Spring?Security權(quán)限注解啟動(dòng)及邏輯處理使用示例
啟用注解
@EnableGlobalMethodSecurity(prePostEnabled = true)
正常啟用開(kāi)啟那個(gè)注解就行,下面放下我的配置
package com.fedtech.sys.provider.config.config;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.data.redis.connection.RedisConnectionFactory;
import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity;
import org.springframework.security.oauth2.config.annotation.web.configuration.EnableResourceServer;
import org.springframework.security.oauth2.config.annotation.web.configuration.ResourceServerConfigurerAdapter;
import org.springframework.security.oauth2.config.annotation.web.configurers.ResourceServerSecurityConfigurer;
import org.springframework.security.oauth2.provider.token.TokenStore;
import org.springframework.security.oauth2.provider.token.store.redis.RedisTokenStore;
import javax.annotation.Resource;
/**
* 資源配置
*
* @author <a href = "mailto:njpkhuan@gmail.com" > huan </a >
* @date 2021/1/13
* @since 1.0.0
*/
@Configuration
@EnableResourceServer
@EnableGlobalMethodSecurity(prePostEnabled = true)
public class ResourceServerConfig extends ResourceServerConfigurerAdapter {
@Resource
RedisConnectionFactory redisConnectionFactory;
@Resource
private TokenStore tokenStore;
@Bean
public TokenStore redisTokenStore() {
return new RedisTokenStore(redisConnectionFactory);
}
@Override
public void configure(ResourceServerSecurityConfigurer resources) {
resources.tokenStore(tokenStore);
}
}角色
/**
* 查詢單個(gè)用戶
*
* @param query {@link UserQuery}
*
* @return com.fedtech.common.util.result.R<com.fedtech.sys.provider.view.UserView>
*
* @author <a href = "mailto:njpkhuan@gmail.com" > huan </a >
* @date 2021/2/20
* @since 1.0.0
*/
@GetMapping("select")
@PreAuthorize("hasAuthority('admin')")
public R<UserView> selectUser(UserQuery query) {
UserDto dto = userService.selectUser(query);
return R.successWithData(userMapper.dto2View(dto));
}權(quán)限
默認(rèn)的是DenyAllPermissionEvaluator,所有權(quán)限都拒絕,所以要自定義
自定義處理邏輯
我是把權(quán)限放到了自定義的userDetails里面
package com.fedtech.common.model;
import cn.hutool.core.collection.CollUtil;
import lombok.Data;
import lombok.extern.slf4j.Slf4j;
import org.springframework.security.core.GrantedAuthority;
import org.springframework.security.core.authority.SimpleGrantedAuthority;
import org.springframework.security.core.userdetails.UserDetails;
import java.util.ArrayList;
import java.util.Collection;
import java.util.List;
import java.util.StringTokenizer;
/**
* 該類返回的是安全的,能夠提供給用戶看到的信息,即脫敏后的信息
*
* @author <a href = "mailto:njpkhuan@gmail.com" > huan </a >
* @date 2021/1/9
* @since 1.0.0
*/
@Data
@Slf4j
public class SecurityUser implements UserDetails {
private static final long serialVersionUID = 8689435103879098852L;
/**
* 鹽
*/
private String salt;
/**
* 用戶token
*/
private String token;
/**
* 用戶狀態(tài)
*/
private String status;
/**
* 用戶密碼
*/
private String password;
/**
* 用戶登錄賬號(hào)
*/
private String loginName;
private Long userId;
/**
* 用戶角色
*
* @date 2021/1/10
* @since 1.0.0
*/
private List<UserRole> roleList;
/**
* 權(quán)限列表
*
* @date 2021/1/11
* @since 1.0.0
*/
private List<UserPermission> permissionList;
/**
* 客戶端用戶
*
* @param client 客戶端
*
* @author <a href = "mailto:njpkhuan@gmail.com" > huan </a >
* @date 2021/1/13
* @since 1.0.0
*/
public SecurityUser(OauthClientDetails client) {
if (client != null) {
password = client.getClientSecret();
loginName = client.getClientId();
String authorities = client.getAuthorities();
