|
@@ -1,10 +1,9 @@
|
|
|
package com.ruoyi.framework.config;
|
|
|
|
|
|
-import com.ruoyi.framework.config.properties.PermitAllUrlProperties;
|
|
|
-import com.ruoyi.framework.security.filter.JwtAuthenticationTokenFilter;
|
|
|
-import com.ruoyi.framework.security.handle.AuthenticationEntryPointImpl;
|
|
|
-import com.ruoyi.framework.security.handle.LogoutSuccessHandlerImpl;
|
|
|
+import java.util.List;
|
|
|
+
|
|
|
import org.springframework.beans.factory.annotation.Autowired;
|
|
|
+import org.springframework.beans.factory.annotation.Value;
|
|
|
import org.springframework.context.annotation.Bean;
|
|
|
import org.springframework.context.annotation.Configuration;
|
|
|
import org.springframework.http.HttpMethod;
|
|
@@ -19,8 +18,14 @@ import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
|
|
|
import org.springframework.security.web.SecurityFilterChain;
|
|
|
import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter;
|
|
|
import org.springframework.security.web.authentication.logout.LogoutFilter;
|
|
|
+import org.springframework.util.CollectionUtils;
|
|
|
import org.springframework.web.filter.CorsFilter;
|
|
|
|
|
|
+import com.ruoyi.framework.config.properties.PermitAllUrlProperties;
|
|
|
+import com.ruoyi.framework.security.filter.JwtAuthenticationTokenFilter;
|
|
|
+import com.ruoyi.framework.security.handle.AuthenticationEntryPointImpl;
|
|
|
+import com.ruoyi.framework.security.handle.LogoutSuccessHandlerImpl;
|
|
|
+
|
|
|
/**
|
|
|
* spring security配置
|
|
|
*
|
|
@@ -60,12 +65,14 @@ public class SecurityConfig {
|
|
|
private CorsFilter corsFilter;
|
|
|
|
|
|
/**
|
|
|
- * 允许匿名访问的地址,
|
|
|
- * 配合使用 @Anonymous 注解
|
|
|
+ * 允许匿名访问的地址, 配合使用 @Anonymous 注解
|
|
|
*/
|
|
|
@Autowired
|
|
|
private PermitAllUrlProperties permitAllUrl;
|
|
|
|
|
|
+ @Value("${huashe.permit.urlPatterns:[]}")
|
|
|
+ private List<String> urlPatterns;
|
|
|
+
|
|
|
/**
|
|
|
* 身份验证实现
|
|
|
*/
|
|
@@ -78,50 +85,49 @@ public class SecurityConfig {
|
|
|
}
|
|
|
|
|
|
/**
|
|
|
- * anyRequest | 匹配所有请求路径
|
|
|
- * access | SpringEl表达式结果为true时可以访问
|
|
|
- * anonymous | 匿名可以访问
|
|
|
- * denyAll | 用户不能访问
|
|
|
- * fullyAuthenticated | 用户完全认证可以访问(非remember-me下自动登录)
|
|
|
- * hasAnyAuthority | 如果有参数,参数表示权限,则其中任何一个权限可以访问
|
|
|
- * hasAnyRole | 如果有参数,参数表示角色,则其中任何一个角色可以访问
|
|
|
- * hasAuthority | 如果有参数,参数表示权限,则其权限可以访问
|
|
|
- * hasIpAddress | 如果有参数,参数表示IP地址,如果用户IP和参数匹配,则可以访问
|
|
|
- * hasRole | 如果有参数,参数表示角色,则其角色可以访问
|
|
|
- * permitAll | 用户可以任意访问
|
|
|
- * rememberMe | 允许通过remember-me登录的用户访问
|
|
|
- * authenticated | 用户登录后可访问
|
|
|
+ * anyRequest | 匹配所有请求路径 access | SpringEl表达式结果为true时可以访问 anonymous | 匿名可以访问 denyAll | 用户不能访问 fullyAuthenticated |
|
|
|
+ * 用户完全认证可以访问(非remember-me下自动登录) hasAnyAuthority | 如果有参数,参数表示权限,则其中任何一个权限可以访问 hasAnyRole |
|
|
|
+ * 如果有参数,参数表示角色,则其中任何一个角色可以访问 hasAuthority | 如果有参数,参数表示权限,则其权限可以访问 hasIpAddress | 如果有参数,参数表示IP地址,如果用户IP和参数匹配,则可以访问
|
|
|
+ * hasRole | 如果有参数,参数表示角色,则其角色可以访问 permitAll | 用户可以任意访问 rememberMe | 允许通过remember-me登录的用户访问 authenticated | 用户登录后可访问
|
|
|
*/
|
|
|
@Bean
|
|
|
protected SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception {
|
|
|
return httpSecurity
|
|
|
- // CSRF禁用,因为不使用session
|
|
|
- .csrf(csrf -> csrf.disable())
|
|
|
- // 禁用HTTP响应标头
|
|
|
- .headers((headersCustomizer) -> {
