當(dāng)前位置:
首頁 >
前端技术
> javascript
>内容正文
javascript
SpringSecurity分布式整合之验证认证的过滤器
生活随笔
收集整理的這篇文章主要介紹了
SpringSecurity分布式整合之验证认证的过滤器
小編覺得挺不錯的,現(xiàn)在分享給大家,幫大家做個參考.
編寫檢驗token過濾器
public class JwtVerifyFilter extends BasicAuthenticationFilter {private RsaKeyProperties prop;public JwtVerifyFilter(AuthenticationManager authenticationManager, RsaKeyProperties prop) {super(authenticationManager);this.prop = prop;}public void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain chain) throws IOException, ServletException {String header = request.getHeader("Authorization");if (header == null || !header.startsWith("Bearer ")) {//如果攜帶錯誤的token,則給用戶提示請登錄!chain.doFilter(request, response);response.setContentType("application/json;charset=utf-8");response.setStatus(HttpServletResponse.SC_FORBIDDEN);PrintWriter out = response.getWriter();Map resultMap = new HashMap();resultMap.put("code", HttpServletResponse.SC_FORBIDDEN);resultMap.put("msg", "請登錄!");out.write(new ObjectMapper().writeValueAsString(resultMap));out.flush();out.close();} else {//如果攜帶了正確格式的token要先得到tokenString token = header.replace("Bearer ", "");//驗證tken是否正確Payload<SysUser> payload = JwtUtils.getInfoFromToken(token, prop.getPublicKey(), SysUser.class);SysUser user = payload.getUserInfo();if(user!=null){UsernamePasswordAuthenticationToken authResult = new UsernamePasswordAuthenticationToken(user.getUsername(), null, user.getAuthorities());SecurityContextHolder.getContext().setAuthentication(authResult);chain.doFilter(request, response);}}} }總結(jié)
以上是生活随笔為你收集整理的SpringSecurity分布式整合之验证认证的过滤器的全部內(nèi)容,希望文章能夠幫你解決所遇到的問題。
- 上一篇: SpringSecurity常用过滤器介
- 下一篇: gradle idea java ssm