ShiroConfig.java 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353
  1. package com.qxgmat.util.shiro;
  2. import com.nuliji.tools.shiro.*;
  3. import com.nuliji.tools.shiro.cache.RedisManager;
  4. import com.nuliji.tools.shiro.cache.CustomCacheManager;
  5. import com.nuliji.tools.shiro.cache.RedisCacheProvider;
  6. import com.nuliji.tools.shiro.inter.HeaderTokenManager;
  7. import com.nuliji.tools.shiro.session.CustomSessionDao;
  8. import com.nuliji.tools.shiro.session.RedisSessionRepository;
  9. import com.nuliji.tools.shiro.session.SessionRepository;
  10. import com.qxgmat.util.shiro.impl.UserTokenManager;
  11. import org.apache.shiro.authc.credential.HashedCredentialsMatcher;
  12. import org.apache.shiro.authc.pam.AtLeastOneSuccessfulStrategy;
  13. import org.apache.shiro.cache.CacheManager;
  14. import org.apache.shiro.codec.Base64;
  15. import org.apache.shiro.realm.Realm;
  16. import org.apache.shiro.session.Session;
  17. import org.apache.shiro.session.SessionListener;
  18. import org.apache.shiro.session.mgt.ExecutorServiceSessionValidationScheduler;
  19. import org.apache.shiro.session.mgt.SessionManager;
  20. import org.apache.shiro.session.mgt.eis.JavaUuidSessionIdGenerator;
  21. import org.apache.shiro.session.mgt.eis.SessionDAO;
  22. import org.apache.shiro.session.mgt.eis.SessionIdGenerator;
  23. import org.apache.shiro.spring.LifecycleBeanPostProcessor;
  24. import org.apache.shiro.spring.security.interceptor.AuthorizationAttributeSourceAdvisor;
  25. import org.apache.shiro.spring.web.ShiroFilterFactoryBean;
  26. import org.apache.shiro.spring.web.config.DefaultShiroFilterChainDefinition;
  27. import org.apache.shiro.spring.web.config.ShiroFilterChainDefinition;
  28. import org.apache.shiro.web.mgt.CookieRememberMeManager;
  29. import org.apache.shiro.web.mgt.DefaultWebSecurityManager;
  30. import org.apache.shiro.web.servlet.Cookie;
  31. import org.apache.shiro.web.servlet.SimpleCookie;
  32. import org.apache.shiro.web.session.mgt.DefaultWebSessionManager;
  33. import org.springframework.aop.framework.autoproxy.DefaultAdvisorAutoProxyCreator;
  34. import org.springframework.context.annotation.Bean;
  35. import org.springframework.context.annotation.Configuration;
  36. import org.springframework.context.annotation.DependsOn;
  37. import org.springframework.data.redis.connection.RedisConnectionFactory;
  38. import javax.servlet.Filter;
  39. import java.io.Serializable;
  40. import java.util.ArrayList;
  41. import java.util.Collection;
  42. import java.util.Map;
  43. @Configuration
  44. public class ShiroConfig {
  45. @Bean
  46. public ShiroFilterChainDefinition shiroFilterChainDefinition() {
  47. DefaultShiroFilterChainDefinition chain = new DefaultShiroFilterChainDefinition();
  48. chain.addPathDefinition("/admin/auth/**", "anon");
  49. chain.addPathDefinition("/admin/**", "role[manager]");
  50. chain.addPathDefinition("/api/auth/**", "anon");
  51. chain.addPathDefinition("/api/my/**", "token,role[user]");
  52. chain.addPathDefinition("/api/question/**", "token,role[user]");
  53. chain.addPathDefinition("/**", "anon");
  54. return chain;
  55. }
  56. @Bean(name = "shiroFilter")
  57. public ShiroFilterFactoryBean getShiroFilterFactoryBean(DefaultWebSecurityManager securityManager) {
  58. ShiroFilterFactoryBean shiroFilterFactoryBean = new ShiroFilterFactoryBean();
  59. // 必须设置 SecurityManager
  60. shiroFilterFactoryBean.setSecurityManager(securityManager);
  61. Map<String, Filter> filters = shiroFilterFactoryBean.getFilters();
  62. DevelopFilter developFilter = new DevelopFilter();
  63. RoleFilter roleFilter = new RoleFilter();
  64. TokenFilter tokenFilter = new TokenFilter(headerTokenManager());
  65. filters.put("role", roleFilter);
  66. filters.put("develop", developFilter);
  67. filters.put("token", tokenFilter);
  68. shiroFilterFactoryBean.setFilters(filters);
  69. shiroFilterFactoryBean.setFilterChainDefinitionMap(shiroFilterChainDefinition().getFilterChainMap());
  70. return shiroFilterFactoryBean;
  71. }
  72. @Bean
  73. public RedisManager redisManager(RedisConnectionFactory factory){
  74. RedisManager redisManager = new RedisManager();
  75. redisManager.setFactory(factory);
  76. redisManager.setExpire(86400000);
  77. return redisManager;
  78. }
  79. @Bean
