spring boot 利用注解實(shí)現(xiàn)權(quán)限驗(yàn)證的實(shí)現(xiàn)代碼
這里使用 aop 來(lái)實(shí)現(xiàn)權(quán)限驗(yàn)證
引入依賴
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-aop</artifactId> </dependency>
定義注解
package com.lmxdawn.api.admin.annotation;
import java.lang.annotation.ElementType;
import java.lang.annotation.Retention;
import java.lang.annotation.RetentionPolicy;
import java.lang.annotation.Target;
/**
* 后臺(tái)登錄授權(quán)/權(quán)限驗(yàn)證的注解
*/
//此注解只能修飾方法
@Target(ElementType.METHOD)
//當(dāng)前注解如何去保持
@Retention(RetentionPolicy.RUNTIME)
public @interface AuthRuleAnnotation {
String value();
}
攔截實(shí)現(xiàn)登錄和權(quán)限驗(yàn)證
package com.lmxdawn.api.admin.aspect;
import com.lmxdawn.api.admin.annotation.AuthRuleAnnotation;
import com.lmxdawn.api.admin.enums.ResultEnum;
import com.lmxdawn.api.admin.exception.JsonException;
import com.lmxdawn.api.admin.service.auth.AuthLoginService;
import com.lmxdawn.api.common.utils.JwtUtils;
import io.jsonwebtoken.Claims;
import lombok.extern.slf4j.Slf4j;
import org.aspectj.lang.JoinPoint;
import org.aspectj.lang.annotation.Aspect;
import org.aspectj.lang.annotation.Before;
import org.aspectj.lang.annotation.Pointcut;
import org.aspectj.lang.reflect.MethodSignature;
import org.springframework.stereotype.Component;
import org.springframework.web.context.request.RequestContextHolder;
import org.springframework.web.context.request.ServletRequestAttributes;
import javax.annotation.Resource;
import javax.servlet.http.HttpServletRequest;
import java.lang.reflect.Method;
import java.util.List;
/**
* 登錄驗(yàn)證 AOP
*/
@Aspect
@Component
@Slf4j
public class AuthorizeAspect {
@Resource
private AuthLoginService authLoginService;
@Pointcut("@annotation(com.lmxdawn.api.admin.annotation.AuthRuleAnnotation)")
public void adminLoginVerify() {
}
/**
* 登錄驗(yàn)證
*
* @param joinPoint
*/
@Before("adminLoginVerify()")
public void doAdminAuthVerify(JoinPoint joinPoint) {
ServletRequestAttributes attributes = (ServletRequestAttributes) RequestContextHolder.getRequestAttributes();
if (attributes == null) {
throw new JsonException(ResultEnum.NOT_NETWORK);
}
HttpServletRequest request = attributes.getRequest();
String id = request.getHeader("X-Adminid");
Long adminId = Long.valueOf(id);
String token = request.getHeader("X-Token");
if (token == null) {
throw new JsonException(ResultEnum.LOGIN_VERIFY_FALL);
}
// 驗(yàn)證 token
Claims claims = JwtUtils.parse(token);
if (claims == null) {
throw new JsonException(ResultEnum.LOGIN_VERIFY_FALL);
}
Long jwtAdminId = Long.valueOf(claims.get("admin_id").toString());
if (adminId.compareTo(jwtAdminId) != 0) {
throw new JsonException(ResultEnum.LOGIN_VERIFY_FALL);
}
// 判斷是否進(jìn)行權(quán)限驗(yàn)證
MethodSignature signature = (MethodSignature) joinPoint.getSignature();
//從切面中獲取當(dāng)前方法
Method method = signature.getMethod();
