain.java:221)

at org.apache.cxf.endpoint.ClientImpl.onMessage(ClientImpl.java:449)

at org.apache.cxf.transport.http.HTTPConduit$WrappedOutputStream.handleResponse(HTTPConduit.java:1996)

at org.apache.cxf.transport.http.HTTPConduit$WrappedOutputStream.close(HTTPConduit.java:1832)

at org.apache.cxf.transport.AbstractConduit.close(AbstractConduit.java:66)

at org.apache.cxf.transport.http.HTTPConduit.close(HTTPConduit.java:591)

at org.apache.cxf.interceptor.MessageSenderInterceptor$MessageSenderEndingInterceptor.handleMessage(MessageSenderInterceptor.java:62)

at org.apache.cxf.phase.PhaseInterceptorChain.doIntercept(PhaseInterceptorChain.java:221)

at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:296)

at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:242)

at org.apache.cxf.frontend.ClientProxy.invokeSync(ClientProxy.java:73)

at org.apache.cxf.jaxws.JaxWsClientProxy.invoke(JaxWsClientProxy.java:178)

at $Proxy43.sayHi(Unknown Source)

at a.Client.main(Client.java:38)

Caused by: javax.xml.soap.SOAPException: Failed to create MessageFactory: org.apache.axis.soap.MessageFactoryImpl

at javax.xml.soap.MessageFactory.newInstance(MessageFactory.java:55)

at org.apache.cxf.binding.soap.saaj.SAAJInInterceptor.handleMessage(SAAJInInterceptor.java:77)

... 15 more

1 楼

sskhnje

2008-08-19

你好, 我也看了CXF的文档, 怎么我除了配helloworld外什么都没学到, 请问你是怎么学的?

期望你的指教, 谢谢啊!

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值