springboot使用注解實(shí)現(xiàn)鑒權(quán)功能
Spring Boot 使用注解和AOP實(shí)現(xiàn)鑒權(quán)功能
一、自定義注解
自定義一個(gè)注解,實(shí)現(xiàn)以下幾個(gè)要求:
1、注解使用使用在方法上;
2、注解保留到運(yùn)行時(shí);
3、注解可以傳入單個(gè)參數(shù)、多個(gè)參數(shù)或者不傳參數(shù)
@Documented
@Target({ElementType.METHOD}) // 用在方法上
@Retention(RetentionPolicy.RUNTIME) //注解保留到運(yùn)行時(shí)
public @interface RoleType {
String[] value() default {};
}二、用戶信息上下文
定義了一個(gè)名為 UserContext 的類,用于管理用戶上下文信息。它使用 ThreadLocal 變量來(lái)存儲(chǔ)每個(gè)線程獨(dú)立的用戶數(shù)據(jù),包括用戶名、角色列表和登錄狀態(tài)。
public class UserContext {
private static final ThreadLocal<List<String>> role = new ThreadLocal<>();
private static final ThreadLocal<String> username = new ThreadLocal<>();
private static final ThreadLocal<Boolean> loginStatus = new ThreadLocal<>();
public static boolean loginStatus() {
return loginStatus.get();
}
public static void login() {
UserContext.loginStatus.set(true);
}
public static void logout() {
UserContext.loginStatus.set(false);
}
public static String getUsername() {
return username.get();
}
public static void setUsername(String username) {
UserContext.username.set(username);
}
public static void clearUsername() {
username.remove();
}
public static List<String> getRole() {
return role.get();
}
public static void setRole(List<String> role) {
UserContext.role.set(role);
}
public static void setRole(String role) {
UserContext.role.set(List.of(role));
}
public static void clearRole() {
role.remove();
}
}三、設(shè)置用于攔截識(shí)別用戶信息的過(guò)濾器
@Component
public class AuthFilter extends OncePerRequestFilter {
@Override
protected void doFilterInternal(HttpServletRequest request,
HttpServletResponse response,
FilterChain filterChain ) throws ServletException, IOException {
//將用戶信息寫入上下文,可以從session或redis或者從關(guān)系型數(shù)據(jù)庫(kù)獲取用戶信息及角色信息
UserContext.setUsername(username);
UserContext.setRole(roles);
UserContext.login();
filterChain.doFilter(request,response);
}
}四、使用AOP實(shí)現(xiàn)權(quán)限校驗(yàn)
使用Spring AOP(面向切面編程)實(shí)現(xiàn)的權(quán)限控制切面。使用注解的方法檢查用戶是否具有訪問(wèn)該方法所需的權(quán)限。
@Aspect
@Component
public class AuthAspect extends HttpServlet {
@Pointcut("@annotation(RoleType)")
public void annotatedMethod() {
}
//注解存在時(shí),需要在登陸情況下v愛可以訪問(wèn)接口
@Around("annotatedMethod()")
public Object aroundAnnotatedMethod(ProceedingJoinPoint joinPoint) throws Throwable {
//訪問(wèn)接口時(shí)需要的權(quán)限標(biāo)識(shí)集合
List<String> apiRole = Arrays.asList(AnnotationUtils.findAnnotation(((MethodSignature) joinPoint.getSignature()).getMethod(), RoleType.class).value());
//用戶擁有的權(quán)限標(biāo)識(shí)集合
List<String> userRole = UserContext.getRole();
//注解存在,并且登陸情況下可以訪問(wèn)接口
if (UserContext.loginStatus()){
//如果任意接口標(biāo)識(shí)中元素在用戶權(quán)限標(biāo)識(shí)中存在,則有權(quán)訪問(wèn)該接口
if (apiRole.isEmpty() || apiRole.stream().anyMatch(userRole::contains)) {
return joinPoint.proceed();
} else {
throw new MallException(403, "無(wú)權(quán)限訪問(wèn)!");
}
}else {
throw new MallException(500,"請(qǐng)先登陸再訪問(wèn)!");
}
}
//程序運(yùn)行結(jié)束后清楚上下文
@After("annotatedMethod()")
public void afterAnnotatedMethod(JoinPoint joinPoint) {
UserContext.clearRole();
UserContext.clearUsername();
UserContext.clearRole();
}
}六、注解的使用
1、無(wú)參數(shù)
使用注解情況下,必須登錄情況下才可以訪問(wèn)
@RoleType
public String test(){
return UserContext.getRole();
}2、一個(gè)參數(shù)
用戶有role權(quán)限標(biāo)識(shí)才可以訪問(wèn)該方法
@RoleType("role")
public String test(){
return UserContext.getRole();
}3、多個(gè)參數(shù)
用戶有role或test等任意一個(gè)權(quán)限標(biāo)識(shí)才可以訪問(wèn)該方法
@RoleType({"role","test",...})
public String test(){
return UserContext.getRole();
}到此這篇關(guān)于springboot使用注解實(shí)現(xiàn)鑒權(quán)功能的文章就介紹到這了,更多相關(guān)springbbot注解實(shí)現(xiàn)鑒權(quán)內(nèi)容請(qǐng)搜索腳本之家以前的文章或繼續(xù)瀏覽下面的相關(guān)文章希望大家以后多多支持腳本之家!
