API接口加密及安全设置

通过时间戳,秘钥,token等实现接口安全性要求,一段不成熟的代码,但愿可以提供一些思路。

@Slf4j
public class UserInfoInterceptor implements HandlerInterceptor {

    /**
     * 封装,不需要过滤的list列表
     */
    protected static List<String> URLS = new ArrayList<String>();

    static {
        URLS.add("/api/system/getUserInfo");
        URLS.add("/api/system/getYearInfo");
    }


    /**
     * 封装,不需要过滤的list列表
     */
    protected static List<String> APIURLS = new ArrayList<String>();

    static {
        APIURLS.add("/api/system/saveUser");
        APIURLS.add("/api/system/removeUser");
        APIURLS.add("/api/system/saveZtInfo");
        APIURLS.add("/api/system/removeZtInfo");
    }

    @Resource
    private RedisUtil redisUtil;


    private static final String PRIVATE_KEY =  "tbl@52sm";


    @Override
    public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws UnsupportedEncodingException {
        String url = request.getRequestURI();
        String ipAddress = getIpAddress(request);
        // 通过ip可以设置ip黑名单进行拦截

        //过滤不需要拦截的请求
        for (String u : URLS) {
            if (StringUtils.contains(url, u)) {
                return true;
            }
        }
        // 时间戳
        String timestamp = request.getHeader("timestamp");
        if (StringUtils.isBlank(timestamp)) {
            log.error("timestamp未传");
            throw new BizException(ResultCode.HEADER_PARAMS_NOT_UNDELIVERED.getCode(), ResultCode.HEADER_PARAMS_NOT_UNDELIVERED.getDesc());
        }
        // 签名
        String sign = request.getHeader("sign");
        if (StringUtils.isBlank(timestamp)) {
            log.error("sign未传");
            throw new BizException(ResultCode.HEADER_PARAMS_NOT_UNDELIVERED.getCode(), ResultCode.HEADER_PARAMS_NOT_UNDELIVERED.getDesc());
        }
        //解析签名:时间戳+tbb52sm 双重MD5加密
        String newSign = DigestUtils.md5Hex(timestamp + PRIVATE_KEY);
        newSign = DigestUtils.md5Hex(newSign);
        // 校验签名是否正确
        if (!sign.equals(newSign)) {
            log.error("非法操作");
            throw new BizException(ResultCode.ILLEGAL_OPERATION.getCode(), ResultCode.ILLEGAL_OPERATION.getDesc());
        }

        // 签名存放在redis中,设定1分钟的有效期
        long incr = redisUtil.incr("sign:" + ipAddress + url + sign, 1);
        if (incr == 1) {
            redisUtil.expire("sign:" + ipAddress + url + sign, 60);
        } else {
            log.error("非法操作");
            throw new BizException(ResultCode.ILLEGAL_OPERATION.getCode(), ResultCode.ILLEGAL_OPERATION.getDesc());
        }

        // 时间戳相差超过1分钟,认定为非法操作
        long interval = System.currentTimeMillis() - Long.valueOf(timestamp);
        if (interval > SessionKeyConstants.REQUEST_EXP_TIME) {
            log.error("非法操作");
            throw new BizException(ResultCode.ILLEGAL_OPERATION.getCode(), ResultCode.ILLEGAL_OPERATION.getDesc());
        }

        // 对外api请求只需要传递时间戳和签名,此段代码位置不能变动
        for (String apiUrl : APIURLS) {
            if (StringUtils.contains(url, apiUrl)) {
                return true;
            }
        }
        // accessToken
        String accessToken = request.getHeader("accessToken");
        if (StringUtils.isBlank(accessToken)) {
            log.error("access_token未传");
            throw new BizException(ResultCode.HEADER_PARAMS_NOT_UNDELIVERED.getCode(), ResultCode.HEADER_PARAMS_NOT_UNDELIVERED.getDesc());
        }
        // 用户信息
        Object operator = redisUtil.get(SessionKeyConstants.ACCESS_TOKEN + accessToken);
        if (Objects.isNull(operator)) {
            log.error("accessToken过期");
            throw new BizException(ResultCode.ACCESS_TOKEN_EXPIRED.getCode(), ResultCode.ACCESS_TOKEN_EXPIRED.getDesc());
        } else {
            FinancialLoginUserVO userVO = JSON.parseObject(operator.toString(), FinancialLoginUserVO.class);
            // 保存用户数据
            UserThreadLocal.set(userVO);
        }
        return true;
    }


    @Override
    public void postHandle(HttpServletRequest request, HttpServletResponse response, Object handler, ModelAndView modelAndView) throws Exception {

    }

    @Override
    public void afterCompletion(HttpServletRequest request, HttpServletResponse response, Object handler, Exception ex) throws Exception {
       UserThreadLocal.remove();
    }


    /**
     * ip
     * @param request
     * @return
     */
    public static String getIpAddress(HttpServletRequest request) {
        String ip = request.getHeader("x-forwarded-for");
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("Proxy-Client-IP");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("WL-Proxy-Client-IP");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("HTTP_CLIENT_IP");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("HTTP_X_FORWARDED_FOR");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getRemoteAddr();
        }
        return ip;
    }

}

  • 2
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值