shiro安全框架是目前为止作为登录注册最常用的框架,因为它十分的强大简单,提供了认证、授权、加密和会话管理等功能 。

  shiro能做什么?

       认证:验证用户的身份

       授权:对用户执行访问控制:判断用户是否被允许做某事

       会话管理:在任何环境下使用 Session API,即使没有 Web 或EJB 容器。

       加密:以更简洁易用的方式使用加密功能,保护或隐藏数据防止被偷窥

       Realms:聚集一个或多个用户安全数据的数据源

       单点登录(SSO)功能。

       为没有关联到登录的用户启用 "Remember Me“ 服务

  Shiro 的四大核心部分

      Authentication(身份验证):简称为“登录”,即证明用户是谁。

      Authorization(授权):访问控制的过程,即决定是否有权限去访问受保护的资源。

      Session Management(会话管理):管理用户特定的会话,即使在非 Web 或 EJB 应用程序。

      Cryptography(加密):通过使用加密算法保持数据安全

  shiro的三个核心组件:     

      Subject :正与系统进行交互的人,或某一个第三方服务。所有 Subject 实例都被绑定到(且这是必须的)一个SecurityManager 上。

      SecurityManager:Shiro 架构的心脏,用来协调内部各安全组件,管理内部组件实例,并通过它来提供安全管理的各种服务。当 Shiro 与一个 Subject 进行交互时,实质上是幕后的 SecurityManager 处理所有繁重的 Subject 安全操作。

      Realms :本质上是一个特定安全的 DAO。当配置 Shiro 时,必须指定至少一个 Realm 用来进行身份验证和/或授权。Shiro 提供了多种可用的 Realms 来获取安全相关的数据。如关系数据库(JDBC),INI 及属性文件等。可以定义自己 Realm 实现来代表自定义的数据源。

shiro整合SSM框架:

1.我的demo目录:

2.pom.xml

  1. <project xmlns="http://maven.apache.org/POM/4.0.0"
  2. xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
  3. xsi:schemaLocation="http://maven.apache.org/POM/4.0.0
  4. http://maven.apache.org/maven-v4_0_0.xsd">
  5. <modelVersion>4.0.0</modelVersion>
  6. <groupId>com.xingshang</groupId>
  7. <artifactId>ShiroDemo</artifactId>
  8. <packaging>war</packaging>
  9. <version>1.0-SNAPSHOT</version>
  10. <name>ShiroDemo Maven Webapp</name>
  11. <url>http://maven.apache.org</url>
  12. <properties>
  13. <!-- spring版本号 -->
  14. <spring.version>3.2.4.RELEASE</spring.version>
  15. <!-- mybatis版本号 -->
  16. <mybatis.version>3.2.4</mybatis.version>
  17. <!-- log4j日志文件管理包版本 -->
  18. <slf4j.version>1.6.6</slf4j.version>
  19. <log4j.version>1.2.9</log4j.version>
  20. </properties>
  21. <dependencies>
  22. <!-- spring核心包 -->
  23. <!-- springframe start -->
  24. <dependency>
  25. <groupId>org.springframework</groupId>
  26. <artifactId>spring-core</artifactId>
  27. <version>${spring.version}</version>
  28. </dependency>
  29.  
  30. <dependency>
  31. <groupId>org.springframework</groupId>
  32. <artifactId>spring-web</artifactId>
  33. <version>${spring.version}</version>
  34. </dependency>
  35.  
  36. <dependency>
  37. <groupId>org.springframework</groupId>
  38. <artifactId>spring-oxm</artifactId>
  39. <version>${spring.version}</version>
  40. </dependency>
  41.  
  42. <dependency>
  43. <groupId>org.springframework</groupId>
  44. <artifactId>spring-tx</artifactId>
  45. <version>${spring.version}</version>
  46. </dependency>
  47.  
  48. <dependency>
  49. <groupId>org.springframework</groupId>
  50. <artifactId>spring-jdbc</artifactId>
  51. <version>${spring.version}</version>
  52. </dependency>
  53.  
  54. <dependency>
  55. <groupId>org.springframework</groupId>
  56. <artifactId>spring-webmvc</artifactId>
  57. <version>${spring.version}</version>
  58. </dependency>
  59.  
  60. <dependency>
  61. <groupId>org.springframework</groupId>
  62. <artifactId>spring-aop</artifactId>
  63. <version>${spring.version}</version>
  64. </dependency>
  65.  
  66. <dependency>
  67. <groupId>org.springframework</groupId>
  68. <artifactId>spring-context-support</artifactId>
  69. <version>${spring.version}</version>
  70. </dependency>
  71.  
  72. <dependency>
  73. <groupId>org.springframework</groupId>
  74. <artifactId>spring-aop</artifactId>
  75. <version>${spring.version}</version>
  76. </dependency>
  77.  
  78. <dependency>
  79. <groupId>org.springframework</groupId>
  80. <artifactId>spring-test</artifactId>
  81. <version>${spring.version}</version>
  82. </dependency>
  83. <!-- springframe end -->
  84.  
  85. <!-- mybatis核心包 -->
  86. <dependency>
  87. <groupId>org.mybatis</groupId>
  88. <artifactId>mybatis</artifactId>
  89. <version>${mybatis.version}</version>
  90. </dependency>
  91. <!-- mybatis/spring包 -->
  92. <dependency>
  93. <groupId>org.mybatis</groupId>
  94. <artifactId>mybatis-spring</artifactId>
  95. <version>1.2.2</version>
  96. </dependency>
  97. <!-- mysql驱动包 -->
  98. <dependency>
  99. <groupId>mysql</groupId>
  100. <artifactId>mysql-connector-java</artifactId>
  101. <version>5.1.29</version>
  102. </dependency>
  103. <!-- junit测试包 -->
  104. <dependency>
  105. <groupId>junit</groupId>
  106. <artifactId>junit</artifactId>
  107. <version>4.11</version>
  108. <scope>test</scope>
  109. </dependency>
  110. <!-- 阿里巴巴数据源 包 -->
  111. <dependency>
  112. <groupId>com.alibaba</groupId>
  113. <artifactId>druid</artifactId>
  114. <version>1.0.2</version>
  115. </dependency>
  116.  
  117. <!-- json数据 -->
  118. <dependency>
  119. <groupId>org.codehaus.jackson</groupId>
  120. <artifactId>jackson-mapper-asl</artifactId>
  121. <version>1.9.13</version>
  122. </dependency>
  123.  
  124. <!-- 日志文件管理包 -->
  125. <!-- log start -->
  126. <dependency>
  127. <groupId>log4j</groupId>
  128. <artifactId>log4j</artifactId>
  129. <version>${log4j.version}</version>
  130. </dependency>
  131. <dependency>
  132. <groupId>org.slf4j</groupId>
  133. <artifactId>slf4j-api</artifactId>
  134. <version>${slf4j.version}</version>
  135. </dependency>
  136. <dependency>
  137. <groupId>org.slf4j</groupId>
  138. <artifactId>slf4j-log4j12</artifactId>
  139. <version>${slf4j.version}</version>
  140. </dependency>
  141. <!-- log end -->
  142.  
  143. <!--shiro核心包-->
  144. <dependency>
  145. <groupId>org.apache.shiro</groupId>
  146. <artifactId>shiro-core</artifactId>
  147. <version>1.2.2</version>
  148. </dependency>
  149. <!--shiro web支持-->
  150. <dependency>
  151. <groupId>org.apache.shiro</groupId>
  152. <artifactId>shiro-web</artifactId>
  153. <version>1.2.2</version>
  154. </dependency>
  155. <!--shiro spring支持-->
  156. <dependency>
  157. <groupId>org.apache.shiro</groupId>
  158. <artifactId>shiro-spring</artifactId>
  159. <version>1.2.2</version>
  160. </dependency>
  161. <!---->
  162. <dependency>
  163. <groupId>org.apache.shiro</groupId>
  164. <artifactId>shiro-ehcache</artifactId>
  165. <version>1.2.2</version>
  166. </dependency>
  167. <dependency>
  168. <groupId>com.alipay</groupId>
  169. <artifactId>sdk-java</artifactId>
  170. <version>20180309170622</version>
  171. </dependency>
  172. </dependencies>
  173. <build>
  174. <finalName>ShiroDemo</finalName>
  175. </build>
  176. </project>