相關(guān)文章
MyBatis不同Mapper文件引用resultMap實(shí)例代碼
這篇文章主要介紹了mybatis 不同Mapper文件引用resultMap的實(shí)例代碼,非常不錯(cuò)具有參考借鑒價(jià)值,需要的朋友可以參考下2017-07-07
SpringBoot實(shí)現(xiàn)緩存與數(shù)據(jù)庫(kù)雙寫策略的詳細(xì)代碼
在SpringBoot企業(yè)開發(fā)中,為了提升系統(tǒng)性能,我們都會(huì)給高頻查詢接口加上緩存,把熱點(diǎn)數(shù)據(jù)緩存起來(lái),減少數(shù)據(jù)庫(kù)查詢壓力,因此本文給大家介紹了SpringBoot實(shí)現(xiàn)緩存與數(shù)據(jù)庫(kù)雙寫策略的詳細(xì)方法,需要的朋友可以參考下2026-04-04
DolphinScheduler容錯(cuò)Master源碼分析
這篇文章主要為大家介紹了DolphinScheduler容錯(cuò)Master源碼分析,有需要的朋友可以借鑒參考下,希望能夠有所幫助,祝大家多多進(jìn)步,早日升職加薪2023-02-02
Spring Security OAuth2.0登出的實(shí)現(xiàn)
本文主要介紹了Spring Security OAuth2.0登出的實(shí)現(xiàn),文中通過(guò)示例代碼介紹的非常詳細(xì),對(duì)大家的學(xué)習(xí)或者工作具有一定的參考學(xué)習(xí)價(jià)值,需要的朋友們下面隨著小編來(lái)一起學(xué)習(xí)學(xué)習(xí)吧2026-03-03
Java數(shù)據(jù)結(jié)構(gòu)之二叉搜索樹詳解
二叉搜索樹作為一個(gè)經(jīng)典的數(shù)據(jù)結(jié)構(gòu),具有鏈表的快速插入與刪除的特點(diǎn),同時(shí)查詢效率也很優(yōu)秀,所以應(yīng)用十分廣泛。本文將詳細(xì)講講二叉搜索樹的原理與實(shí)現(xiàn),需要的可以參考一下2022-06-06
java報(bào)錯(cuò):javax.xml.bind.JAXBException:?JAXB解決辦法
這篇文章主要介紹了java報(bào)錯(cuò):javax.xml.bind.JAXBException:?JAXB的解決辦法,文中通過(guò)示例提出多種解決方案,幫助開發(fā)者快速定位并解決問(wèn)題,需要的朋友可以參考下2025-05-05
java web項(xiàng)目實(shí)現(xiàn)文件下載實(shí)例代碼
現(xiàn)在項(xiàng)目里面有個(gè)需求,需要把系統(tǒng)產(chǎn)生的日志文件給下載到本地 先獲取所有的日志文件列表,顯示到界面,選擇一個(gè)日志文件,把文件名傳到后臺(tái)2013-09-09
EntityWrapper如何在and條件中嵌套o(hù)r語(yǔ)句
這篇文章主要介紹了EntityWrapper如何在and條件中嵌套o(hù)r語(yǔ)句,具有很好的參考價(jià)值,希望對(duì)大家有所幫助。如有錯(cuò)誤或未考慮完全的地方,望不吝賜教2022-03-03

