ShiroConfig.java 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352
  1. package com.qxgmat.util.shiro;
  2. import com.nuliji.tools.shiro.*;
  3. import com.nuliji.tools.shiro.cache.RedisManager;
  4. import com.nuliji.tools.shiro.cache.CustomCacheManager;
  5. import com.nuliji.tools.shiro.cache.RedisCacheProvider;
  6. import com.nuliji.tools.shiro.inter.HeaderTokenManager;
  7. import com.nuliji.tools.shiro.session.CustomSessionDao;
  8. import com.nuliji.tools.shiro.session.RedisSessionRepository;
  9. import com.nuliji.tools.shiro.session.SessionRepository;
  10. import com.qxgmat.util.shiro.impl.UserTokenManager;
  11. import org.apache.shiro.authc.credential.HashedCredentialsMatcher;
  12. import org.apache.shiro.authc.pam.AtLeastOneSuccessfulStrategy;
  13. import org.apache.shiro.cache.CacheManager;
  14. import org.apache.shiro.codec.Base64;
  15. import org.apache.shiro.realm.Realm;
  16. import org.apache.shiro.session.Session;
  17. import org.apache.shiro.session.SessionListener;
  18. import org.apache.shiro.session.mgt.ExecutorServiceSessionValidationScheduler;
  19. import org.apache.shiro.session.mgt.SessionManager;
  20. import org.apache.shiro.session.mgt.eis.JavaUuidSessionIdGenerator;
  21. import org.apache.shiro.session.mgt.eis.SessionDAO;
  22. import org.apache.shiro.session.mgt.eis.SessionIdGenerator;
  23. import org.apache.shiro.spring.LifecycleBeanPostProcessor;
  24. import org.apache.shiro.spring.security.interceptor.AuthorizationAttributeSourceAdvisor;
  25. import org.apache.shiro.spring.web.ShiroFilterFactoryBean;
  26. import org.apache.shiro.spring.web.config.DefaultShiroFilterChainDefinition;
  27. import org.apache.shiro.spring.web.config.ShiroFilterChainDefinition;
  28. import org.apache.shiro.web.mgt.CookieRememberMeManager;
  29. import org.apache.shiro.web.mgt.DefaultWebSecurityManager;
  30. import org.apache.shiro.web.servlet.Cookie;
  31. import org.apache.shiro.web.servlet.SimpleCookie;
  32. import org.apache.shiro.web.session.mgt.DefaultWebSessionManager;
  33. import org.springframework.aop.framework.autoproxy.DefaultAdvisorAutoProxyCreator;
  34. import org.springframework.context.annotation.Bean;
  35. import org.springframework.context.annotation.Configuration;
  36. import org.springframework.context.annotation.DependsOn;
  37. import org.springframework.data.redis.connection.RedisConnectionFactory;
  38. import javax.servlet.Filter;
  39. import java.io.Serializable;
  40. import java.util.ArrayList;
  41. import java.util.Collection;
  42. import java.util.Map;
  43. @Configuration
  44. public class ShiroConfig {
  45. @Bean
  46. public ShiroFilterChainDefinition shiroFilterChainDefinition() {
  47. DefaultShiroFilterChainDefinition chain = new DefaultShiroFilterChainDefinition();
  48. chain.addPathDefinition("/admin/auth/**", "anon");
  49. chain.addPathDefinition("/admin/**", "role[manager]");
  50. chain.addPathDefinition("/api/auth/**", "anon");
  51. chain.addPathDefinition("/api/my/**", "token,role[user]");
  52. chain.addPathDefinition("/**", "anon");
  53. return chain;
  54. }
  55. @Bean(name = "shiroFilter")
  56. public ShiroFilterFactoryBean getShiroFilterFactoryBean(DefaultWebSecurityManager securityManager) {
  57. ShiroFilterFactoryBean shiroFilterFactoryBean = new ShiroFilterFactoryBean();
  58. // 必须设置 SecurityManager
  59. shiroFilterFactoryBean.setSecurityManager(securityManager);
  60. Map<String, Filter> filters = shiroFilterFactoryBean.getFilters();
  61. DevelopFilter developFilter = new DevelopFilter();
  62. RoleFilter roleFilter = new RoleFilter();
  63. TokenFilter tokenFilter = new TokenFilter(headerTokenManager());
  64. filters.put("role", roleFilter);
  65. filters.put("develop", developFilter);
  66. filters.put("token", tokenFilter);
  67. shiroFilterFactoryBean.setFilters(filters);
  68. shiroFilterFactoryBean.setFilterChainDefinitionMap(shiroFilterChainDefinition().getFilterChainMap());
  69. return shiroFilterFactoryBean;
  70. }
  71. @Bean
  72. public RedisManager redisManager(RedisConnectionFactory factory){
  73. RedisManager redisManager = new RedisManager();
  74. redisManager.setFactory(factory);
  75. redisManager.setExpire(86400000);
  76. return redisManager;
  77. }
  78. @Bean
  79. public RedisCacheProvider redisCacheProvider(RedisManager redisManager){
