SpringSecurity原理剖析及其实战(二)

11 篇文章 1 订阅
5 篇文章 0 订阅

SpringSecurity原理剖析及其实战(二)

Spring Security整合数据库认证服务器

Spring security整合数据库认证本人这边所使用的技术栈如下:

技术描述
mybatis持久层
mybatis-plusMyBatis (opens new window) 的增强工具
hutooljava工具类库
lombok一种 Java™ 实用工具
EasyCode代码生成器

后面的整合oauth2、jwt中也会大量以上技术,包括最后整套Spring Cloud Alibaba - vue前后端分离体系
废话到这,下面正式开始

  • 1.先导入依赖
  
<dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-jdbc</artifactId>
        </dependency>
        <dependency>
            <groupId>mysql</groupId>
            <artifactId>mysql-connector-java</artifactId>
        </dependency>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-security</artifactId>
        </dependency>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-web</artifactId>
        </dependency>

        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-test</artifactId>
            <scope>test</scope>
        </dependency>
        <dependency>
            <groupId>org.springframework.security</groupId>
            <artifactId>spring-security-test</artifactId>
            <scope>test</scope>
        </dependency>
        <!--lombok-->
        <dependency>
            <groupId>org.projectlombok</groupId>
            <artifactId>lombok</artifactId>
            <version>1.18.6</version>
        </dependency>
         <!-- hutool-->
        <dependency>
            <groupId>cn.hutool</groupId>
            <artifactId>hutool-all</artifactId>
            <version>5.7.15</version>
        </dependency>

         <!-- mybatis-plus -->
        <dependency>
            <groupId>com.baomidou</groupId>
            <artifactId>mybatis-plus-boot-starter</artifactId>
            <version>3.1.2</version>
        </dependency>
        <!-- MyBatis-Plus模板引擎 -->
        <dependency>
            <groupId>org.apache.velocity</groupId>
            <artifactId>velocity-engine-core</artifactId>
            <version>2.1</version>
        </dependency>
        <!--热部署  每次修改代码springboot自动重启服务-->
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-devtools</artifactId>
            <optional>true</optional>
        </dependency>
        <dependency>
            <groupId>junit</groupId>
            <artifactId>junit</artifactId>
        </dependency>

整体目录如下,
在这里插入图片描述
我这边使用的是EasyCode代码生成器,也可自己去配置mybatis的代码生成器,如需使用EasyCode代码生成器,Plugins 搜索easycode下载重启idea即可

在这里插入图片描述

这里分享一下我自定义的模版,只需点击导入模版输入:171c65ee922df8a54fb81abdf018761f,即可使用,如过期评论区下方留言即可,后面会逐步完善模版
在这里插入图片描述
EasyCode使用方式如下图,选择服务,生成路径以后需要生成的文件
在这里插入图片描述

  • 2.application.yaml的连接池配置如下(数据库表已经在上一章最后面贴出来了)

server:
  port: 8881
  servlet:
      context-path: /
spring:
  datasource:
    type: com.zaxxer.hikari.HikariDataSource
    driver-class-name: com.mysql.cj.jdbc.Driver
    url: jdbc:mysql://localhost:3306/hejinwen?useUnicode=true&characterEncoding=utf-8&useSSL=false&serverTimezone=UTC
    username: root
    password: root
    hikari:
      minimum-idle: 5
      idle-timeout: 600000
      maximum-pool-size: 10
      auto-commit: true
      pool-name: MyHikariCP
      max-lifetime: 1800000
      connection-timeout: 30000
      connection-test-query: SELECT 1

  • 3.dao/TbPermissionDao.java
package com.csw.jdbc.dao;
 
import com.baomidou.mybatisplus.core.mapper.BaseMapper;
import com.csw.jdbc.entity.TbPermission;
import org.apache.ibatis.annotations.Mapper;
import org.apache.ibatis.annotations.Select;

import java.util.List;
 
/**
 * 权限表(TbPermission)表数据库访问层
 * @author chengshengwen
 * @description 
 * @since 2021-11-01 00:20:07
 */
@Mapper
public interface TbPermissionDao extends BaseMapper<TbPermission> {
    /**
     * 根据用户id查找数据
     * @param userId
     * @return
     */
    List<TbPermission> selectByUserId(Long userId);
}

mapper/TbPermissionMapper.xml

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE mapper PUBLIC "-//mybatis.org//DTD Mapper 3.0//EN" "http://mybatis.org/dtd/mybatis-3-mapper.dtd">
<mapper namespace="com.csw.jdbc.dao.TbPermissionDao">
 
