shiro登陆

登陆认证
整合shiro
1 添加依赖

<dependency>
	<groupId>org.apache.shiro</groupId>
	<artifactId>shiro-spring</artifactId>
</dependency>

2 web.xml中注册

    <!-- shiro过虑器,DelegatingFilterProxy通过代理模式将spring容器中的bean和filter关联起来 -->
    <filter>
	<filter-name>shiroFilter</filter-name>
	<filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class> <!-- 设置true由servlet容器控制filter的生命周期 -->
	<!-- 设置true由servlet容器控制filter的生命周期 -->
	<init-param>
		<param-name>targetFilterLifecycle</param-name>
		<param-value>true</param-value>
	</init-param> 
	<!-- 设置spring容器filter的bean id,如果不设置则找与filter-name一致的bean -->
	<init-param>
		<param-name>targetBeanName</param-name>
		<param-value>shiro</param-value>
	</init-param>
	</filter>
	<filter-mapping>
		<filter-name>shiroFilter</filter-name>
		<url-pattern>/*</url-pattern>
	</filter-mapping>

3 自定义Realm

//自定义的Realm
public class MyRealm extends AuthorizingRealm{

	 //认证的方法
	@Override
	protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken token) throws AuthenticationException {
		// TODO Auto-generated method stub
		return null;
	}
	
	//授权的方法
	@Override
	protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principals) {
		// TODO Auto-generated method stub
		return null;
	}

}

4 添加shiro的配置文件

<?xml version="1.0" encoding="UTF-8"?>
<beans xmlns="http://www.springframework.org/schema/beans"
    xmlns:context="http://www.springframework.org/schema/context" xmlns:p="http://www.springframework.org/schema/p"
    xmlns:aop="http://www.springframework.org/schema/aop" xmlns:tx="http://www.springframework.org/schema/tx"
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-4.2.xsd
    http://www.springframework.org/schema/context http://www.springframework.org/schema/context/spring-context-4.2.xsd
    http://www.springframework.org/schema/aop http://www.springframework.org/schema/aop/spring-aop-4.2.xsd http://www.springframework.org/schema/tx http://www.springframework.org/schema/tx/spring-tx-4.2.xsd
    http://www.springframework.org/schema/util http://www.springframework.org/schema/util/spring-util-4.2.xsd">
    
    <!-- 注册自定义Realm -->
    <bean class="com.i.shiro.SecurityRealm" id="myRealm">
    	<property name="credentialsMatcher">
    		<bean class="org.apache.shiro.authc.credential.HashedCredentialsMatcher">
    			<property name="hashAlgorithmName" value="md5"/>
    			<property name="hashIterations" value="1024"/>
    		</bean>
    	</property>
    </bean>
    
    <!-- 注册SecurityManager -->
    <bean class="org.apache.shiro.web.mgt.DefaultWebSecurityManager" id="securityManager">
        <!-- 配置自定义Realm -->
        <property name="realm" ref="myRealm"/>
    </bean>
    
    <!-- 注册ShiroFilterFactoryBean 注意id必须和web.xml中注册的targetBeanName的值一致 -->
    <bean class="org.apache.shiro.spring.web.ShiroFilterFactoryBean" id="shiro">
        <!-- 注册SecurityManager -->
        <property name="securityManager" ref="securityManager"/>
        <!-- 登录地址 如果用户请求的的地址是 login.do 那么会对该地址认证-->
        <property name="loginUrl" value="/login.do"/>
        <!-- 登录成功的跳转地址 -->
        <property name="successUrl" value="/home"/>
        <!-- 访问未授权的页面跳转的地址 -->
        <property name="unauthorizedUrl" value="/jsp/refuse.jsp"/>
        <!-- 设置 过滤器链 -->
        <property name="filterChainDefinitions">
            <value>
                <!--加载顺序从上往下。
                    authc需要认证
                    anon可以匿名访问的资源
                 -->
                 / = anon
                /login = anon
                /images/** = anon
                /css/** = anon
                /js/** = anon
                /lib/** = anon
                /login.do = authc
                /** = authc
            </value>
        </property>
    </bean>
</beans>

登陆
1 登陆页面

<%@ page language="java" contentType="text/html; charset=UTF-8"pageEncoding="UTF-8"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>欢迎登录后台管理系统</title>
<link href="css/style.css" rel="stylesheet" type="text/css" />
<script language="JavaScript" src="js/jquery.js"></script>
<script src="js/cloud.js" type="text/javascript"></script>

<script language="javascript">
	$(function(){
    $('.loginbox').css({'position':'absolute','left':($(window).width()-692)/2});
	$(window).resize(function(){  
    $('.loginbox').css({'position':'absolute','left':($(window).width()-692)/2});
    })  
});  
</script> 

</head>

<body style="background-color:#1c77ac; background-image:url(images/light.png); background-repeat:no-repeat; background-position:center top; overflow:hidden;">