//得到了方,提取出他的注解
AuthRuleAnnotation action = method.getAnnotation(AuthRuleAnnotation.class);
// 進(jìn)行權(quán)限驗(yàn)證
authRuleVerify(action.value(), adminId);
}
/**
* 權(quán)限驗(yàn)證
*
* @param authRule
*/
private void authRuleVerify(String authRule, Long adminId) {
if (authRule != null && authRule.length() > 0) {
List<String> authRules = authLoginService.listRuleByAdminId(adminId);
// admin 為最高權(quán)限
for (String item : authRules) {
if (item.equals("admin") || item.equals(authRule)) {
return;
}
}
throw new JsonException(ResultEnum.AUTH_FAILED);
}
}
}
Controller 中使用
使用 AuthRuleAnnotation 注解, value 值就是在數(shù)據(jù)庫(kù)里面定義的 權(quán)限規(guī)則名稱
/**
* 獲取管理員列表
*/
@AuthRuleAnnotation("admin/auth/admin/index")
@GetMapping("/admin/auth/admin/index")
public ResultVO index(@Valid AuthAdminQueryForm authAdminQueryForm,
BindingResult bindingResult) {
if (bindingResult.hasErrors()) {
return ResultVOUtils.error(ResultEnum.PARAM_VERIFY_FALL, bindingResult.getFieldError().getDefaultMessage());
}
if (authAdminQueryForm.getRoleId() != null) {
List<AuthRoleAdmin> authRoleAdmins = authRoleAdminService.listByRoleId(authAdminQueryForm.getRoleId());
List<Long> ids = new ArrayList<>();
if (authRoleAdmins != null && !authRoleAdmins.isEmpty()) {
ids = authRoleAdmins.stream().map(AuthRoleAdmin::getAdminId).collect(Collectors.toList());
}
authAdminQueryForm.setIds(ids);
}
List<AuthAdmin> authAdminList = authAdminService.listAdminPage(authAdminQueryForm);
// 查詢所有的權(quán)限
List<Long> adminIds = authAdminList.stream().map(AuthAdmin::getId).collect(Collectors.toList());
List<AuthRoleAdmin> authRoleAdminList = authRoleAdminService.listByAdminIdIn(adminIds);
// 視圖列表
List<AuthAdminVo> authAdminVoList = authAdminList.stream().map(item -> {
AuthAdminVo authAdminVo = new AuthAdminVo();
BeanUtils.copyProperties(item, authAdminVo);
List<Long> roles = authRoleAdminList.stream()
.filter(authRoleAdmin -> authAdminVo.getId().equals(authRoleAdmin.getAdminId()))
.map(AuthRoleAdmin::getRoleId)
.collect(Collectors.toList());
authAdminVo.setRoles(roles);
return authAdminVo;
}).collect(Collectors.toList());
PageInfo<AuthAdmin> authAdminPageInfo = new PageInfo<>(authAdminList);
PageSimpleVO<AuthAdminVo> authAdminPageSimpleVO = new PageSimpleVO<>();
authAdminPageSimpleVO.setTotal(authAdminPageInfo.getTotal());
authAdminPageSimpleVO.setList(authAdminVoList);
return ResultVOUtils.success(authAdminPageSimpleVO);
}
相關(guān)地址
GitHub 地址: https://github.com/lmxdawn/vue-admin-java
以上就是本文的全部?jī)?nèi)容,希望對(duì)大家的學(xué)習(xí)有所幫助,也希望大家多多支持腳本之家。
相關(guān)文章
java防盜鏈在報(bào)表中的應(yīng)用實(shí)例(推薦)
下面小編就為大家?guī)?lái)一篇java防盜鏈在報(bào)表中的應(yīng)用實(shí)例(推薦)。小編覺(jué)得挺不錯(cuò)的,現(xiàn)在就分享給大家,也給大家做個(gè)參考。一起跟隨小編過(guò)來(lái)看看吧2016-09-09
Java程序中添加播放MIDI音樂(lè)功能的實(shí)現(xiàn)方法詳解
本篇文章是對(duì)在Java程序中添加播放MIDI音樂(lè)功能的方法進(jìn)行了詳細(xì)的分析介紹,需要的朋友參考下2013-05-05