|
|
|
- headersCustomizer.cacheControl(cache -> cache.disable()).frameOptions(options -> options.sameOrigin());
|
|
|
- })
|
|
|
- // 认证失败处理类
|
|
|
- .exceptionHandling(exception -> exception.authenticationEntryPoint(unauthorizedHandler))
|
|
|
- // 基于token,所以不需要session
|
|
|
- .sessionManagement(session -> session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
|
|
|
- // 注解标记允许匿名访问的url
|
|
|
- .authorizeHttpRequests((requests) -> {
|
|
|
- permitAllUrl.getUrls().forEach(url -> requests.antMatchers(url).permitAll());
|
|
|
- // 对于登录login 注册register 验证码captchaImage 允许匿名访问
|
|
|
- requests.antMatchers("/login", "/register", "/captchaImage").permitAll().antMatchers("/ws/**", "/websocket/**").permitAll()
|
|
|
- // 静态资源,可匿名访问
|
|
|
- .antMatchers(HttpMethod.GET, "/", "/*.html", "/**/*.html", "/**/*.css", "/**/*.js", "/profile/**").permitAll().antMatchers("/swagger-ui.html", "/swagger-resources/**", "/webjars/**", "/*/api-docs", "/druid/**").permitAll()
|
|
|
- // 除上面外的所有请求全部需要鉴权认证
|
|
|
- .anyRequest().authenticated();
|
|
|
- })
|
|
|
+ // CSRF禁用,因为不使用session
|
|
|
+ .csrf(csrf -> csrf.disable())
|
|
|
+ // 禁用HTTP响应标头
|
|
|
+ .headers((headersCustomizer) -> {
|
|
|
+ headersCustomizer.cacheControl(cache -> cache.disable()).frameOptions(options -> options.sameOrigin());
|
|
|
+ })
|
|
|
+ // 认证失败处理类
|
|
|
+ .exceptionHandling(exception -> exception.authenticationEntryPoint(unauthorizedHandler))
|
|
|
+ // 基于token,所以不需要session
|
|
|
+ .sessionManagement(session -> session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
|
|
|
+ // 注解标记允许匿名访问的url
|
|
|
+ .authorizeHttpRequests((requests) -> {
|
|
|
+ permitAllUrl.getUrls().forEach(url -> requests.antMatchers(url).permitAll());
|
|
|
+ if (!CollectionUtils.isEmpty(urlPatterns)) {
|
|
|
+ requests.antMatchers(urlPatterns.toArray(new String[urlPatterns.size()])).permitAll();
|
|
|
+ }
|
|
|
+ // 对于登录login 注册register 验证码captchaImage 允许匿名访问
|
|
|
+ requests.antMatchers("/login", "/register", "/captchaImage").permitAll()
|
|
|
+ .antMatchers("/ws/**", "/websocket/**").permitAll()
|
|
|
+ // 静态资源,可匿名访问
|
|
|
+ .antMatchers(HttpMethod.GET, "/", "/*.html", "/**/*.html", "/**/*.css", "/**/*.js", "/profile/**")
|
|
|
+ .permitAll()
|
|
|
+ .antMatchers("/swagger-ui.html", "/swagger-resources/**", "/webjars/**", "/*/api-docs", "/druid/**")
|
|
|
+ .permitAll()
|
|
|
+ // 除上面外的所有请求全部需要鉴权认证
|
|
|
+ .anyRequest().authenticated();
|
|
|
+ })
|
|
|
|
|
|
- // 添加Logout filter
|
|
|
- .logout(logout -> logout.logoutUrl("/logout").logoutSuccessHandler(logoutSuccessHandler))
|
|
|
- // 添加JWT filter
|
|
|
- .addFilterBefore(authenticationTokenFilter, UsernamePasswordAuthenticationFilter.class)
|
|
|
- // 添加CORS filter
|
|
|
- .addFilterBefore(corsFilter, JwtAuthenticationTokenFilter.class).addFilterBefore(corsFilter, LogoutFilter.class).build();
|
|
|
+ // 添加Logout filter
|
|
|
+ .logout(logout -> logout.logoutUrl("/logout").logoutSuccessHandler(logoutSuccessHandler))
|
|
|
+ // 添加JWT filter
|
|
|
+ .addFilterBefore(authenticationTokenFilter, UsernamePasswordAuthenticationFilter.class)
|
|
|
+ // 添加CORS filter
|
|
|
+ .addFilterBefore(corsFilter, JwtAuthenticationTokenFilter.class)
|
|
|
+ .addFilterBefore(corsFilter, LogoutFilter.class).build();
|
|
|
}
|
|
|
|
|
|
/**
|