ShiroConfig.java 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338
  1. package com.qxgmat.util.shiro;
  2. import com.nuliji.tools.shiro.DevelopFilter;
  3. import com.nuliji.tools.shiro.DevelopRealm;
  4. import com.nuliji.tools.shiro.RealmAuthenticator;
  5. import com.nuliji.tools.shiro.RoleFilter;
  6. import com.nuliji.tools.shiro.cache.RedisManager;
  7. import com.nuliji.tools.shiro.cache.CustomCacheManager;
  8. import com.nuliji.tools.shiro.cache.RedisCacheProvider;
  9. import com.nuliji.tools.shiro.session.CustomSessionDao;
  10. import com.nuliji.tools.shiro.session.RedisSessionRepository;
  11. import com.nuliji.tools.shiro.session.SessionRepository;
  12. import org.apache.shiro.authc.credential.HashedCredentialsMatcher;
  13. import org.apache.shiro.authc.credential.PasswordMatcher;
  14. import org.apache.shiro.authc.credential.SimpleCredentialsMatcher;
  15. import org.apache.shiro.authc.pam.AtLeastOneSuccessfulStrategy;
  16. import org.apache.shiro.cache.CacheManager;
  17. import org.apache.shiro.codec.Base64;
  18. import org.apache.shiro.realm.Realm;
  19. import org.apache.shiro.session.Session;
  20. import org.apache.shiro.session.SessionListener;
  21. import org.apache.shiro.session.mgt.ExecutorServiceSessionValidationScheduler;
  22. import org.apache.shiro.session.mgt.SessionManager;
  23. import org.apache.shiro.session.mgt.eis.JavaUuidSessionIdGenerator;
  24. import org.apache.shiro.session.mgt.eis.SessionDAO;
  25. import org.apache.shiro.session.mgt.eis.SessionIdGenerator;
  26. import org.apache.shiro.spring.LifecycleBeanPostProcessor;
  27. import org.apache.shiro.spring.security.interceptor.AuthorizationAttributeSourceAdvisor;
  28. import org.apache.shiro.spring.web.ShiroFilterFactoryBean;
  29. import org.apache.shiro.spring.web.config.DefaultShiroFilterChainDefinition;
  30. import org.apache.shiro.spring.web.config.ShiroFilterChainDefinition;
  31. import org.apache.shiro.web.mgt.CookieRememberMeManager;
  32. import org.apache.shiro.web.mgt.DefaultWebSecurityManager;
  33. import org.apache.shiro.web.servlet.Cookie;
  34. import org.apache.shiro.web.servlet.SimpleCookie;
  35. import org.apache.shiro.web.session.mgt.DefaultWebSessionManager;
  36. import org.springframework.aop.framework.autoproxy.DefaultAdvisorAutoProxyCreator;
  37. import org.springframework.context.annotation.Bean;
  38. import org.springframework.context.annotation.Configuration;
  39. import org.springframework.context.annotation.DependsOn;
  40. import org.springframework.data.redis.connection.RedisConnectionFactory;
  41. import javax.servlet.Filter;
  42. import java.io.Serializable;
  43. import java.util.ArrayList;
  44. import java.util.Collection;
  45. import java.util.Map;
  46. @Configuration
  47. public class ShiroConfig {
  48. @Bean
  49. public ShiroFilterChainDefinition shiroFilterChainDefinition() {
  50. DefaultShiroFilterChainDefinition chain = new DefaultShiroFilterChainDefinition();
  51. chain.addPathDefinition("/admin/auth/**", "anon");
  52. chain.addPathDefinition("/admin/**", "role[manager]");
  53. chain.addPathDefinition("/api/my/**", "role[user]");
  54. chain.addPathDefinition("/api/question/**", "role[user]");
  55. chain.addPathDefinition("/**", "anon");
  56. return chain;
  57. }
  58. @Bean
  59. public ShiroFilterFactoryBean getShiroFilterFactoryBean(DefaultWebSecurityManager securityManager) {
  60. ShiroFilterFactoryBean shiroFilterFactoryBean = new ShiroFilterFactoryBean();
  61. // 必须设置 SecurityManager
  62. shiroFilterFactoryBean.setSecurityManager(securityManager);
  63. Map<String, Filter> filters = shiroFilterFactoryBean.getFilters();
  64. DevelopFilter developFilter = new DevelopFilter();
  65. RoleFilter roleFilter = new RoleFilter();
  66. filters.put("role", roleFilter);
  67. filters.put("develop", developFilter);
  68. shiroFilterFactoryBean.setFilters(filters);
  69. shiroFilterFactoryBean.setFilterChainDefinitionMap(shiroFilterChainDefinition().getFilterChainMap());
  70. return shiroFilterFactoryBean;
  71. }
  72. @Bean
  73. public RedisManager redisManager(RedisConnectionFactory factory){
  74. RedisManager redisManager = new RedisManager();