    <select id="selectByUserId" resultType="com.csw.jdbc.entity.TbPermission">
        select p.* from tb_user as u
        LEFT JOIN tb_user_role ur on u.id = ur.user_id
        LEFT JOIN tb_role as r  on r.id = ur.role_id
        LEFT JOIN tb_role_permission as p on r.id = p.permission_id
        WHERE u.id = #{userId}
    </select>

   
</mapper>

如下图,主要代码是selectByUserId()方法,其他是EasyCo de生成的方法,后面会逐步完善EasyCode模版:
在这里插入图片描述
service/TbPermissionService.java

package com.csw.jdbc.service;
 
import com.csw.jdbc.entity.TbPermission;
import java.util.List;

 /**
 * 权限表(TbPermission)表服务接口
 * @author chengshengwen
 * @description 
 * @since 2021-11-01 00:20:08
 */
public interface TbPermissionService {
 
    //根据用户id查询
    List<TbPermission>  selectByUserId(Long userId);

}

service/impl/TbPermissionServiceImpl.java

package com.csw.jdbc.service.impl;
 
import com.csw.jdbc.dao.TbUserDao;
import com.csw.jdbc.entity.TbPermission;
import com.csw.jdbc.dao.TbPermissionDao;
import com.csw.jdbc.service.TbPermissionService;
import org.springframework.stereotype.Service;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.transaction.annotation.Transactional;

import java.util.List;
 
 
 /**
 * 权限表(TbPermission)表服务实现类
 * @author chengshengwen
 * @description 
 * @since 2021-11-01 00:20:09
 */
@Service
@Transactional 
@AllArgsConstructor
public class TbPermissionServiceImpl implements TbPermissionService {

    private final TbPermissionDao tbPermissionDao;
 
     @Override
     public List<TbPermission> selectByUserId(Long userId) {
         return tbPermissionDao.selectByUserId(userId);
     }


 }

dao/TbUserDao.java

package com.csw.jdbc.dao;
 
import com.baomidou.mybatisplus.core.mapper.BaseMapper;
import com.csw.jdbc.entity.TbUser;
import org.apache.ibatis.annotations.Mapper;

import java.util.List;
 
/**
 * 用户表(TbUser)表数据库访问层
 * @author chengshengwen
 * @description 
 * @since 2021-10-31 23:27:00
 */
@Mapper
public interface TbUserDao extends BaseMapper<TbUser> {
}

service/TbUserService.java

//根据用户名获取用户信息
    package com.csw.jdbc.service;
 
import com.csw.jdbc.entity.TbUser;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;

import java.util.List;
 
 /**
 * 用户表(TbUser)表服务接口
 * @author chengshengwen
 * @description 
 * @since 2021-10-31 23:27:01
 */
public interface TbUserService {
 
    //根据用户名获取用户信息
    TbUser getByUsername(String username);
 
}

service/impl/TbUserServiceImpl.java(核心代码)

package com.csw.jdbc.service.impl;
 
import cn.hutool.core.util.StrUtil;
import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
import com.csw.jdbc.dao.TbPermissionDao;
import com.csw.jdbc.entity.TbPermission;
import com.csw.jdbc.entity.TbUser;
import com.csw.jdbc.dao.TbUserDao;
import com.csw.jdbc.service.TbUserService;
import lombok.AllArgsConstructor;
import org.springframework.security.core.GrantedAuthority;
import org.springframework.security.core.authority.SimpleGrantedAuthority;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.core.userdetails.UsernameNotFoundException;
import org.springframework.stereotype.Service;
import org.springframework.transaction.annotation.Transactional;

import java.util.ArrayList;
import java.util.List;
 
 
 /**
 * 用户表(TbUser)表服务实现类
 * @author chengshengwen
 * @description 
 * @since 2021-10-31 23:27:01
 */
@Service
@Transactional
@AllArgsConstructor
public class TbUserServiceImpl implements TbUserService,UserDetailsService{


    private final TbUserDao tbUserDao;

    private final TbPermissionDao tbPermissionDao;
 