StringTokenizer stringTokenizer = new StringTokenizer(authorities, ", ");
roleList = new ArrayList<>();
if (stringTokenizer.hasMoreTokens()) {
UserRole userRole = new UserRole();
userRole.setCode(stringTokenizer.nextToken());
roleList.add(userRole);
}
}
}
/**
* 普通用戶
*
* @param user 用戶
* @param roleList 角色
* @param permissionList 權(quán)限
*
* @author <a href = "mailto:njpkhuan@gmail.com" > huan </a >
* @date 2021/1/13
* @since 1.0.0
*/
public SecurityUser(User user, List<UserRole> roleList, List<UserPermission> permissionList) {
if (user != null) {
salt = user.getSalt();
token = user.getToken();
status = user.getStatus();
password = user.getPassword();
loginName = user.getLoginName();
userId = user.getId();
this.roleList = roleList;
this.permissionList = permissionList;
}
}
@Override
public Collection<? extends GrantedAuthority> getAuthorities() {
Collection<GrantedAuthority> authorities = new ArrayList<>();
if (!CollUtil.isEmpty(roleList)) {
for (UserRole role : roleList) {
SimpleGrantedAuthority authority = new SimpleGrantedAuthority(role.getCode());
authorities.add(authority);
}
}
log.debug("獲取到的用戶權(quán)限:{}", authorities);
return authorities;
}
@Override
public String getPassword() {
return password;
}
@Override
public String getUsername() {
return loginName;
}
@Override
public boolean isAccountNonExpired() {
return true;
}
@Override
public boolean isAccountNonLocked() {
return true;
}
@Override
public boolean isCredentialsNonExpired() {
return true;
}
@Override
public boolean isEnabled() {
return true;
}
}package com.fedtech.common.config;
import cn.hutool.core.collection.CollUtil;
import com.fedtech.common.model.SecurityUser;
import com.fedtech.common.model.UserPermission;
import lombok.extern.slf4j.Slf4j;
import org.apache.commons.lang3.StringUtils;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.access.PermissionEvaluator;
import org.springframework.security.core.Authentication;
import java.io.Serializable;
import java.util.List;
/**
* 自定義權(quán)限處理
*
* @author <a href="mailto:njpkhuan@gmail.com" rel="external nofollow" >huan</a>
* @version 1.0.0
* @date 2021/2/26
*/
@Slf4j
@Configuration
public class MyPermissionEvaluator implements PermissionEvaluator {
@Override
public boolean hasPermission(Authentication authentication, Object targetDomainObject, Object permission) {
SecurityUser principal = (SecurityUser) authentication.getPrincipal();
List<UserPermission> permissionList = principal.getPermissionList();
if (CollUtil.isNotEmpty(permissionList)) {
return permissionList.stream().anyMatch(x -> StringUtils.equals(x.getUrl(), (CharSequence) targetDomainObject) &&
StringUtils.equals(x.getCode(), (CharSequence) permission));
}
return false;
}
@Override
public boolean hasPermission(Authentication authentication, Serializable targetId, String targetType, Object permission) {
return false;
}
}使用
/**
* 查詢單個(gè)用戶
*
* @param query {@link UserQuery}
*
* @return com.fedtech.common.util.result.R<com.fedtech.sys.provider.view.UserView>
*
* @author <a href = "mailto:njpkhuan@gmail.com" > huan </a >
* @date 2021/2/20
* @since 1.0.0
*/
@GetMapping("select")
@PreAuthorize("hasPermission('/sys/user/insert','userInsert')")
public R<UserView> selectUser(UserQuery query) {
UserDto dto = userService.selectUser(query);
return R.successWithData(userMapper.dto2View(dto));
}以上就是Spring Security權(quán)限注解啟動(dòng)及邏輯處理使用示例的詳細(xì)內(nèi)容,更多關(guān)于Spring Security權(quán)限注解的資料請(qǐng)關(guān)注腳本之家其它相關(guān)文章!
