spring boot 重构请求 自定义注解 接口验签 加密 防重复提交

重构请求 自定义注解 接口验签

在这里插入图片描述

定义注解

package com.jianmu.config.request.anno;

import java.lang.annotation.ElementType;
import java.lang.annotation.Retention;
import java.lang.annotation.RetentionPolicy;
import java.lang.annotation.Target;

/**
 * 禁止重复提交
 *
 * @author kong
 */
@Target(ElementType.METHOD)
@Retention(RetentionPolicy.RUNTIME)
public @interface SafetyApi {
    /**
     * 请求失效时间,单位毫秒
     * 超过当前时间则当前请求直接失效
     **/
    long expireTime() default 2000;

    /**
     * 重复请求的时间,单位毫秒
     */
    long repeatTime() default 3000;

    /**
     * 接口数据是否加密
     */
    boolean encrypt() default false;
}
package com.jianmu.config.request.anno;

import lombok.Data;
import lombok.experimental.Accessors;

/**
 * @author kong
 */
@Data
@Accessors(chain = true)
public class Safety {
    /**
     * 接口
     */
    private String uri;
    /**
     * 失效时间
     */
    private Long expireTime;
    /**
     * 重复提交时间
     */
    private Long repeatTime;
    /**
     * 是否数据加密
     */
    private Boolean encrypt;
}

package com.jianmu.config.request.anno;

import com.jianmu.tools.AnnotationTools;
import org.springframework.web.bind.annotation.RestController;

import java.util.List;

/**
 * @author kong
 * 验签注解 相关常量
 * URIS 记录被注解的URI
 */
public class SafetyConstant {
    public static final List<Safety> URIS;

    static {
        URIS = AnnotationTools.findUrisByAnnoScan("com.jianmu.api", RestController.class, SafetyApi.class);
    }

    private SafetyConstant() {
    }

}


包装HttpServletRequest,目的是让其输入流可重复读

package com.jianmu.config.request;

import lombok.extern.slf4j.Slf4j;

import javax.servlet.ReadListener;
import javax.servlet.ServletInputStream;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletRequestWrapper;
import java.io.BufferedReader;
import java.io.ByteArrayInputStream;
import java.io.InputStreamReader;

/**
 * 包装HttpServletRequest,目的是让其输入流可重复读
 *
 * @author kong
 */
@Slf4j
public class RefactorRequestWrapper extends HttpServletRequestWrapper {
    /**
     * 存储body数据的容器
     */
    private final byte[] body;

    public RefactorRequestWrapper(HttpServletRequest request, byte[] body) {
        super(request);
        this.body = body;
    }

    @Override
    public BufferedReader getReader() {
        return new BufferedReader(new InputStreamReader(getInputStream()));
    }

    @Override
    public ServletInputStream getInputStream() {

        final ByteArrayInputStream inputStream = new ByteArrayInputStream(body);

        return new ServletInputStream() {
            @Override
            public int read() {
                return inputStream.read();
            }

            @Override
            public boolean isFinished() {
                return false;
            }

            @Override
            public boolean isReady() {
                return false;
            }

            @Override
            public void setReadListener(ReadListener readListener) {
            }
        };
    }
}

重构请求 并验签

RSA 前端用公钥加密的数据 后端用私钥解密

package com.jianmu.config.request;

import com.alibaba.fastjson.JSON;
import com.alibaba.fastjson.JSONObject;
import com.jianmu.config.RsaConfig;
import com.jianmu.config.request.anno.Safety;
import com.jianmu.config.request.anno.SafetyConstant;
import com.jianmu.exception.MessagePromptException;
import com.jianmu.tools.ApiTools;
import com.jianmu.tools.EncryptTools;
import com.jianmu.tools.Md5Tools;
import lombok.extern.slf4j.Slf4j;
import org.apache.commons.collections4.CollectionUtils;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.data.redis.core.RedisTemplate;
import org.springframework.data.redis.core.ValueOperations;
import org.springframework.stereotype.Component;
import org.springframework.web.servlet.HandlerExceptionResolver;

import javax.servlet.*;
import javax.servlet.annotation.WebFilter;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.BufferedReader;
import java.io.IOException;
import java.io.InputStream;
import java.io.InputStreamReader;
import java.nio.charset.StandardCharsets;
import java.util.Objects;
import java.util.Optional;
import java.util.concurrent.TimeUnit;

/**
 * @author kong
 * 
 */
@WebFilter
@Slf4j
@Component
public class RefactorRequestFilter implements Filter {
    private final RsaConfig rsaConfig;
    private final RedisTemplate<String, Object> redisTemplate;
   
    private final HandlerExceptionResolver handlerExceptionResolver;
    private Safety safety;

    @Autowired
    public RefactorRequestFilter(RsaConfig rsaConfig, RedisTemplate<String, Object> redisTemplate, HandlerExceptionResolver handlerExceptionResolver) {
        this.rsaConfig = rsaConfig;
        this.redisTemplate = redisTemplate;
        this.handlerExceptionResolver = handlerExceptionResolver;
    }

    public String getBodyString(ServletRequest request) {
        StringBuilder sb = new StringBuilder();
        try (InputStream inputStream = request.getInputStream(); BufferedReader reader = new BufferedReader(new InputStreamReader(inputStream, StandardCharsets.UTF_8))) {
            String line;
            while ((line = reader.readLine()) != null) {
                sb.append(line);
            }
        } catch (Exception e) {
            log.error(e.getMessage());
        }
        return sb.toString();
    }

