spring security+Jwt实现认证授权

Spring security+JWT实现认证授权

spring security官网链接:https://spring.io/projects/spring-security

JWT官网链接:https://jwt.io/

spring security介绍

Spring Security是一个功能强大且高度可定制的身份验证和访问控制框架。它是用于保护基于Spring的应用程序的实际标准。

Spring Security是一个框架,致力于为Java应用程序提供身份验证和授权。像所有Spring项目一样,Spring Security的真正强大之处在于可以轻松扩展以满足自定义要求

特征

对身份验证和授权的全面且可扩展的支持

防止攻击,例如会话固定,点击劫持,跨站点请求伪造等

核心

spring security提供一组过滤链,项目启动后进行自动配置,主要过滤流程如下:
客户端请求——>OncePerRequestFilter——>SecurityContextPersistenceFilter——>HeaderWriterFilter——>CsrfFilter——>LogoutFilter——>UsernmaePasswordAuthenticationFilter——>RequestCacheAwareFilter——>SecurityContextHolderAwareRequestFilter——>AnonymousAuthenticationFilter——>ExceptionTranslationFilter——>FilterSecurityInterceptor

简单来说:
1、客户端发起请求,spring security过滤链拦截
2、LogoutFilter判断是否是登出路径,如果是进入logoutHandler,如果登出成功则到logoutSuccessHandler登出成功,如果失败则进入ExceptionTranslationFilter,否则进入用户登录认证
3、UsernamePasswordAuthenticationFilter进行登录过滤器操作,如果登录失败则到AuthenticationFailureHandler登录失败处理。如果登录成功则到AuthenticationSuccessHandler登录成功处理器处理(只有是登录请求才能进入当前过滤器)
4、最后FilterSecurityInterceptor拿到uri,根据uri去找对应的鉴权管理器,鉴权成功进入控制层Controller,否则进入AccessDeniedHandler鉴权失败处理器处理

配置代码实现

spring security配置类代码:

package cn.xgb.com.xgb_business.config;

import cn.xgb.com.xgb_business.component.JwtAuthenticationTokenFilter;
import cn.xgb.com.xgb_business.component.RestAuthenticationEntryPoint;
import cn.xgb.com.xgb_business.component.RestfulAccessDeniedHandler;
import cn.xgb.com.xgb_business.sys.bo.AdminUserDetails;
import cn.xgb.com.xgb_business.sys.entity.SysPermission;
import cn.xgb.com.xgb_business.sys.entity.SysUserVo;
import cn.xgb.com.xgb_business.sys.mapper.SysUserMapper;
import cn.xgb.com.xgb_business.sys.service.ISysUserService;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.web.servlet.FilterRegistrationBean;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.http.HttpMethod;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
import org.springframework.security.config.http.SessionCreationPolicy;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.core.userdetails.UsernameNotFoundException;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter;
import org.springframework.web.cors.CorsConfiguration;
import org.springframework.web.cors.UrlBasedCorsConfigurationSource;
import org.springframework.web.filter.CorsFilter;

import java.util.List;

/**
 * ClassName: SecurityConfig
 * Description:
 * date: 2020/7/1 10:15
 *
 * @author xu
 * @since JDK 1.8
 */
@Configuration
@EnableWebSecurity
@EnableGlobalMethodSecurity(prePostEnabled = true)
public class SecurityConfig extends WebSecurityConfigurerAdapter {
    @Autowired
    private ISysUserService sysUserService;
    @Autowired
    private SysUserMapper userMapper;
    @Autowired
    RestfulAccessDeniedHandler restfulAccessDeniedHandler;
    @Autowired
    RestAuthenticationEntryPoint restAuthenticationEntryPoint;
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.csrf()
                .disable()
                .sessionManagement()//基于token,所以不需要session
                .sessionCreationPolicy(SessionCreationPolicy.STATELESS)
                .and()
                .authorizeRequests()
                .antMatchers(HttpMethod.GET,
                        "/",
                        "/*.html",
                        "/favicon.ico",
                        "/**/*.html",
                        "/**/*.css",
                        "/**/*.js",
                        "/swagger-resources/**",
                        "/v2/api-docs/**")
        .permitAll()
        .antMatchers("/admin/login","/admin/register")//对登录注册要允许匿名访问
        .permitAll()
        .antMatchers(HttpMethod.OPTIONS)//跨域请求会先进行一次options请求
        .permitAll()
        .antMatchers("/**")
        .permitAll()
        .anyRequest()
        .authenticated();

        //禁用缓存
        http.headers().cacheControl();
        //添加JWT 过滤
        http.addFilterBefore(jwtAuthenticationTokenFilter(), UsernamePasswordAuthenticationFilter.class);
        //添加自定义未授权和未登录结果返回
        http.exceptionHandling().accessDeniedHandler(restfulAccessDeniedHandler)
            .authenticationEntryPoint(restAuthenticationEntryPoint);

    }
    /**
    * Description: 配置认证授权用户并进行加密
    * @author: xu
    * @date: 2020/7/22 8:57
    * @param:
    * @return:
    */
    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        auth.userDetailsService(userDetailsService()).passwordEncoder(passwordEncoder());
    }
    @Bean
    public PasswordEncoder passwordEncoder(){return  new BCryptPasswordEncoder(); }