 
     @Override
     public TbUser getByUsername(String username) {
         QueryWrapper<TbUser> wrapper = new QueryWrapper<>();
         wrapper.eq("username",username);
         return this.tbUserDao.selectOne(wrapper);
     }

     @Override
     public UserDetails loadUserByUsername(String username) throws UsernameNotFoundException {
        //从数据库查用户
        TbUser user = getByUsername(username);
        ArrayList<GrantedAuthority> authorities = new ArrayList<>();
        if(user != null) {
            List<TbPermission> tbPermissions = tbPermissionDao.selectByUserId(user.getId());

            //设置权限
            tbPermissions.forEach(permissions -> {
                if(permissions != null && !StrUtil.isEmpty(permissions.getEnname())) {
                    SimpleGrantedAuthority grantedAuthority = new SimpleGrantedAuthority(permissions.getEnname());
                    authorities.add(grantedAuthority);
                }
            });
            //封装成UserDetails的实现类
            return new org.springframework.security.core.userdetails.User(
                    user.getUsername(),user.getPassword(),authorities);
        }else {
            throw new UsernameNotFoundException("用户名不存在");
        }
     }
 }

entity/TbUser.java

package com.csw.jdbc.entity;

import java.util.Date;
import java.io.Serializable;
import lombok.*;
/**
 * 用户表(TbUser)实体类
 * @author chengshengwen
 * @description 
 * @since 2021-10-31 23:26:58
 */
@Data
public class TbUser implements Serializable {
    private static final long serialVersionUID = 734210779083900189L;

        private Long id;

    /*** 用户名 */    private String username;

    /*** 密码,加密存储 */    private String password;

    /*** 注册手机号 */    private String phone;

    /*** 注册邮箱 */    private String email;

        private Date created;

        private Date updated;
}

entity/TbRole.java

package com.csw.jdbc.entity;

import java.util.Date;
import java.io.Serializable;
import lombok.*;
/**
 * 角色表(TbRole)实体类
 * @author chengshengwen
 * @description 
 * @since 2021-11-01 11:16:22
 */
@Data
public class TbRole implements Serializable {
    private static final long serialVersionUID = 768391666783014299L;

        private Long id;

    /*** 父角色 */    private Long parentId;

    /*** 角色名称 */    private String name;

    /*** 角色英文名称 */    private String enname;

    /*** 备注 */    private String description;

        private Date created;

        private Date updated;
}

entity/TbPermission.java

package com.csw.jdbc.entity;

import java.util.Date;
import java.io.Serializable;
import lombok.*;
/**
 * 权限表(TbPermission)实体类
 * @author chengshengwen
 * @description 
 * @since 2021-11-01 00:20:05
 */
@Data
public class TbPermission implements Serializable {
    private static final long serialVersionUID = -91733717429724780L;

        private Long id;

    /*** 父权限 */    private Long parentId;

    /*** 权限名称 */    private String name;

    /*** 权限英文名称 */    private String enname;

    /*** 授权路径 */    private String url;

    /*** 备注 */    private String description;

        private Date created;

        private Date updated; 
}

以上代码都可以使用EasyCode或者其他代码生成器生成的,核心代码只有TbUserServiceImpl.java里面的…
config/WebSecurityConfig.java

package com.csw.jdbc.config;

import com.csw.jdbc.service.impl.TbUserServiceImpl;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;

@Configuration
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {

    @Autowired
    private TbUserServiceImpl userServiceImpl;


    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        //设置UserDetailsService的实现类
        auth.userDetailsService(userServiceImpl);
    }
    @Bean
    public PasswordEncoder passwordEncoder(){
        return new BCryptPasswordEncoder();
    }
}

到这里注意,我已经在TbUserServiceImpl去实现了UserDetailsService接口的loadUserByUsername方法
在这里插入图片描述
整体代码已上传至(https://gitee.com/JAVA8888/spring-security.git),顺便在这里打个广告,推荐一个不错的SpringCloud Alibaba + vue项目(https://gitee.com/youlaitech/youlai-mall
我们试下登录后的效果:
在这里插入图片描述
debug登录认证效果如下图:
在这里插入图片描述
以上就是Spring security整合数据库认证,都是一些比较基础的东西,为整合Oauth2打下点基础,争取下篇把Spring Security完结了,喜欢的朋友点个关注,您的关注或点赞都是博主的动力
-> SpringSecurity原理剖析及其实战(三)

  • 0
    点赞
  • 2
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值