最新国产好看的视频,伊人天堂AV在线,国产Aaaaaa视频,蜜臀视频在线观看一区,人妻av色图,密臀久久久精品影片,青青视频免费观看毛片,久草在线观看视,国产三级精品色情在线

SpringBoot的Security和OAuth2的使用示例小結(jié)

 更新時(shí)間:2024年06月18日 08:51:03   作者:kiba518  
這篇文章主要介紹了SpringBoot的Security和OAuth2的使用,本文通過示例圖文相結(jié)合給大家講解的非常詳細(xì),感興趣的朋友跟隨小編一起看看吧

創(chuàng)建項(xiàng)目

先創(chuàng)建一個(gè)spring項(xiàng)目。

然后編寫pom文件如下,引入spring-boot-starter-security,我這里使用的spring boot是2.4.2,這里使用使用spring-boot-dependencies,在這里就能找到對(duì)應(yīng)的security的包。

<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
    <modelVersion>4.0.0</modelVersion>
    <groupId>com.example</groupId>
    <artifactId>app-kiba-security</artifactId>
    <version>0.0.1-SNAPSHOT</version>
    <name>app-kiba-security</name>
    <description>app-kiba-security</description>
    <properties>
        <java.version>1.8</java.version>
        <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
        <project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>
        <spring-boot.version>2.4.2</spring-boot.version>
    </properties>
    <dependencies>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-security</artifactId>
        </dependency>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-web</artifactId>
        </dependency>
        <dependency>
            <groupId>org.projectlombok</groupId>
            <artifactId>lombok</artifactId>
            <optional>true</optional>
        </dependency>
    </dependencies>
    <dependencyManagement>
        <dependencies>
            <dependency>
                <groupId>org.springframework.boot</groupId>
                <artifactId>spring-boot-dependencies</artifactId>
                <version>${spring-boot.version}</version>
                <type>pom</type>
                <scope>import</scope>
            </dependency>
        </dependencies>
    </dependencyManagement>
    <build>
        <plugins>
            <plugin>
                <groupId>org.apache.maven.plugins</groupId>
                <artifactId>maven-compiler-plugin</artifactId>
                <version>3.8.1</version>
                <configuration>
                    <source>1.8</source>
                    <target>1.8</target>
                    <encoding>UTF-8</encoding>
                </configuration>
            </plugin>
            <plugin>
                <groupId>org.springframework.boot</groupId>
                <artifactId>spring-boot-maven-plugin</artifactId>
                <version>${spring-boot.version}</version>
                <configuration>
                    <mainClass>com.kiba.appkibasecurity.AppKibaSecurityApplication</mainClass>
                    <skip>true</skip>
                </configuration>
                <executions>
                    <execution>
                        <id>repackage</id>
                        <goals>
                            <goal>repackage</goal>
                        </goals>
                    </execution>
                </executions>
            </plugin>
        </plugins>
    </build>
</project>

然后訪問創(chuàng)建項(xiàng)目時(shí)默認(rèn)生成的接口:http://127.0.0.1:8080/user/123/roles/222,得到如下界面。

image

這是相當(dāng)于,在我們的接口請(qǐng)求的前面做了一個(gè)攔截,類似filter,攔截后,跳轉(zhuǎn)到了一個(gè)界面,讓我們輸入賬號(hào)密碼。這里,我由于沒有設(shè)置賬號(hào)密碼,所以登錄不進(jìn)去。

設(shè)置訪問一

下面設(shè)置一個(gè)賬號(hào)密碼,并且設(shè)置hello接口可以直接訪問,設(shè)置很簡單,就是注入兩個(gè)bean,InMemoryUserDetailsManager和WebSecurityCustomizer,代碼如下:

@Configuration
public class SecurityConfig   {
    /**
     * 注冊(cè)用戶,這里用戶是在內(nèi)存中的
     *  {noop}表示“無操作”(No Operation)密碼編碼。
     * @return
     */
    @Bean
    UserDetailsService userDetailsService() {
        InMemoryUserDetailsManager users = new InMemoryUserDetailsManager();
        users.createUser(User.withUsername("kiba").password("{noop}123").roles("admin").build()); 
        return users;
    }
    /**
     * 讓hello可以不用登錄,就可以直接訪問,例如:http://127.0.0.1:8080/hello?name=kiba就可以直接訪問
     * @return
     */
    @Bean
    WebSecurityCustomizer webSecurityCustomizer() {
        return new WebSecurityCustomizer() {
            @Override
            public void customize(WebSecurity web) {
                web.ignoring().antMatchers("/hello");
            }
        };
    }
}

