日韩性视频-久久久蜜桃-www中文字幕-在线中文字幕av-亚洲欧美一区二区三区四区-撸久久-香蕉视频一区-久久无码精品丰满人妻-国产高潮av-激情福利社-日韩av网址大全-国产精品久久999-日本五十路在线-性欧美在线-久久99精品波多结衣一区-男女午夜免费视频-黑人极品ⅴideos精品欧美棵-人人妻人人澡人人爽精品欧美一区-日韩一区在线看-欧美a级在线免费观看

歡迎訪問 生活随笔!

生活随笔

當(dāng)前位置: 首頁 > 人文社科 > 生活经验 >内容正文

生活经验

SpringBoot设置Session失效时间

發(fā)布時(shí)間:2023/11/27 生活经验 42 豆豆
生活随笔 收集整理的這篇文章主要介紹了 SpringBoot设置Session失效时间 小編覺得挺不錯(cuò)的,現(xiàn)在分享給大家,幫大家做個(gè)參考.
1 #Session超時(shí)時(shí)間設(shè)置,單位是秒,默認(rèn)是30分鐘
2 server.session.timeout=10

然而并沒有什么用,因?yàn)镾pringBoot在TomcatServletWebServerFactory代碼中寫了這個(gè)

1     private long getSessionTimeoutInMinutes() {
2         Duration sessionTimeout = this.getSession().getTimeout();
3         return this.isZeroOrLess(sessionTimeout) ? 0L : Math.max(sessionTimeout.toMinutes(), 1L);
4     }

?

⒈Session失效后如何跳轉(zhuǎn)到Session失效地址

 1 package cn.coreqi.security.config;
 2 
 3 import cn.coreqi.security.Filter.SmsCodeFilter;
 4 import cn.coreqi.security.Filter.ValidateCodeFilter;
 5 import org.springframework.beans.factory.annotation.Autowired;
 6 import org.springframework.context.annotation.Bean;
 7 import org.springframework.context.annotation.Configuration;
 8 import org.springframework.security.config.annotation.web.builders.HttpSecurity;
 9 import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
10 import org.springframework.security.crypto.password.NoOpPasswordEncoder;
11 import org.springframework.security.crypto.password.PasswordEncoder;
12 import org.springframework.security.web.authentication.AuthenticationFailureHandler;
13 import org.springframework.security.web.authentication.AuthenticationSuccessHandler;
14 import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter;
15 
16 @Configuration
17 public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
18 
19     @Autowired
20     private AuthenticationSuccessHandler coreqiAuthenticationSuccessHandler;
21 
22     @Autowired
23     private AuthenticationFailureHandler coreqiAuthenticationFailureHandler;
24 
25     @Autowired
26     private SmsCodeAuthenticationSecurityConfig smsCodeAuthenticationSecurityConfig;
27 
28     @Bean
29     public PasswordEncoder passwordEncoder(){
30         return NoOpPasswordEncoder.getInstance();
31     }
32 
33 
34     @Override
35     protected void configure(HttpSecurity http) throws Exception {
36         ValidateCodeFilter validateCodeFilter = new ValidateCodeFilter();
37         validateCodeFilter.setAuthenticationFailureHandler(coreqiAuthenticationFailureHandler);
38 
39         SmsCodeFilter smsCodeFilter = new SmsCodeFilter();
40 
41 
42         //http.httpBasic()    //httpBasic登錄 BasicAuthenticationFilter
43         http.addFilterBefore(smsCodeFilter, UsernamePasswordAuthenticationFilter.class)    //加載用戶名密碼過濾器的前面
44                 .addFilterBefore(validateCodeFilter, UsernamePasswordAuthenticationFilter.class)    //加載用戶名密碼過濾器的前面
45                 .formLogin()    //表單登錄 UsernamePasswordAuthenticationFilter
46                     .loginPage("/coreqi-signIn.html")  //指定登錄頁面
47                     //.loginPage("/authentication/require")
48                     .loginProcessingUrl("/authentication/form") //指定表單提交的地址用于替換UsernamePasswordAuthenticationFilter默認(rèn)的提交地址
49                     .successHandler(coreqiAuthenticationSuccessHandler) //登錄成功以后要用我們自定義的登錄成功處理器,不用Spring默認(rèn)的。
50                     .failureHandler(coreqiAuthenticationFailureHandler) //自己體會(huì)把
51                 .and()
52                 .sessionManagement()
53                     .invalidSessionUrl("session/invalid")    //session過期后跳轉(zhuǎn)的URL
54                 .and()
55                 .authorizeRequests()    //對(duì)授權(quán)請(qǐng)求進(jìn)行配置
56                     .antMatchers("/coreqi-signIn.html","/code/image","/session/invalid").permitAll() //指定登錄頁面不需要身份認(rèn)證
57                     .anyRequest().authenticated()  //任何請(qǐng)求都需要身份認(rèn)證
58                     .and().csrf().disable()    //禁用CSRF
59                 .apply(smsCodeAuthenticationSecurityConfig);
60             //FilterSecurityInterceptor 整個(gè)SpringSecurity過濾器鏈的最后一環(huán)
61     }
62 }
1     @GetMapping("/session/invalid")
2     @ResponseStatus(code = HttpStatus.UNAUTHORIZED)
3     public SimpleResponse sessionInvalid(){
4         String message = "session失效";
5         return new SimpleResponse(message);
6     }

?

轉(zhuǎn)載于:https://www.cnblogs.com/fanqisoft/p/10658070.html

總結(jié)

以上是生活随笔為你收集整理的SpringBoot设置Session失效时间的全部?jī)?nèi)容,希望文章能夠幫你解決所遇到的問題。

如果覺得生活随笔網(wǎng)站內(nèi)容還不錯(cuò),歡迎將生活随笔推薦給好友。