相關(guān)文章
使用FeignClient調(diào)用遠(yuǎn)程服務(wù)時(shí)整合本地的實(shí)現(xiàn)方法
這篇文章主要介紹了使用FeignClient調(diào)用遠(yuǎn)程服務(wù)時(shí)整合本地的實(shí)現(xiàn)方法,具有很好的參考價(jià)值,希望對(duì)大家有所幫助。如有錯(cuò)誤或未考慮完全的地方,望不吝賜教2022-03-03
淺談synchronized方法對(duì)非synchronized方法的影響
下面小編就為大家?guī)?lái)一篇淺談synchronized方法對(duì)非synchronized方法的影響。小編覺(jué)得挺不錯(cuò)的,現(xiàn)在就分享給大家,也給大家做個(gè)參考。一起跟隨小編過(guò)來(lái)看看吧2017-10-10
Spring AI對(duì)接大模型開(kāi)發(fā)易錯(cuò)點(diǎn)總結(jié)與實(shí)戰(zhàn)解決辦法
本文介紹了SpringAI接入大模型時(shí)常見(jiàn)的問(wèn)題及解決方案,主要從地址配置、密鑰鑒權(quán)、模型匹配、版本依賴四大維度入手,詳細(xì)分析了各種問(wèn)題的成因,并提供了實(shí)用的配置與代碼解決方案,幫助開(kāi)發(fā)者快速避坑,提高開(kāi)發(fā)效率,需要的朋友可以參考下2026-05-05
在Android中使用WebView在線查看PDF文件的方法示例
在Android應(yīng)用開(kāi)發(fā)中,有時(shí)我們需要在客戶端展示PDF文件,以便用戶可以閱讀或交互,這篇文章主要介紹了在Android中使用WebView在線查看PDF文件的方法,文中通過(guò)代碼介紹的非常詳細(xì),需要的朋友可以參考下2025-09-09
JDK21中虛擬線程到底是什么以及用法總結(jié)(看完便知)
這篇文章主要給大家介紹了關(guān)于JDK21中虛擬線程到底是什么以及用法的相關(guān)資料,虛擬線程是一種輕量化的線程封裝,由jvm直接調(diào)度和管理,反之普通的線程其實(shí)是調(diào)用的操作系統(tǒng)的能力,對(duì)應(yīng)的是操作系統(tǒng)級(jí)的線程,需要的朋友可以參考下2023-12-12
spring通過(guò)導(dǎo)入jar包和配置xml文件啟動(dòng)的步驟詳解
這篇文章主要介紹了spring通過(guò)導(dǎo)入jar包和配置xml文件啟動(dòng),本文分步驟通過(guò)實(shí)例代碼給大家介紹的非常詳細(xì),對(duì)大家的學(xué)習(xí)或工作具有一定的參考借鑒價(jià)值,需要的朋友可以參考下2020-08-08
java數(shù)據(jù)結(jié)構(gòu)與算法之冒泡排序詳解
這篇文章主要介紹了java數(shù)據(jù)結(jié)構(gòu)與算法之冒泡排序,結(jié)合實(shí)例形式詳細(xì)分析了java冒泡排序的原理、實(shí)現(xiàn)技巧與相關(guān)注意事項(xiàng),需要的朋友可以參考下2017-05-05
Java運(yùn)行時(shí)環(huán)境之ClassLoader類加載機(jī)制詳解
這篇文章主要給大家介紹了關(guān)于Java運(yùn)行時(shí)環(huán)境之ClassLoader類加載機(jī)制的相關(guān)資料,文中通過(guò)示例代碼介紹的非常詳細(xì),對(duì)大家的學(xué)習(xí)或者工作具有一定的參考學(xué)習(xí)價(jià)值,需要的朋友們下面隨著小編來(lái)一起學(xué)習(xí)學(xué)習(xí)吧2019-01-01