現(xiàn)在我們?cè)L問http://127.0.0.1:8080/user/123/roles/222,進(jìn)入到登錄頁面,輸入kiba/123就可以查看接口執(zhí)行的結(jié)果了。

http://127.0.0.1:8080/hello?name=kiba就無需登錄,可以直接訪問。

登錄一次,其他接口就可以自由訪問了

控制請(qǐng)求

現(xiàn)在,增加一個(gè)類SecurityAdapter,繼承自WebSecurityConfigurerAdapter。然后重寫他的configure方法

@Configuration
@AllArgsConstructor
public class SecurityAdapter extends WebSecurityConfigurerAdapter {
    /**
     * authenticated():用戶需要通過用戶名/密碼登錄,記住我功能也可以(remember-me)。
     * fullyAuthenticated()用戶需要通過用戶名/密碼登錄,記住我功能不行。 
     */
    @Override
    @SneakyThrows
    protected void configure(HttpSecurity http) {
        http.httpBasic().and()
                //禁用跨站請(qǐng)求偽造(CSRF)保護(hù)。
                .csrf().disable()
                .authorizeRequests().anyRequest().fullyAuthenticated();
    } 
}

當(dāng)使用,增加了SecurityAdapter后,我們重新請(qǐng)求http://127.0.0.1:8080/user/123/roles/222,得到界面如下:

image

可以看到,登錄界面的樣式被美化了。

設(shè)置訪問二(推薦)

我們還可以使用第二種方法,來做用戶密碼的配置。

通過重寫configure(AuthenticationManagerBuilder auth)函數(shù),來創(chuàng)建用戶,這種方式創(chuàng)建用戶會(huì)將前面的bean-UserDetailsService給覆蓋,即,用戶只剩下這里創(chuàng)建的。

代碼如下:

@Configuration
@AllArgsConstructor
public class SecurityAdapter extends WebSecurityConfigurerAdapter {
    /**
     * authenticated():用戶需要通過用戶名/密碼登錄,記住我功能也可以(remember-me)。
     * fullyAuthenticated()用戶需要通過用戶名/密碼登錄,記住我功能不行。
     */
    @Override
    @SneakyThrows
    protected void configure(HttpSecurity http) {
        http.httpBasic().and()
                //禁用跨站請(qǐng)求偽造(CSRF)保護(hù)。
                .csrf().disable()
                .authorizeRequests().anyRequest().fullyAuthenticated();
    }
    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        auth.inMemoryAuthentication()
                .withUser("kiba518")
                .password(passwordEncoder().encode("123"))
                .authorities(new ArrayList<>(0));
    }
    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }
}

這里的用戶是寫死的,用戶是可以修改成讀取數(shù)據(jù)庫的信息的。

我們查看WebSecurityConfigurerAdapter的代碼,可以看到他有注解@Order(100),數(shù)越大,執(zhí)行越優(yōu)先級(jí)越低,即,他的執(zhí)行順序是相對(duì)比較靠后的。

授權(quán)OAuth2

授權(quán)這個(gè)設(shè)計(jì)理念是這樣,它是結(jié)合上面的security的操作,實(shí)現(xiàn)了一個(gè)普通的WebApp轉(zhuǎn)換成授權(quán)服務(wù)器WebApp。

授權(quán)服務(wù)器轉(zhuǎn)換思路

我們先了解一下security轉(zhuǎn)授權(quán)服務(wù)器的思路。

1,在這個(gè)應(yīng)用里,創(chuàng)建一個(gè)auth接口,然后任何人想訪問這個(gè)接口,就都需要輸入賬戶密碼了。

2,我們這個(gè)auth接口的返回值是個(gè)code,然后我們的前端,或者其他調(diào)用接口的APP,就可以把這個(gè)code作為用戶登錄的token了,。