  80. public RedisCacheProvider redisCacheProvider(RedisManager redisManager){
  81. RedisCacheProvider redisCacheProvider = new RedisCacheProvider();
  82. redisCacheProvider.setRedisManager(redisManager);
  83. return redisCacheProvider;
  84. }
  85. @Bean
  86. public SessionRepository redisSessionRepository(RedisManager redisManager){
  87. RedisSessionRepository redisSessionRepository = new RedisSessionRepository();
  88. redisSessionRepository.setRedisManager(redisManager);
  89. return redisSessionRepository;
  90. }
  91. @Bean
  92. public CacheManager customCacheManager(RedisCacheProvider redisCacheProvider){
  93. CustomCacheManager customCacheManager = new CustomCacheManager();
  94. customCacheManager.setCacheProvider(redisCacheProvider);
  95. return customCacheManager;
  96. }
  97. /**
  98. * 加密方式
  99. *
  100. * @return
  101. */
  102. @Bean
  103. public HashedCredentialsMatcher hashedCredentialsMatcher() {
  104. HashedCredentialsMatcher hashedCredentialsMatcher = new HashedCredentialsMatcher();
  105. hashedCredentialsMatcher.setHashAlgorithmName("md5");// 散列算法:这里使用MD5算法;
  106. hashedCredentialsMatcher.setHashIterations(2);// 散列的次数,比如散列两次,相当于md5(md5(""));
  107. hashedCredentialsMatcher.setStoredCredentialsHexEncoded(false);// 表示是否存储散列后的密码为16进制,需要和生成密码时的一样,默认是base64;
  108. return hashedCredentialsMatcher;
  109. }
  110. @Bean
  111. public HeaderTokenManager headerTokenManager() {
  112. UserTokenManager userTokenManager = new UserTokenManager();
  113. return userTokenManager;
  114. }
  115. @Bean
  116. public UserRealm userRealm() {
  117. UserRealm userRealm = new UserRealm();
  118. // userRealm.setCredentialsMatcher(new SimpleCredentialsMatcher());
  119. userRealm.setCachingEnabled(true);
  120. return userRealm;
  121. }
  122. @Bean
  123. public TokenRealm tokenRealm() {
  124. TokenRealm tokenRealm = new TokenRealm();
  125. // userRealm.setCredentialsMatcher(new SimpleCredentialsMatcher());
  126. tokenRealm.setCachingEnabled(true);
  127. return tokenRealm;
  128. }
  129. @Bean
  130. public ManagerRealm managerRealm() {
  131. ManagerRealm managerRealm = new ManagerRealm();
  132. // managerRealm.setCredentialsMatcher(new SimpleCredentialsMatcher());
  133. managerRealm.setCachingEnabled(true);
  134. return managerRealm;
  135. }
  136. @Bean
  137. public OauthRealm oauthRealm(){
  138. OauthRealm oauthRealm = new OauthRealm();
  139. oauthRealm.setCachingEnabled(false);
  140. return oauthRealm;
  141. }
  142. @Bean
  143. public DevelopRealm developRealm(){
  144. DevelopRealm developRealm = new DevelopRealm();
  145. developRealm.setCachingEnabled(true);
  146. return developRealm;
  147. }
  148. @Bean
  149. public Collection<Realm> realms() {
  150. Collection<Realm> realms = new ArrayList<>();
  151. realms.add(userRealm());
  152. realms.add(tokenRealm());
  153. realms.add(oauthRealm());
  154. realms.add(managerRealm());
  155. realms.add(developRealm());
  156. return realms;
  157. }
  158. /**
  159. * 配置认证策略,只要有一个Realm认证成功即可,并且返回所有认证成功信息
  160. *
  161. * @return
  162. */
  163. @Bean
  164. AtLeastOneSuccessfulStrategy authenticationStrategy() {
  165. return new AtLeastOneSuccessfulStrategy();
  166. }
  167. /**
  168. * 配置使用自定义认证器,可以实现多Realm认证,并且可以指定特定Realm处理特定类型的验证
  169. *
  170. * @return
  171. */
  172. @Bean
  173. RealmAuthenticator authenticator() {
  174. RealmAuthenticator authenticator = new RealmAuthenticator();
  175. authenticator.setAuthenticationStrategy(authenticationStrategy());
  176. return authenticator;
  177. }
  178. @Bean
  179. public Cookie rememberMeCookie() {
  180. // 这个参数是cookie的名称,对应前端的checkbox的name = rememberMe
  181. SimpleCookie simpleCookie = new SimpleCookie("rememberMe");
  182. // <!-- 记住我cookie生效时间30天 ,单位秒;-->
  183. simpleCookie.setMaxAge(259200);
  184. return simpleCookie;
  185. }
  186. /**
  187. * CookieRememberMeManager
  188. *
  189. * @return
  190. */
  191. @Bean
  192. public CookieRememberMeManager rememberMeManager() {
  193. CookieRememberMeManager cookieRememberMeManager = new CookieRememberMeManager();
  194. cookieRememberMeManager.setCookie(rememberMeCookie());
  195. cookieRememberMeManager.setCipherKey(Base64.decode("2AvVhdsgUs0FSA3SDFAdag=="));
  196. return cookieRememberMeManager;
  197. }
  198. // @Bean