  75. redisManager.setFactory(factory);
  76. redisManager.setExpire(86400000);
  77. return redisManager;
  78. }
  79. @Bean
  80. public RedisCacheProvider redisCacheProvider(RedisManager redisManager){
  81. RedisCacheProvider redisCacheProvider = new RedisCacheProvider();
  82. redisCacheProvider.setRedisManager(redisManager);
  83. return redisCacheProvider;
  84. }
  85. @Bean
  86. public SessionRepository redisSessionRepository(RedisManager redisManager){
  87. RedisSessionRepository redisSessionRepository = new RedisSessionRepository();
  88. redisSessionRepository.setRedisManager(redisManager);
  89. return redisSessionRepository;
  90. }
  91. @Bean
  92. public CacheManager customCacheManager(RedisCacheProvider redisCacheProvider){
  93. CustomCacheManager customCacheManager = new CustomCacheManager();
  94. customCacheManager.setCacheProvider(redisCacheProvider);
  95. return customCacheManager;
  96. }
  97. /**
  98. * 加密方式
  99. *
  100. * @return
  101. */
  102. @Bean
  103. public HashedCredentialsMatcher hashedCredentialsMatcher() {
  104. HashedCredentialsMatcher hashedCredentialsMatcher = new HashedCredentialsMatcher();
  105. hashedCredentialsMatcher.setHashAlgorithmName("md5");// 散列算法:这里使用MD5算法;
  106. hashedCredentialsMatcher.setHashIterations(2);// 散列的次数,比如散列两次,相当于md5(md5(""));
  107. hashedCredentialsMatcher.setStoredCredentialsHexEncoded(false);// 表示是否存储散列后的密码为16进制,需要和生成密码时的一样,默认是base64;
  108. return hashedCredentialsMatcher;
  109. }
  110. @Bean
  111. public UserRealm userRealm() {
  112. UserRealm userRealm = new UserRealm();
  113. // userRealm.setCredentialsMatcher(new SimpleCredentialsMatcher());
  114. userRealm.setCachingEnabled(false);
  115. return userRealm;
  116. }
  117. @Bean
  118. public ManagerRealm managerRealm() {
  119. ManagerRealm managerRealm = new ManagerRealm();
  120. // managerRealm.setCredentialsMatcher(new SimpleCredentialsMatcher());
  121. managerRealm.setCachingEnabled(false);
  122. return managerRealm;
  123. }
  124. @Bean
  125. public OauthRealm oauthRealm(){
  126. OauthRealm oauthRealm = new OauthRealm();
  127. oauthRealm.setCachingEnabled(false);
  128. return oauthRealm;
  129. }
  130. @Bean
  131. public DevelopRealm developRealm(){
  132. DevelopRealm developRealm = new DevelopRealm();
  133. developRealm.setCachingEnabled(false);
  134. return developRealm;
  135. }
  136. @Bean
  137. public Collection<Realm> realms() {
  138. Collection<Realm> realms = new ArrayList<>();
  139. realms.add(userRealm());
  140. realms.add(oauthRealm());
  141. realms.add(managerRealm());
  142. realms.add(developRealm());
  143. return realms;
  144. }
  145. /**
  146. * 配置认证策略,只要有一个Realm认证成功即可,并且返回所有认证成功信息
  147. *
  148. * @return
  149. */
  150. @Bean
  151. AtLeastOneSuccessfulStrategy authenticationStrategy() {
  152. return new AtLeastOneSuccessfulStrategy();
  153. }
  154. /**
  155. * 配置使用自定义认证器,可以实现多Realm认证,并且可以指定特定Realm处理特定类型的验证
  156. *
  157. * @return
  158. */
  159. @Bean
  160. RealmAuthenticator authenticator() {
  161. RealmAuthenticator authenticator = new RealmAuthenticator();
  162. authenticator.setAuthenticationStrategy(authenticationStrategy());
  163. return authenticator;
  164. }
  165. @Bean
  166. public Cookie rememberMeCookie() {
  167. // 这个参数是cookie的名称,对应前端的checkbox的name = rememberMe
  168. SimpleCookie simpleCookie = new SimpleCookie("rememberMe");
  169. // <!-- 记住我cookie生效时间30天 ,单位秒;-->
  170. simpleCookie.setMaxAge(259200);
  171. return simpleCookie;
  172. }
  173. /**
  174. * CookieRememberMeManager
  175. *
  176. * @return
  177. */
  178. @Bean
  179. public CookieRememberMeManager rememberMeManager() {
  180. CookieRememberMeManager cookieRememberMeManager = new CookieRememberMeManager();
  181. cookieRememberMeManager.setCookie(rememberMeCookie());
  182. cookieRememberMeManager.setCipherKey(Base64.decode("2AvVhdsgUs0FSA3SDFAdag=="));
  183. return cookieRememberMeManager;
  184. }
  185. // @Bean
  186. // public MyShiroSessionListener myShiroSessionListener() {
  187. // return new MyShiroSessionListener();
  188. // }
  189. /**
  190. * 会话监听器
  191. *
  192. * @return