    @Override
    public void init(FilterConfig filterConfig) {

    }

    @Override
    public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain chain) throws IOException, ServletException {
        HttpServletRequest request = (HttpServletRequest) servletRequest;
        HttpServletResponse response = (HttpServletResponse) servletResponse;
        if (CollectionUtils.isNotEmpty(SafetyConstant.URIS)) {
            //所有注解的禁止重复的uri其中是否有一个匹配当前请求uri
            this.safety = SafetyConstant.URIS.parallelStream().filter(i -> i.getUri().contains(request.getRequestURI())).findFirst().orElse(null);
        }

        if (CollectionUtils.isNotEmpty(SafetyConstant.URIS) && Objects.nonNull(this.safety)) {
            if (log.isDebugEnabled()) {
                log.debug("需要安全验证的api:{}", request.getRequestURI());
            }
            //获取request的body参数
            byte[] data;
            try {
                JSONObject paramJson = JSON.parseObject(this.getBodyString(request));
                if (log.isDebugEnabled()) {
                    log.debug("数据加密密文:{}", paramJson.toJSONString());
                }
                //是否需要解密
                if (this.safety.getEncrypt()) {
                    final String encrypt = paramJson.getString("b");
                    if (encrypt == null) {
                        throw new MessagePromptException("数据异常");
                    }
                    //RSA 前端用公钥加密的数据  后端用私钥解密
                    paramJson.put("b", EncryptTools.decrypt(rsaConfig.getPrivateKey(), encrypt));
                }
                if (log.isDebugEnabled()) {
                    log.debug("数据加密解文:{}", paramJson);
                }
                data = handler(paramJson);
            } catch (Exception e) {
                log.error("error:", e);
                handlerExceptionResolver.resolveException(request, response, null, new MessagePromptException(e.getMessage()));
                return;
            }
            chain.doFilter(new RefactorRequestWrapper(request, data), response);
        } else {
            chain.doFilter(request, response);
        }

    }

    @Override
    public void destroy() {

    }

    private byte[] handler(JSONObject params) throws MessagePromptException {
        JSONObject b = params.getJSONObject("b");
        //时间戳
        final long timestamp = b.getLongValue("t");
        //签名
        final String sign = b.getString("s");
        //请求业务参数
        JSONObject p = JSON.parseObject(b.getString("p"));
        p.put("gp", EncryptTools.aesDecrypt(p.getString("gp")));
        //验证是否超时
        this.isExpired(timestamp);
        //验证签名
        this.isSign(b);
        //验证是否重复提交
        this.isRepeatSubmit(sign, this.safety.getExpireTime());

        p.put("v", params.getString("v"));
        final String ps = p.toJSONString();
        if (log.isDebugEnabled()) {
            log.debug("业务参数:{}", ps);
        }
        return ps.getBytes();
    }


    private void isExpired(final long timestamp) throws MessagePromptException {
        //请求时间间隔
        final long currentTime = System.currentTimeMillis();
        final long requestInterval = currentTime - timestamp;
        if (requestInterval > Optional.ofNullable(this.safety.getExpireTime()).orElseThrow(() -> new MessagePromptException("请求异常"))) {
            log.error("请求超时时间:{},当前时间:{},超时:{}", currentTime, timestamp, requestInterval);
            throw new MessagePromptException("请求超时");
        }
    }

    private void isSign(final JSONObject dataJson) throws MessagePromptException {
        // 校验签名(将所有的参数加进来,防止别人篡改参数) 所有参数看参数名升续排序拼接成url
        // 业务数据+流水号 nonce 进行签名
        final String signStr = ApiTools.concatSignString(dataJson.getInnerMap());
        final String serverSign = Md5Tools.encode(signStr);
        final String sign = dataJson.getString("s");

        final boolean flag = serverSign.equals(sign);
        if (log.isDebugEnabled()) {
            log.debug("签名数据:{}", JSON.toJSONString(dataJson.getInnerMap()));
            log.debug("签名字符串:{}", signStr);
            log.debug("签名1:{}", serverSign);
            log.debug("签名2:{}", sign);
        }
        if (!flag) {
            throw new MessagePromptException("签名错误");
        }
    }

    private void isRepeatSubmit(final String sign, final long expireTime) throws MessagePromptException {
        ValueOperations<String, Object> signRedis = redisTemplate.opsForValue();
        final boolean exists = Optional.ofNullable(redisTemplate.hasKey(sign)).orElse(false);
        if (exists) {
            throw new MessagePromptException("重复提交");
        }
        signRedis.set(sign, 0, expireTime, TimeUnit.MILLISECONDS);
    }

    /*
      1.需要获取到公钥
      2.传入正确的参数格式
      3.新的时间戳
      4.正确的签名方式
      5.破解时间
     */
}

  • 0
    点赞
  • 4
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

等一场春雨

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值