    @Bean
    public UserDetailsService userDetailsService(){
        //获取用户登录信息
        return username -> {
           SysUserVo admin =  userMapper.selectByUserName(username);
           if(admin!=null){
               if(admin.getSupplyId()!=null&&admin.getSupplyId()==1L){
                List<SysPermission> permissionList  =  sysUserService.listPerms();
                return new AdminUserDetails(admin,permissionList);
               }
               List<SysPermission> permissions = sysUserService.listUserPerms(admin.getId());
                return new AdminUserDetails(admin,permissions);
           }
           throw new UsernameNotFoundException("用户活密码错误");
        };
    }

    @Bean
    public JwtAuthenticationTokenFilter jwtAuthenticationTokenFilter(){return new JwtAuthenticationTokenFilter();}
    /**
    * Description: 允许跨域调用过滤器
    * @author: xu
    * @date: 2020/7/24 10:57
    * @param:
    * @return:
    */
    @Bean
    public CorsFilter corsFilter(){
        UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
        CorsConfiguration config = new CorsConfiguration();
        config.addAllowedOrigin("*");
        config.setAllowCredentials(true);
        config.addAllowedHeader("*");
        config.addAllowedMethod("*");
        source.registerCorsConfiguration("/**", config);
        FilterRegistrationBean bean = new FilterRegistrationBean(new CorsFilter(source));
        bean.setOrder(0);
        return new CorsFilter(source);
    }
}

其中configure(HttpSecurity http)是核心,内部封装整个认证和授权过程。

配置JWT(JSON web Token)

在UsernamePasswordAurhenticationFilter过滤器之前添加自行实现的JWT拦截

  http.addFilterBefore(jwtAuthenticationTokenFilter(), UsernamePasswordAuthenticationFilter.class);

jwt介绍

JSON Web令牌(JWT)是一个开放标准(RFC 7519),它定义了一种紧凑且自包含的方式,用于在各方之间安全地将信息作为JSON对象传输。由于此信息是经过数字签名的,因此可以进行验证和信任。可以使用秘密(使用HMAC算法)或使用RSA或ECDSA的公钥/私钥对对JWT进行签名。

jwt结构

jWt token的格式:header.payload.signature

  • header的格式(算法、token的类型):
    {“alg”: “HS512”,“typ”: “JWT”}
  • payload的格式(用户名、创建时间、生成时间):
    {“sub”: “wang”,“created”:1482134234,“exp”:2323423234}
  • signature的生成算法:
    HMACSHA256(base64UrlEncode(header)+"."+base64UrlEncode(payload),secret)

结果调试

在这里插入图片描述

Spring security 权限控制

@Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        auth.userDetailsService(userDetailsService()).passwordEncoder(passwordEncoder());
    }

**

  • AuthenticationManagerBuilder实现认证和授权管理
  • UserDetails定义的用户接口有开发者自行实现
    **

至此,配置完成

总结

spring security配置关键在于configure(HttpSecurity http)方法
扩展用户鉴权异常处理方式accessDeniedHandler(未授权),authenticationEntryPoint(未登录)。
token认证校验方式,使用jwt扩展UsernamePasswordAuthenticationFilter用户认证并生成token,另外,spring security的处理器大部分是重定向,但是我们不一般接口都是返回json,那么就需要重写处理器

  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
Spring Security JWT实现是指使用JWT(JSON Web Token)作为身份验证和授权机制的Spring Security解决方案。Spring SecurityJWT提供了自动化配置,使得使用JWT进行身份验证和授权变得更加简单和高效。通过配置JwtAuthenticationTokenFilter,可以实现JWT的验证和解析。同时,可以通过RestfulAccessDeniedHandler和RestAuthenticationEntryPoint来处理登录校验和权限校验的逻辑。使用JWT实现Spring Security解决方案可以提供更加强大和灵活的身份验证和授权功能。 [2 [3<span class="em">1</span><span class="em">2</span><span class="em">3</span> #### 引用[.reference_title] - *1* *2* [厉害,我带的实习生仅用四步就整合好SpringSecurity+JWT实现登录认证](https://blog.csdn.net/qing_gee/article/details/124016059)[target="_blank" data-report-click={"spm":"1018.2226.3001.9630","extra":{"utm_source":"vip_chatgpt_common_search_pc_result","utm_medium":"distribute.pc_search_result.none-task-cask-2~all~insert_cask~default-1-null.142^v93^chatsearchT3_1"}}] [.reference_item style="max-width: 50%"] - *3* [单点登录SSO解决方案之SpringSecurity+JWT实现.docx](https://download.csdn.net/download/njbaige/34581331)[target="_blank" data-report-click={"spm":"1018.2226.3001.9630","extra":{"utm_source":"vip_chatgpt_common_search_pc_result","utm_medium":"distribute.pc_search_result.none-task-cask-2~all~insert_cask~default-1-null.142^v93^chatsearchT3_1"}}] [.reference_item style="max-width: 50%"] [ .reference_list ]

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值