  199. // public MyShiroSessionListener myShiroSessionListener() {
  200. // return new MyShiroSessionListener();
  201. // }
  202. /**
  203. * 会话监听器
  204. *
  205. * @return
  206. */
  207. @Bean
  208. public Collection<SessionListener> sessionListeners() {
  209. Collection<SessionListener> listeners = new ArrayList<>();
  210. // listeners.add(myShiroSessionListener());
  211. return listeners;
  212. }
  213. /**
  214. * 会话ID生成器
  215. *
  216. * @return
  217. */
  218. @Bean
  219. public SessionIdGenerator sessionIdGenerator() {
  220. SessionIdGenerator idGenerator = new SessionIdGenerator() {
  221. @Override
  222. public Serializable generateId(Session session) {
  223. Serializable uuid = new JavaUuidSessionIdGenerator().generateId(session);
  224. System.out.println("sessionIdGenerator:" + uuid);
  225. return uuid;
  226. }
  227. };
  228. return idGenerator;
  229. }
  230. /**
  231. * 会话DAO
  232. *
  233. * @return
  234. */
  235. @Bean
  236. public CustomSessionDao sessionDao(SessionRepository sessionRepository) {
  237. CustomSessionDao sessionDao = new CustomSessionDao();
  238. sessionDao.setSessionRepository(sessionRepository);
  239. sessionDao.setSessionIdGenerator(sessionIdGenerator());
  240. return sessionDao;
  241. }
  242. /**
  243. * 处理session有效期
  244. *
  245. * @return
  246. */
  247. @Bean
  248. public ExecutorServiceSessionValidationScheduler sessionValidationScheduler() {
  249. ExecutorServiceSessionValidationScheduler sessionValidationScheduler = new ExecutorServiceSessionValidationScheduler();
  250. sessionValidationScheduler.setInterval(1800000);
  251. return sessionValidationScheduler;
  252. }
  253. @Bean(name = "sessionManager")
  254. public SessionManager sessionManager(SessionDAO sessionDAO) {
  255. DefaultWebSessionManager sessionManager = new DefaultWebSessionManager();
  256. Cookie sessionIdCookie = new SimpleCookie("JSESSIONID");
  257. sessionIdCookie.setPath("/");
  258. sessionManager.setSessionIdCookie(sessionIdCookie);
  259. sessionManager.setGlobalSessionTimeout(86400000);
  260. sessionManager.setDeleteInvalidSessions(true);
  261. sessionManager.setSessionIdUrlRewritingEnabled(false);
  262. sessionManager.setSessionValidationScheduler(sessionValidationScheduler());
  263. sessionManager.setSessionValidationSchedulerEnabled(true);
  264. sessionManager.setSessionListeners(sessionListeners());
  265. sessionManager.setSessionDAO(sessionDAO);
  266. return sessionManager;
  267. }
  268. /**
  269. * 会话管理器
  270. *
  271. * @return
  272. */
  273. @Bean(name = "securityManager")
  274. public DefaultWebSecurityManager securityManager(CacheManager cacheManager, SessionManager sessionManager) {
  275. DefaultWebSecurityManager securityManager = new DefaultWebSecurityManager();
  276. securityManager.setCacheManager(cacheManager);
  277. securityManager.setAuthenticator(authenticator());
  278. securityManager.setRememberMeManager(rememberMeManager());
  279. securityManager.setRealms(realms());
  280. securityManager.setSessionManager(sessionManager);
  281. return securityManager;
  282. }
  283. /**
  284. * 开启shiro注解 ---- 注解权限
  285. *
  286. * @param securityManager
  287. * @return
  288. */
  289. @Bean
  290. public AuthorizationAttributeSourceAdvisor authorizationAttributeSourceAdvisor(org.apache.shiro.mgt.SecurityManager securityManager) {
  291. AuthorizationAttributeSourceAdvisor authorizationAttributeSourceAdvisor = new AuthorizationAttributeSourceAdvisor();
  292. authorizationAttributeSourceAdvisor.setSecurityManager(securityManager);
  293. return authorizationAttributeSourceAdvisor;
  294. }
  295. /**
  296. * Shiro生命周期处理器 ---可以自定的来调用配置在 Spring IOC 容器中 shiro bean 的生命周期方法.
  297. *
  298. * @return
  299. */
  300. @Bean
  301. public LifecycleBeanPostProcessor lifecycleBeanPostProcessor() {
  302. return new LifecycleBeanPostProcessor();
  303. }
  304. /**
  305. * 开启shiro注解 ----启用 IOC 容器中使用 shiro 的注解. 但必须在配置了 LifecycleBeanPostProcessor
  306. * 之后才可以使用
  307. *
  308. * @return
  309. */
  310. @Bean
  311. @DependsOn("lifecycleBeanPostProcessor")
  312. public DefaultAdvisorAutoProxyCreator getDefaultAdvisorAutoProxyCreator() {
  313. DefaultAdvisorAutoProxyCreator daap = new DefaultAdvisorAutoProxyCreator();
  314. daap.setProxyTargetClass(true);
  315. return daap;
  316. }
  317. }