3,然后我們?cè)僮鲆粋€(gè)接口,接受一個(gè)token參數(shù),可以驗(yàn)證token是否有效。

這樣我們這個(gè)授權(quán)服務(wù)器的搭建思路就構(gòu)建完成了。

但按這個(gè)思路,我們需要做很多操作,比如創(chuàng)建接口,緩存token等等,現(xiàn)在spring提供了一個(gè)Oauth2的包,他可以幫我們實(shí)現(xiàn)這些接口定義。

OAuth2的接口如下,可以自行研究。

/oauth/authorize:授權(quán)端點(diǎn)

/oauth/token:獲取令牌端點(diǎn)

/oauth/confirm_access:用戶確認(rèn)授權(quán)提交端點(diǎn)

/oauth/error:授權(quán)服務(wù)錯(cuò)誤信息端點(diǎn)

/oauth/check_token:用于資源服務(wù)訪問的令牌解析端點(diǎn)

/oauth/token_key:提供公有密匙的端點(diǎn),如果使用JWT令牌的話

實(shí)現(xiàn)授權(quán)服務(wù)器

現(xiàn)在我們實(shí)現(xiàn)一個(gè)授權(quán)服務(wù)器。

先添加OAuth2的引用。

 <dependency>
            <groupId>org.springframework.security.oauth</groupId>
            <artifactId>spring-security-oauth2</artifactId>
            <version>2.4.0.RELEASE</version>
        </dependency>

然后增加配置文件AuthorizationConfig。

@Configuration
@EnableAuthorizationServer //開啟授權(quán)服務(wù)
public class AuthorizationConfig extends AuthorizationServerConfigurerAdapter {
    @Autowired
    private PasswordEncoder passwordEncoder;
    @Autowired
    private AuthenticationManager authenticationManager;
    @Override
    public void configure(AuthorizationServerSecurityConfigurer security) throws Exception {
        //允許表單提交
        security.allowFormAuthenticationForClients()
                .checkTokenAccess("isAuthenticated()");
    }
    @Override
    public void configure(ClientDetailsServiceConfigurer clients) throws Exception {
        clients.inMemory()
                .withClient("client-kiba") //客戶端唯一標(biāo)識(shí)(client_id)
                .secret(passwordEncoder.encode("kiba518-123456")) //客戶端的密碼(client_secret),這里的密碼應(yīng)該是加密后的
                .authorizedGrantTypes("password") //授權(quán)模式標(biāo)識(shí),共4種模式[授權(quán)碼(authorization-code)隱藏式(implicit) 密碼式(password)客戶端憑證(client credentials)]
                .scopes("read_scope"); //作用域
    }
    @Override
    public void configure(AuthorizationServerEndpointsConfigurer endpoints) throws Exception {
        endpoints.authenticationManager(authenticationManager);
    }
}

然后打開SecurityAdapter,增加一個(gè)bean,如下,目的是讓上面的AuthorizationConfig里Autowired的authenticationManager可以實(shí)例化。

@Bean
    public AuthenticationManager authenticationManager() throws Exception {
        return super.authenticationManager();
    }

然后使用APIFox調(diào)用一下/oauth/token接口。

先選擇auth,輸入賬號(hào)密碼,這個(gè)賬號(hào)密碼就是AuthorizationConfig里配置的客戶端id和密碼。

image

這個(gè)數(shù)據(jù)在請(qǐng)求時(shí),會(huì)進(jìn)行base64編碼,然后以http的header屬性Authorization的值的模式傳遞,如下。

image

然后輸入?yún)?shù),參數(shù)里scope和grant_type要和AuthorizationConfig里定義的scopes和authorizedGrantTypes一樣,如下。

image

請(qǐng)求后,得到結(jié)果,如上圖。

我們得到"access_token": "19d37af2-6e13-49c3-bf19-30a738b56886"。

有了access_token后,我們的前端其實(shí)就已經(jīng)可以進(jìn)行各種騷操作了。

資源服務(wù)

這個(gè)是Oauth為我們提供的一項(xiàng)很好用的功能。

我們創(chuàng)建一個(gè)項(xiàng)目做為資源服務(wù)。

添加依賴,版本與上面相同。

  <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-security</artifactId>
        </dependency>
        <dependency>
            <groupId>org.springframework.security.oauth</groupId>
            <artifactId>spring-security-oauth2</artifactId>
            <version>2.4.0.RELEASE</version>
        </dependency>

然后編寫資源配置,代碼如下:

@Configuration
@EnableResourceServer
public class ResourceServerConfig extends ResourceServerConfigurerAdapter {
    @Bean
    public RemoteTokenServices remoteTokenServices() {
        final RemoteTokenServices tokenServices = new RemoteTokenServices();
        tokenServices.setClientId("client-kiba");
        tokenServices.setClientSecret("kiba518-123456");
        tokenServices.setCheckTokenEndpointUrl("http://localhost:8080/oauth/check_token");//這個(gè)接口是oauth自帶的
        return tokenServices;
    }
    @Override
    public void configure(ResourceServerSecurityConfigurer resources) throws Exception {
        resources.stateless(true);
    }
    @Override
    public void configure(HttpSecurity http) throws Exception {
        //session創(chuàng)建策略
        http.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.IF_REQUIRED);
        //所有請(qǐng)求需要認(rèn)證
        http.authorizeRequests().anyRequest().authenticated();
    }
}

因?yàn)樘砑恿藄pring-boot-starter-security,所以,我們請(qǐng)求這個(gè)資源WebApp,就都需要輸入賬號(hào)密碼。

但因?yàn)?,我們配置了ResourceServerConfig,這里我們配置了遠(yuǎn)程token服務(wù),設(shè)置的信息是我們上面創(chuàng)建授權(quán)服務(wù)的信息。所以,在訪問這個(gè)WebApp時(shí),我們提供token即可。

使用APIFOX測試,先添加auth的token,內(nèi)容是來自于上面,/oauth/token的返回值access_token的值。

image

然后請(qǐng)求user接口,我這user接口沒有參數(shù),請(qǐng)求結(jié)果如下:

image

總結(jié)

這個(gè)授權(quán)服務(wù)挺好用的,就是配置太繁瑣了,初學(xué)者不太好理解,而且功能太多,配置太鬧心。

這個(gè)資源服務(wù)還是很貼心的,他提我們實(shí)現(xiàn)了,tokencheck的部分,但要注意的是,他這tokencheck是基于http請(qǐng)求的。

雖然Oath很好用,但,我還是覺得,這個(gè)認(rèn)證部分自己寫比較好,我們可以根據(jù)項(xiàng)目的需求,設(shè)計(jì)輕量級(jí)的授權(quán)認(rèn)證。

比如,我們想減少http請(qǐng)求,把部分tokencheck在緩存內(nèi)進(jìn)行check,那使用oauth時(shí),修改起來就會(huì)很頭疼。如果是自己寫的授權(quán)服務(wù)器,就不會(huì)有修改困難的問題。

注:此文章為原創(chuàng),任何形式的轉(zhuǎn)載都請(qǐng)聯(lián)系作者獲得授權(quán)并注明出處!

https://www.cnblogs.com/kiba/p/18252859

https://www.cnblogs.com/kiba/

到此這篇關(guān)于SpringBoot的Security和OAuth2的使用的文章就介紹到這了,更多相關(guān)SpringBoot的Security和OAuth2的使用內(nèi)容請(qǐng)搜索腳本之家以前的文章或繼續(xù)瀏覽下面的相關(guān)文章希望大家以后多多支持腳本之家!

相關(guān)文章

  • spring中的FactoryBean代碼示例

    spring中的FactoryBean代碼示例

    這篇文章主要介紹了spring中的FactoryBean代碼示例,涉及FactoryBean的實(shí)現(xiàn)等相關(guān)內(nèi)容,具有一定參考價(jià)值,需要的朋友可以了解下。
    2017-10-10
  • Java結(jié)構(gòu)型模式之代理模式詳解

    Java結(jié)構(gòu)型模式之代理模式詳解

    這篇文章主要介紹了Java結(jié)構(gòu)型模式之代理模式,代理模式是常用的java設(shè)計(jì)模式,他的特征是代理類與委托類有同樣的接口,代理類主要負(fù)責(zé)為委托類預(yù)處理消息、過濾消息、把消息轉(zhuǎn)發(fā)給委托類,以及事后處理消息等
    2023-02-02
  • Java 二維碼,QR碼,J4L-QRCode 的資料整理

    Java 二維碼,QR碼,J4L-QRCode 的資料整理

    本文主要介紹Java 中二維碼,QR碼,J4L-QRCode,這里整理了詳細(xì)的資料供大家學(xué)習(xí)參考關(guān)于二維碼的知識(shí),有需要的小伙伴可以參考下
    2016-08-08
  • 使用Java編寫圖形化的菜單的教程