  193. */
  194. @Bean
  195. public Collection<SessionListener> sessionListeners() {
  196. Collection<SessionListener> listeners = new ArrayList<>();
  197. // listeners.add(myShiroSessionListener());
  198. return listeners;
  199. }
  200. /**
  201. * 会话ID生成器
  202. *
  203. * @return
  204. */
  205. @Bean
  206. public SessionIdGenerator sessionIdGenerator() {
  207. SessionIdGenerator idGenerator = new SessionIdGenerator() {
  208. @Override
  209. public Serializable generateId(Session session) {
  210. Serializable uuid = new JavaUuidSessionIdGenerator().generateId(session);
  211. System.out.println("sessionIdGenerator:" + uuid);
  212. return uuid;
  213. }
  214. };
  215. return idGenerator;
  216. }
  217. /**
  218. * 会话DAO
  219. *
  220. * @return
  221. */
  222. @Bean
  223. public CustomSessionDao sessionDao(SessionRepository sessionRepository) {
  224. CustomSessionDao sessionDao = new CustomSessionDao();
  225. sessionDao.setSessionRepository(sessionRepository);
  226. sessionDao.setSessionIdGenerator(sessionIdGenerator());
  227. return sessionDao;
  228. }
  229. /**
  230. * 处理session有效期
  231. *
  232. * @return
  233. */
  234. @Bean
  235. public ExecutorServiceSessionValidationScheduler sessionValidationScheduler() {
  236. ExecutorServiceSessionValidationScheduler sessionValidationScheduler = new ExecutorServiceSessionValidationScheduler();
  237. sessionValidationScheduler.setInterval(1800000);
  238. return sessionValidationScheduler;
  239. }
  240. @Bean(name = "sessionManager")
  241. public SessionManager sessionManager(SessionDAO sessionDAO) {
  242. DefaultWebSessionManager sessionManager = new DefaultWebSessionManager();
  243. Cookie sessionIdCookie = new SimpleCookie("JSESSIONID");
  244. sessionIdCookie.setPath("/");
  245. sessionManager.setSessionIdCookie(sessionIdCookie);
  246. sessionManager.setGlobalSessionTimeout(86400000);
  247. sessionManager.setDeleteInvalidSessions(true);
  248. sessionManager.setSessionIdUrlRewritingEnabled(false);
  249. sessionManager.setSessionValidationScheduler(sessionValidationScheduler());
  250. sessionManager.setSessionValidationSchedulerEnabled(true);
  251. sessionManager.setSessionListeners(sessionListeners());
  252. sessionManager.setSessionDAO(sessionDAO);
  253. return sessionManager;
  254. }
  255. /**
  256. * 会话管理器
  257. *
  258. * @return
  259. */
  260. @Bean(name = "securityManager")
  261. public DefaultWebSecurityManager securityManager(CacheManager cacheManager, SessionManager sessionManager) {
  262. DefaultWebSecurityManager securityManager = new DefaultWebSecurityManager();
  263. securityManager.setCacheManager(cacheManager);
  264. securityManager.setAuthenticator(authenticator());
  265. securityManager.setRememberMeManager(rememberMeManager());
  266. securityManager.setRealms(realms());
  267. securityManager.setSessionManager(sessionManager);
  268. return securityManager;
  269. }
  270. /**
  271. * 开启shiro注解 ---- 注解权限
  272. *
  273. * @param securityManager
  274. * @return
  275. */
  276. @Bean
  277. public AuthorizationAttributeSourceAdvisor authorizationAttributeSourceAdvisor(org.apache.shiro.mgt.SecurityManager securityManager) {
  278. AuthorizationAttributeSourceAdvisor authorizationAttributeSourceAdvisor = new AuthorizationAttributeSourceAdvisor();
  279. authorizationAttributeSourceAdvisor.setSecurityManager(securityManager);
  280. return authorizationAttributeSourceAdvisor;
  281. }
  282. /**
  283. * Shiro生命周期处理器 ---可以自定的来调用配置在 Spring IOC 容器中 shiro bean 的生命周期方法.
  284. *
  285. * @return
  286. */
  287. @Bean
  288. public LifecycleBeanPostProcessor lifecycleBeanPostProcessor() {
  289. return new LifecycleBeanPostProcessor();
  290. }
  291. /**
  292. * 开启shiro注解 ----启用 IOC 容器中使用 shiro 的注解. 但必须在配置了 LifecycleBeanPostProcessor
  293. * 之后才可以使用
  294. *
  295. * @return
  296. */
  297. @Bean
  298. @DependsOn("lifecycleBeanPostProcessor")
  299. public DefaultAdvisorAutoProxyCreator getDefaultAdvisorAutoProxyCreator() {
  300. DefaultAdvisorAutoProxyCreator daap = new DefaultAdvisorAutoProxyCreator();
  301. daap.setProxyTargetClass(true);
  302. return daap;
  303. }
  304. }