  80. RedisCacheProvider redisCacheProvider = new RedisCacheProvider();
  81. redisCacheProvider.setRedisManager(redisManager);
  82. return redisCacheProvider;
  83. }
  84. @Bean
  85. public SessionRepository redisSessionRepository(RedisManager redisManager){
  86. RedisSessionRepository redisSessionRepository = new RedisSessionRepository();
  87. redisSessionRepository.setRedisManager(redisManager);
  88. return redisSessionRepository;
  89. }
  90. @Bean
  91. public CacheManager customCacheManager(RedisCacheProvider redisCacheProvider){
  92. CustomCacheManager customCacheManager = new CustomCacheManager();
  93. customCacheManager.setCacheProvider(redisCacheProvider);
  94. return customCacheManager;
  95. }
  96. /**
  97. * 加密方式
  98. *
  99. * @return
  100. */
  101. @Bean
  102. public HashedCredentialsMatcher hashedCredentialsMatcher() {
  103. HashedCredentialsMatcher hashedCredentialsMatcher = new HashedCredentialsMatcher();
  104. hashedCredentialsMatcher.setHashAlgorithmName("md5");// 散列算法:这里使用MD5算法;
  105. hashedCredentialsMatcher.setHashIterations(2);// 散列的次数,比如散列两次,相当于md5(md5(""));
  106. hashedCredentialsMatcher.setStoredCredentialsHexEncoded(false);// 表示是否存储散列后的密码为16进制,需要和生成密码时的一样,默认是base64;
  107. return hashedCredentialsMatcher;
  108. }
  109. @Bean
  110. public HeaderTokenManager headerTokenManager() {
  111. UserTokenManager userTokenManager = new UserTokenManager();
  112. return userTokenManager;
  113. }
  114. @Bean
  115. public UserRealm userRealm() {
  116. UserRealm userRealm = new UserRealm();
  117. // userRealm.setCredentialsMatcher(new SimpleCredentialsMatcher());
  118. userRealm.setCachingEnabled(true);
  119. return userRealm;
  120. }
  121. @Bean
  122. public TokenRealm tokenRealm() {
  123. TokenRealm tokenRealm = new TokenRealm();
  124. // userRealm.setCredentialsMatcher(new SimpleCredentialsMatcher());
  125. tokenRealm.setCachingEnabled(true);
  126. return tokenRealm;
  127. }
  128. @Bean
  129. public ManagerRealm managerRealm() {
  130. ManagerRealm managerRealm = new ManagerRealm();
  131. // managerRealm.setCredentialsMatcher(new SimpleCredentialsMatcher());
  132. managerRealm.setCachingEnabled(true);
  133. return managerRealm;
  134. }
  135. @Bean
  136. public OauthRealm oauthRealm(){
  137. OauthRealm oauthRealm = new OauthRealm();
  138. oauthRealm.setCachingEnabled(false);
  139. return oauthRealm;
  140. }
  141. @Bean
  142. public DevelopRealm developRealm(){
  143. DevelopRealm developRealm = new DevelopRealm();
  144. developRealm.setCachingEnabled(true);
  145. return developRealm;
  146. }
  147. @Bean
  148. public Collection<Realm> realms() {
  149. Collection<Realm> realms = new ArrayList<>();
  150. realms.add(userRealm());
  151. realms.add(tokenRealm());
  152. realms.add(oauthRealm());
  153. realms.add(managerRealm());
  154. realms.add(developRealm());
  155. return realms;
  156. }
  157. /**
  158. * 配置认证策略,只要有一个Realm认证成功即可,并且返回所有认证成功信息
  159. *
  160. * @return
  161. */
  162. @Bean
  163. AtLeastOneSuccessfulStrategy authenticationStrategy() {
  164. return new AtLeastOneSuccessfulStrategy();
  165. }
  166. /**
  167. * 配置使用自定义认证器,可以实现多Realm认证,并且可以指定特定Realm处理特定类型的验证
  168. *
  169. * @return
  170. */
  171. @Bean
  172. RealmAuthenticator authenticator() {
  173. RealmAuthenticator authenticator = new RealmAuthenticator();
  174. authenticator.setAuthenticationStrategy(authenticationStrategy());
  175. return authenticator;
  176. }
  177. @Bean
  178. public Cookie rememberMeCookie() {
  179. // 这个参数是cookie的名称,对应前端的checkbox的name = rememberMe
  180. SimpleCookie simpleCookie = new SimpleCookie("rememberMe");
  181. // <!-- 记住我cookie生效时间30天 ,单位秒;-->
  182. simpleCookie.setMaxAge(259200);
  183. return simpleCookie;
  184. }
  185. /**
  186. * CookieRememberMeManager
  187. *
  188. * @return
  189. */
  190. @Bean
  191. public CookieRememberMeManager rememberMeManager() {
  192. CookieRememberMeManager cookieRememberMeManager = new CookieRememberMeManager();
  193. cookieRememberMeManager.setCookie(rememberMeCookie());
  194. cookieRememberMeManager.setCipherKey(Base64.decode("2AvVhdsgUs0FSA3SDFAdag=="));
  195. return cookieRememberMeManager;
  196. }
  197. // @Bean
  198. // public MyShiroSessionListener myShiroSessionListener() {