    使用Java編寫圖形化的菜單的教程

    這篇文章主要介紹了使用Java編寫圖形化的菜單的教程,需要的朋友可以參考下
    2015-10-10
  • Java?輕松掌握字符緩沖流的使用

    Java?輕松掌握字符緩沖流的使用

    這篇文章主要介紹了Java的字符緩沖流用法,字符緩沖流的用途很多,主要是幾個(gè)構(gòu)造方法的使用,在項(xiàng)目開發(fā)中經(jīng)常會(huì)用到,需要的朋友參考下吧
    2022-04-04
  • MyBatis-Plus 全面介紹與Spring Boot 集成最佳實(shí)踐

    MyBatis-Plus 全面介紹與Spring Boot 集成最佳實(shí)踐

    MyBatis-Plus是MyBatis的增強(qiáng)工具,提供了通用CRUD、分頁、條件構(gòu)造器等功能,簡化了開發(fā),減少重復(fù)SQL編寫,它支持多種主鍵生成策略,內(nèi)置樂觀鎖和邏輯刪除,且兼容MyBatis原有代碼,本文介紹MyBatis-Plus全面介紹與Spring Boot 集成最佳實(shí)踐,感興趣的朋友一起看看吧
    2025-12-12
  • Java InheritableThreadLocal用法詳細(xì)介紹

    Java InheritableThreadLocal用法詳細(xì)介紹

    InheritableThreadLocal繼承了ThreadLocal,此類擴(kuò)展了ThreadLocal以提供從父線程到子線程的值的繼承:當(dāng)創(chuàng)建子線程時(shí),子線程接收父線程具有的所有可繼承線程局部變量的初始值。 通常子線程的值與父線程的值是一致的
    2022-09-09
  • Java并發(fā)中的Fork/Join 框架機(jī)制詳解

    Java并發(fā)中的Fork/Join 框架機(jī)制詳解

    本文主要介紹了 Java 并發(fā)框架中的 Fork/Join 框架的基本原理和其使用的工作竊取算法(work-stealing)、設(shè)計(jì)方式和部分實(shí)現(xiàn)源碼,感興趣的朋友跟隨小編一起看看吧
    2021-07-07
  • 使用SpringBoot整合高德地圖實(shí)現(xiàn)路線規(guī)劃功能

    使用SpringBoot整合高德地圖實(shí)現(xiàn)路線規(guī)劃功能

    在日常的開發(fā)項(xiàng)目中,地圖服務(wù)是很多系統(tǒng)的核心能力之一,尤其是在物流、同城配送、出行導(dǎo)航等領(lǐng)域,在近期的一個(gè)項(xiàng)目中,需要實(shí)現(xiàn)用戶下單后,系統(tǒng)需要根據(jù)起點(diǎn)和終點(diǎn)地址,自動(dòng)計(jì)算推薦路徑,所以本文給大家分享了如何使用SpringBoot整合高德地圖實(shí)現(xiàn)路線規(guī)劃功能
    2025-07-07
  • SpringBoot定時(shí)任務(wù)@Scheduled使用方式

    SpringBoot定時(shí)任務(wù)@Scheduled使用方式

    本文主要介紹了SpringBoot中的定時(shí)任務(wù)的實(shí)現(xiàn)方法,通過@EnableScheduling開啟定時(shí)任務(wù),使用@Scheduled注解可以設(shè)置定時(shí)任務(wù)的觸發(fā)方式,文中詳細(xì)介紹了corn參數(shù)的使用方法和各種通配符的含義,并給出了示例代碼
    2026-04-04

最新評(píng)論

广南县| 大厂| 长子县| 合肥市| 武汉市| 永川市| 涿州市| 龙泉市| 遂昌县| 峡江县| 桦川县| 长子县| 中卫市| 南华县| 贵港市| 车致| 静海县| 任丘市| 托里县| 革吉县| 治县。| 华容县| 扶余县| 崇信县| 北海市| 咸阳市| 淅川县| 岳西县| 普格县| 肇源县| 赤水市| 桐庐县| 略阳县| 龙游县| 白玉县| 依兰县| 随州市| 呼和浩特市| 关岭| 苍南县| 昭平县|