    <div id="mainBody">
      <div id="cloud1" class="cloud"></div>
      <div id="cloud2" class="cloud"></div>
    </div>  


<div class="logintop">    
    <span>欢迎登录后台管理界面平台</span>    
    <ul>
    <li><a href="#">回首页</a></li>
    <li><a href="#">帮助</a></li>
    <li><a href="#">关于</a></li>
    </ul>    
    </div>
    
    <div class="loginbody">
    
    <span class="systemlogo"></span> 
       
    <div class="loginbox">
    	<form action="/login.do" method="post">
		    <ul>
			    <li><input name="username" type="text" class="loginuser" value="admin" /></li>
			    <li><input name="password" type="text" class="loginpwd" value="1" /></li>
			    <li>
			    	<input type="submit" class="loginbtn" value="登录"/>
				    <label>
				    	<input name="" type="checkbox" value="" checked="checked" />记住密码
				    </label>
				    <label>
				    	<span style="color:red ">${LOGIN_ERROR}</span>
				    </label>
			    </li>
		    </ul>
    	</form>
    </div>
    
    </div>
    
    
    
    <div class="loginbm">版权所有  2013  <a href="http://www.uimaker.com">uimaker.com</a>  仅供学习交流,勿用于任何商业用途</div>
	
    
<div style="display:none"><script src='http://v7.cnzz.com/stat.php?id=155540&web_id=155540' language='JavaScript' charset='gb2312'></script></div>
</body>
</html>
@Controller
public class PageController {

	//根据URL自动调对应的.jsp
	@RequestMapping("/{path}")
	public String goPage(@PathVariable String path){
		return path;
	}
}

2 登陆认证
UserServiceImpl中修改query方法

@Override
	public List<User> query(User user) {
		UserExample example = new UserExample();
		if(user != null){
			Criteria criteria = example.createCriteria();
			if(StringUtils.isNotEmpty(user.getUserName())){
				//根据账号查询
				criteria.andUserNameEqualTo(user.getUserName());
			}
		}
		return userMapper.selectByExample(example);
	}

自定义Realm中完成认证逻辑

package com.i.shiro;

//自定义的Realm  实现认证和授权操作
public class SecurityRealm extends AuthorizingRealm {

	@Resource
	private IUserService userService;
	
	//授权的方法
	@Override
	protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principals) {
		return null;
	}

	//认证的方法
	@Override
	protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken token) throws AuthenticationException {
		if(token instanceof UsernamePasswordToken){
			//获取提交的账号
			UsernamePasswordToken t = (UsernamePasswordToken) token;
			//获取登陆的账号
			String userName = t.getUsername();
			User user = new User();
			user.setUserName(userName);
			//登陆操作
			List<User> list = userService.query(user);
			if(list == null || list.size() > 1){
				//参数不存在或用户过多都返回null
				return null;
			}
			//表示账号存在
			user = list.get(0);
			SimpleAuthenticationInfo info = new SimpleAuthenticationInfo(user,
													user.getPassword(),
													new SimpleByteSource(user.getU1())//盐值
													,"securityRealm");
			return info;
		}
		return null;
	}
}

controller层逻辑

@Controller
public class LoginController {

	//设置登陆失败跳转的页面,获取失败信息
	@RequestMapping("/login.do")
	public String login(HttpServletRequest request,Model m){
		//获取错误的异常信息
		Object obj = request.getAttribute(FormAuthenticationFilter.DEFAULT_ERROR_KEY_ATTRIBUTE_NAME);
		if(obj != null){
			System.out.println(obj.toString());
		}
		if(UnknownAccountException.class.getName().equals(obj)){
			m.addAttribute("LOGIN_ERROR","账号有误");
		}else if(IncorrectCredentialsException.class.getName().equals(obj)){
			m.addAttribute("LOGIN_ERROR","密码有误");
		}else{
			m.addAttribute("LOGIN_ERROR","其他错误");
		}
		return "login";
	}

认证登陆信息

<form action="/login.do" method="post">
		    <ul>
			    <li><input name="username" type="text" class="loginuser" value="admin" /></li>
			    <li><input name="password" type="text" class="loginpwd" value="1" /></li>
			    <li>
			    	<input type="submit" class="loginbtn" value="登录"/>
				    <label>
				    	<input name="" type="checkbox" value="" checked="checked" />记住密码
				    </label>
				    <label>
				    	<span style="color:red ">${LOGIN_ERROR}</span>
				    </label>
			    </li>
		    </ul>
    	</form>

退出功能

<li><a href="/logout.do" target="_parent">退出</a></li>

LoginController中添加退出方法

	//退出
	@RequestMapping("/logout.do")
	public String logout(){
		SecurityUtils.getSubject().logout();
		return "login";
	}
}
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值