3.配置 web.xml 文件

  1. <?xml version="1.0" encoding="UTF-8"?>
  2. <web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
  3. xmlns="http://java.sun.com/xml/ns/javaee"
  4. xmlns:jsp="http://java.sun.com/xml/ns/javaee/jsp"
  5. xsi:schemaLocation="http://java.sun.com/xml/ns/javaee
  6. http://java.sun.com/xml/ns/javaee/web-app_3_0.xsd"
  7. id="WebApp_ID3" version="3.0">
  8.  
  9. <display-name>Archetype Created Web Application</display-name>
  10.  
  11. <!-- 读取spring配置文件 -->
  12. <context-param>
  13. <param-name>contextConfigLocation</param-name>
  14. <param-value>classpath:spring-*.xml</param-value>
  15. </context-param>
  16.  
  17. <!-- Spring字符集过滤器 -->
  18. <filter>
  19. <filter-name>SpringEncodingFilter</filter-name>
  20. <filter-class>org.springframework.web.filter.CharacterEncodingFilter</filter-class>
  21. <init-param>
  22. <param-name>encoding</param-name>
  23. <param-value>UTF-8</param-value>
  24. </init-param>
  25. <init-param>
  26. <param-name>forceEncoding</param-name>
  27. <param-value>true</param-value>
  28. </init-param>
  29. </filter>
  30. <filter-mapping>
  31. <filter-name>SpringEncodingFilter</filter-name>
  32. <url-pattern>/*</url-pattern>
  33. </filter-mapping>
  34.  
  35. <!-- springMVC核心配置 -->
  36. <!--前端控制器-->
  37. <servlet>
  38. <servlet-name>springMVC</servlet-name>
  39. <servlet-class>org.springframework.web.servlet.DispatcherServlet</servlet-class>
  40. <!--初始化所需配置文件位置-->
  41. <init-param>
  42. <param-name>contextConfigLocation</param-name>
  43. <param-value>classpath:spring-mvc.xml</param-value>
  44. </init-param>
  45. <load-on-startup>1</load-on-startup>
  46. </servlet>
  47. <!--设置拦截路径-->
  48. <servlet-mapping>
  49. <servlet-name>springMVC</servlet-name>
  50. <url-pattern>/</url-pattern>
  51. </servlet-mapping>
  52.  
  53. <!--Filter的代理器:shiro拦截-->
  54. <filter>
  55. <filter-name>shiroFilter</filter-name>
  56. <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
  57. <!--DelegatingFilterProxy:去spring的容器中去找filter—name相同名字的bean-->
  58. <init-param>
  59. <param-name>targetFilterLifecycle</param-name>
  60. <param-value>true</param-value>
  61. </init-param>
  62. </filter>
  63. <filter-mapping>
  64. <filter-name>shiroFilter</filter-name>
  65. <url-pattern>/*</url-pattern>
  66. </filter-mapping>
  67.  
  68. <!-- 日志记录 -->
  69. <context-param>
  70. <!-- 日志配置文件路径 -->
  71. <param-name>log4jConfigLocation</param-name>
  72. <param-value>classpath:log4j.properties</param-value>
  73. </context-param>
  74. <context-param>
  75. <!-- 日志页面的刷新间隔 -->
  76. <param-name>log4jRefreshInterval</param-name>
  77. <param-value>6000</param-value>
  78. </context-param>
  79.  
  80. <listener>
  81. <listener-class>org.springframework.web.util.Log4jConfigListener</listener-class>
  82. </listener>
  83.  
  84. <!--spring监听器-->
  85. <listener>
  86. <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class>
  87. </listener>
  88.  
  89. <welcome-file-list>
  90. <welcome-file>login.jsp</welcome-file>
  91. </welcome-file-list>
  92.  
  93. <!-- 错误跳转页面 -->
  94. <error-page>
  95. <!-- 路径不正确 -->
  96. <error-code>404</error-code>
  97. <location>/WEB-INF/file/404.jsp</location>
  98. </error-page>
  99. <error-page>
  100. <!-- 没有访问权限,访问被禁止 -->
  101. <error-code>405</error-code>
  102. <location>/WEB-INF/file/405.jsp</location>
  103. </error-page>
  104. <error-page>
  105. <!-- 内部错误 -->
  106. <error-code>500</error-code>
  107. <location>/WEB-INF/file/500.jsp</location>
  108. </error-page>
  109.  
  110. </web-app>

