zuul简单实现ip黑白名单机制

微服务--zuul简单实现ip黑白名单机制

 网关zuul中简单的实现对访问ip的黑白名单机制,控制服务访问ip,一定程度上提高系统安全性。


目录

微服务--zuul简单实现ip黑白名单机制

一、 从HttpServletRequest获取访问ip方法

二、继承ZuulFilter过滤器,重写run方法,实现 

总结


一、 从HttpServletRequest获取访问ip方法

 


    public static String getIpAddress(HttpServletRequest request) {
        String ip = request.getHeader("x-forwarded-for");
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("Proxy-Client-IP");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("WL-Proxy-Client-IP");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("HTTP_CLIENT_IP");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("HTTP_X_FORWARDED_FOR");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getRemoteAddr();
        }
        return ip;
    }

 

二、继承ZuulFilter过滤器,重写run方法,实现 

package com.ytkj.feec.filter;

import com.alibaba.fastjson.JSON;
import com.netflix.zuul.ZuulFilter;
import com.netflix.zuul.context.RequestContext;
import com.netflix.zuul.exception.ZuulException;
import com.yuantiaokj.commonmodule.base.SysRes;
import com.yuantiaokj.dao.manager.IpTblDao;
import com.yuantiaokj.dict.paycentre_manager.DictIpStatus;
import io.swagger.annotations.ApiOperation;
import lombok.extern.slf4j.Slf4j;
import org.springframework.stereotype.Component;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;

import javax.annotation.Resource;
import javax.servlet.http.HttpServletRequest;
import javax.validation.Valid;
import java.io.IOException;
import java.util.ArrayList;
import java.util.List;

/**
 * ***********************************************************
 * Copyright © 2019 Inc.All rights reserved.  *    *
 * **********************************************************
 *
 * @program: financial_eco-environment_cloud
 * @name: LoginFilter
 * @author: Mr.Cnzz
 * @create: 2019-12-11 15:27
 * @description: 登录认证过滤器
 **/
@Component
@Slf4j
@RestController
@RequestMapping("IpFilter")
public class IpFilter extends ZuulFilter {

    @Resource
    private IpTblDao ipTblDao;

    //全局白名单ip List
    static List<String> whitelist = new ArrayList<>();


//    自定义过虑器需要继承 ZuulFilter,ZuulFilter是一个抽象类,需要覆盖它的4个方法,如下:
//    filterType:返回字符串代表过滤器的类型,返回值有:
//          pre:在请求路由之前执行
//          route:在请求路由时调用
//          post:请求路由之后调用, 也就是在route和errror过滤器之后调用
//          error:处理请求发生错误时调用
//    filterOrder:此方法返回整型数值,通过此数值来定义过滤器的执行顺序,数字越小优先级越高。
//    shouldFilter:返回Boolean值,判断该过滤器是否执行。返回true表示要执行此过虑器,false不执行。
//    run:过滤器的业务逻辑。


    @Override
    public String filterType() {

        //请求路由前调用
        //log.info("请求路由前调用pre====");
        return "pre";
    }

    @Override
    public int filterOrder() {

        //int值来定义过滤器的执行顺序,数值越小优先级越高
        return 1;
    }

    @Override
    public boolean shouldFilter() {

        //该过滤器是否执行,true|执行,false不执行
        return true;
    }

    @Override
    public Object run() throws ZuulException {
        RequestContext context = RequestContext.getCurrentContext();
        HttpServletRequest request = context.getRequest();

        //ip 黑白名单机制
        String ip = getIpAddress(request);
        log.info("当前请求ip={}", ip);
        // 在黑名单中禁用
        //ip白名单
        whitelist.add("127.0.0.1");
        if (!whitelist.contains(ip)) {
            //非白名单
            context.set("isSuccess", false);
            context.setSendZuulResponse(false);
            context.setResponseBody(JSON.toJSONString(SysRes.failure("403", "老铁,你还不是白名单用户!ip=" + ip)));
            context.getResponse().setContentType("application/json; charset=utf-8");
            return null;
        }

        return null;
    }


    public static String getIpAddress(HttpServletRequest request) {
        String ip = request.getHeader("x-forwarded-for");
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("Proxy-Client-IP");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("WL-Proxy-Client-IP");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("HTTP_CLIENT_IP");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getHeader("HTTP_X_FORWARDED_FOR");
        }
        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
            ip = request.getRemoteAddr();
        }
        return ip;
    }

    @ApiOperation("白名单生效")
    @PostMapping("/whiteIpEffect")
    public SysRes whiteIpEffect() {
        whitelist = ipTblDao.findIps(DictIpStatus.white_2.getIndex());
        log.info("白名单生效|whitelist={}", whitelist);
        return SysRes.success(whitelist);
    }

}

 


总结

我这里是ip存储到库里,加了个后门刷新,也可以写个定时任务触发。

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值