  199. // return new MyShiroSessionListener();
  200. // }
  201. /**
  202. * 会话监听器
  203. *
  204. * @return
  205. */
  206. @Bean
  207. public Collection<SessionListener> sessionListeners() {
  208. Collection<SessionListener> listeners = new ArrayList<>();
  209. // listeners.add(myShiroSessionListener());
  210. return listeners;
  211. }
  212. /**
  213. * 会话ID生成器
  214. *
  215. * @return
  216. */
  217. @Bean
  218. public SessionIdGenerator sessionIdGenerator() {
  219. SessionIdGenerator idGenerator = new SessionIdGenerator() {
  220. @Override
  221. public Serializable generateId(Session session) {
  222. Serializable uuid = new JavaUuidSessionIdGenerator().generateId(session);
  223. System.out.println("sessionIdGenerator:" + uuid);
  224. return uuid;
  225. }
  226. };
  227. return idGenerator;
  228. }
  229. /**
  230. * 会话DAO
  231. *
  232. * @return
  233. */
  234. @Bean
  235. public CustomSessionDao sessionDao(SessionRepository sessionRepository) {
  236. CustomSessionDao sessionDao = new CustomSessionDao();
  237. sessionDao.setSessionRepository(sessionRepository);
  238. sessionDao.setSessionIdGenerator(sessionIdGenerator());
  239. return sessionDao;
  240. }
  241. /**
  242. * 处理session有效期
  243. *
  244. * @return
  245. */
  246. @Bean
  247. public ExecutorServiceSessionValidationScheduler sessionValidationScheduler() {
  248. ExecutorServiceSessionValidationScheduler sessionValidationScheduler = new ExecutorServiceSessionValidationScheduler();
  249. sessionValidationScheduler.setInterval(1800000);
  250. return sessionValidationScheduler;
  251. }
  252. @Bean(name = "sessionManager")
  253. public SessionManager sessionManager(SessionDAO sessionDAO) {
  254. DefaultWebSessionManager sessionManager = new DefaultWebSessionManager();
  255. Cookie sessionIdCookie = new SimpleCookie("JSESSIONID");
  256. sessionIdCookie.setPath("/");
  257. sessionManager.setSessionIdCookie(sessionIdCookie);
  258. sessionManager.setGlobalSessionTimeout(86400000);
  259. sessionManager.setDeleteInvalidSessions(true);
  260. sessionManager.setSessionIdUrlRewritingEnabled(false);
  261. sessionManager.setSessionValidationScheduler(sessionValidationScheduler());
  262. sessionManager.setSessionValidationSchedulerEnabled(true);
  263. sessionManager.setSessionListeners(sessionListeners());
  264. sessionManager.setSessionDAO(sessionDAO);
  265. return sessionManager;
  266. }
  267. /**
  268. * 会话管理器
  269. *
  270. * @return
  271. */
  272. @Bean(name = "securityManager")
  273. public DefaultWebSecurityManager securityManager(CacheManager cacheManager, SessionManager sessionManager) {
  274. DefaultWebSecurityManager securityManager = new DefaultWebSecurityManager();
  275. securityManager.setCacheManager(cacheManager);
  276. securityManager.setAuthenticator(authenticator());
  277. securityManager.setRememberMeManager(rememberMeManager());
  278. securityManager.setRealms(realms());
  279. securityManager.setSessionManager(sessionManager);
  280. return securityManager;
  281. }
  282. /**
  283. * 开启shiro注解 ---- 注解权限
  284. *
  285. * @param securityManager
  286. * @return
  287. */
  288. @Bean
  289. public AuthorizationAttributeSourceAdvisor authorizationAttributeSourceAdvisor(org.apache.shiro.mgt.SecurityManager securityManager) {
  290. AuthorizationAttributeSourceAdvisor authorizationAttributeSourceAdvisor = new AuthorizationAttributeSourceAdvisor();
  291. authorizationAttributeSourceAdvisor.setSecurityManager(securityManager);
  292. return authorizationAttributeSourceAdvisor;
  293. }
  294. /**
  295. * Shiro生命周期处理器 ---可以自定的来调用配置在 Spring IOC 容器中 shiro bean 的生命周期方法.
  296. *
  297. * @return
  298. */
  299. @Bean
  300. public LifecycleBeanPostProcessor lifecycleBeanPostProcessor() {
  301. return new LifecycleBeanPostProcessor();
  302. }
  303. /**
  304. * 开启shiro注解 ----启用 IOC 容器中使用 shiro 的注解. 但必须在配置了 LifecycleBeanPostProcessor
  305. * 之后才可以使用
  306. *
  307. * @return
  308. */
  309. @Bean
  310. @DependsOn("lifecycleBeanPostProcessor")
  311. public DefaultAdvisorAutoProxyCreator getDefaultAdvisorAutoProxyCreator() {
  312. DefaultAdvisorAutoProxyCreator daap = new DefaultAdvisorAutoProxyCreator();
  313. daap.setProxyTargetClass(true);
  314. return daap;
  315. }
  316. }