integrated_traffic/src/main/java/com/zcloud/config/ShiroConfiguration.java

141 lines
6.3 KiB
Java
Raw Normal View History

2024-01-03 09:48:43 +08:00
package com.zcloud.config;
import com.zcloud.realm.MyShiroRealm;
import net.sf.ehcache.CacheManager;
import org.apache.shiro.cache.ehcache.EhCacheManager;
import org.apache.shiro.spring.LifecycleBeanPostProcessor;
import org.apache.shiro.spring.security.interceptor.AuthorizationAttributeSourceAdvisor;
import org.apache.shiro.spring.web.ShiroFilterFactoryBean;
import org.apache.shiro.web.mgt.DefaultWebSecurityManager;
import org.springframework.aop.framework.autoproxy.DefaultAdvisorAutoProxyCreator;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.transaction.annotation.EnableTransactionManagement;
import java.util.LinkedHashMap;
import java.util.Map;
/**
* Shiro
* luoxiaobao
* www.qdkjchina.com
*/
@Configuration
@EnableTransactionManagement
public class ShiroConfiguration {
/**
* ShiroFilterFactoryBean
* ShiroFilterFactoryBean
* ShiroFilterFactoryBeanSecurityManager
*
* Filter Chain
* 1URLFilter使
* 2
* 3permsroles
*/
@Bean(name = "shiroFilter")
public ShiroFilterFactoryBean shiroFilterFactoryBean(DefaultWebSecurityManager securityManager) {
ShiroFilterFactoryBean factoryBean = new MyShiroFilterFactoryBean();
factoryBean.setSecurityManager(securityManager);
factoryBean.setLoginUrl("/"); // 如果不设置默认会自动寻找Web工程根目录下的"/login.jsp"页面
factoryBean.setSuccessUrl("/main/index"); // 登录成功后要跳转的连接
factoryBean.setUnauthorizedUrl("/");
loadShiroFilterChain(factoryBean);
return factoryBean;
}
/**
* ShiroFilter
*/
private void loadShiroFilterChain(ShiroFilterFactoryBean factoryBean) {
/** 下面这些规则配置最好配置到配置文件中 */
Map<String, String> filterChainMap = new LinkedHashMap<String, String>();
/**
* authc访Shiro org.apache.shiro.web.filter.authc.FormAuthenticationFilter
* anon,,
* authc:url访; anon:url访
*/
filterChainMap.put("/404/**", "anon");
filterChainMap.put("/assets/**", "anon");
filterChainMap.put("/admin/check", "anon");
2024-03-22 14:53:46 +08:00
filterChainMap.put("/admin/checkPractitioner", "anon");
2024-01-03 09:48:43 +08:00
filterChainMap.put("/admin/islogin", "anon");
filterChainMap.put("/admin/register", "anon");
filterChainMap.put("/admin/sendSmsCode", "anon");
filterChainMap.put("/admin/checkByCode", "anon");
2024-01-03 09:48:43 +08:00
filterChainMap.put("/admin/adminCheck", "anon");
filterChainMap.put("/App**/**", "anon");
filterChainMap.put("/app/**/**", "anon");
filterChainMap.put("/sync/**/**", "anon");
2024-01-31 09:15:43 +08:00
filterChainMap.put("/aiwarning/**", "anon");
filterChainMap.put("/dictionaries/**", "anon");
2024-01-03 09:48:43 +08:00
filterChainMap.put("/corptype/listAllCorpTypeMent", "anon");
filterChainMap.put("/corpinfo/hasCorpName", "anon");
filterChainMap.put("/versionmanager/getVersion", "anon");
filterChainMap.put("/**", "authc");
factoryBean.setFilterChainDefinitionMap(filterChainMap);
}
@Bean
public EhCacheManager ehCacheManager(CacheManager cacheManager) {
EhCacheManager em = new EhCacheManager();
em.setCacheManager(cacheManager);
return em;
}
@Bean(name = "myShiroRealm")
public MyShiroRealm myShiroRealm(EhCacheManager ehCacheManager) {
MyShiroRealm realm = new MyShiroRealm();
realm.setCacheManager(ehCacheManager);
return realm;
}
@Bean(name = "lifecycleBeanPostProcessor")
public LifecycleBeanPostProcessor lifecycleBeanPostProcessor() {
return new LifecycleBeanPostProcessor();
}
@Bean
public DefaultAdvisorAutoProxyCreator defaultAdvisorAutoProxyCreator() {
DefaultAdvisorAutoProxyCreator creator = new DefaultAdvisorAutoProxyCreator();
creator.setProxyTargetClass(true);
return creator;
}
@Bean(name = "securityManager")
public DefaultWebSecurityManager defaultWebSecurityManager(MyShiroRealm realm, EhCacheManager ehCacheManager) {
DefaultWebSecurityManager securityManager = new DefaultWebSecurityManager();
securityManager.setRealm(realm); // 设置realm
securityManager.setCacheManager(ehCacheManager);
return securityManager;
}
@Bean
public AuthorizationAttributeSourceAdvisor authorizationAttributeSourceAdvisor(
DefaultWebSecurityManager securityManager) {
AuthorizationAttributeSourceAdvisor advisor = new AuthorizationAttributeSourceAdvisor();
advisor.setSecurityManager(securityManager);
return advisor;
}
/*
* 1.LifecycleBeanPostProcessorDestructionAwareBeanPostProcessororg.
* apache.shiro.util.InitializablebeanAuthorizingRealm
* EhCacheManager
* 2.HashedCredentialsMatcher
* form
* 3.ShiroRealmAuthorizingRealmJdbcRealm
* 4.EhCacheManagersession
* bean
* 5.SecurityManagersession
* 6.ShiroFilterFactoryBeanfactorybeanShiroFilter
* securityManagerfiltersfilterChainDefinitionManager
* 7.DefaultAdvisorAutoProxyCreatorSpringbeanAdvisorAOP
* 8.AuthorizationAttributeSourceAdvisorshiroAdvisor
* 使AopAllianceAnnotationsAuthorizingMethodInterceptor
*/
}