4.spring-mybatis.xml

  1. <?xml version="1.0" encoding="UTF-8"?>
  2. <beans xmlns="http://www.springframework.org/schema/beans"
  3. xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
  4. xmlns:p="http://www.springframework.org/schema/p"
  5. xmlns:context="http://www.springframework.org/schema/context"
  6. xmlns:aop="http://www.springframework.org/schema/aop"
  7. xmlns:tx="http://www.springframework.org/schema/tx"
  8. xmlns:util="http://www.springframework.org/schema/util"
  9. xsi:schemaLocation="http://www.springframework.org/schema/beans
  10. http://www.springframework.org/schema/beans/spring-beans-3.2.xsd
  11. http://www.springframework.org/schema/context
  12. http://www.springframework.org/schema/context/spring-context-3.2.xsd
  13. http://www.springframework.org/schema/tx
  14. http://www.springframework.org/schema/tx/spring-tx-3.2.xsd
  15. http://www.springframework.org/schema/aop
  16. http://www.springframework.org/schema/aop/spring-aop-3.2.xsd
  17. http://www.springframework.org/schema/util
  18. http://www.springframework.org/schema/util/spring-util-3.2.xsd">
  19. <!-- 引入jdbc配置文件 -->
  20. <context:property-placeholder location="classpath:jdbc.properties" />
  21. <bean id="dataSource" class="com.alibaba.druid.pool.DruidDataSource"
  22. init-method="init" destroy-method="close">
  23. <property name="driverClassName">
  24. <value>${jdbc_driverClassName}</value>
  25. </property>
  26. <property name="url">
  27. <value>${jdbc_url}</value>
  28. </property>
  29. <property name="username">
  30. <value>${jdbc_username}</value>
  31. </property>
  32. <property name="password">
  33. <value>${jdbc_password}</value>
  34. </property>
  35. <!-- 连接池最大使用连接数 -->
  36. <property name="maxActive">
  37. <value>20</value>
  38. </property>
  39. <!-- 初始化连接大小 -->
  40. <property name="initialSize">
  41. <value>1</value>
  42. </property>
  43. <!-- 获取连接最大等待时间 -->
  44. <property name="maxWait">
  45. <value>60000</value>
  46. </property>
  47. <!-- 连接池最大空闲 -->
  48. <property name="maxIdle">
  49. <value>20</value>
  50. </property>
  51. <!-- 连接池最小空闲 -->
  52. <property name="minIdle">
  53. <value>3</value>
  54. </property>
  55. <!-- 自动清除无用连接 -->
  56. <property name="removeAbandoned">
  57. <value>true</value>
  58. </property>
  59. <!-- 清除无用连接的等待时间 -->
  60. <property name="removeAbandonedTimeout">
  61. <value>180</value>
  62. </property>
  63. <!-- 连接属性 -->
  64. <property name="connectionProperties">
  65. <value>clientEncoding=UTF-8</value>
  66. </property>
  67. </bean>
  68.  
  69. <!-- mybatis文件配置,扫描所有mapper文件 -->
  70. <!-- configLocation为mybatis属性;mapperLocations为所有mapper -->
  71. <bean id="sqlSessionFactory" class="org.mybatis.spring.SqlSessionFactoryBean"
  72. p:dataSource-ref="dataSource" p:configLocation="classpath:mybatis-config.xml"
  73. p:mapperLocations="classpath:mapper/*.xml" />
  74.  
  75. <!-- spring与mybatis整合配置,扫描所有dao -->
  76. <bean class="org.mybatis.spring.mapper.MapperScannerConfigurer"
  77. p:basePackage="com.xingshang.dao" p:sqlSessionFactoryBeanName="sqlSessionFactory" />
  78.  
  79. <!-- 对数据源进行事务管理 -->
  80. <bean id="transactionManager"
  81. class="org.springframework.jdbc.datasource.DataSourceTransactionManager"
  82. p:dataSource-ref="dataSource" />
  83. </beans>

5.spring-mvc.xml

  1. <?xml version="1.0" encoding="UTF-8"?>
  2. <beans xmlns="http://www.springframework.org/schema/beans"
  3. xmlns:p="http://www.springframework.org/schema/p"
  4. xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
  5. xmlns:context="http://www.springframework.org/schema/context"
  6. xmlns:mvc="http://www.springframework.org/schema/mvc"
  7. xsi:schemaLocation="
  8. http://www.springframework.org/schema/beans
  9. http://www.springframework.org/schema/beans/spring-beans-3.2.xsd
  10. http://www.springframework.org/schema/context
  11. http://www.springframework.org/schema/context/spring-context-3.2.xsd
  12. http://www.springframework.org/schema/mvc
  13. http://www.springframework.org/schema/mvc/spring-mvc-3.2.xsd">
  14.  
  15. <!-- 扫描controller(controller层注入) -->
  16. <context:component-scan base-package="com.xingshang.controller" />
  17.  
  18. <!-- 避免IE在ajax请求时,返回json出现下载 -->
  19. <bean id="jacksonMessageConverter"
  20. class="org.springframework.http.converter.json.MappingJacksonHttpMessageConverter">
  21. <property name="supportedMediaTypes">
  22. <list>
  23. <value>text/html;charset=UTF-8</value>
  24. </list>
  25. </property>
  26. </bean>
  27.  
  28. <mvc:annotation-driven>
  29. <mvc:message-converters register-defaults="true">
  30. <bean class="org.springframework.http.converter.StringHttpMessageConverter">
  31. <constructor-arg value="UTF-8" />
  32. </bean>
  33. </mvc:message-converters>
  34. </mvc:annotation-driven>
  35.  
  36. <!-- 对模型视图添加前后缀 -->
  37. <bean id="viewResolver"
  38. class="org.springframework.web.servlet.view.InternalResourceViewResolver"
  39. p:prefix="/WEB-INF/" p:suffix=".jsp" />
  40.  
  41. <!-- 开启shiro的注解支持 -->
  42. <bean id="defaultAdvisorAutoProxyCreator" class="org.springframework.aop.framework.autoproxy.DefaultAdvisorAutoProxyCreator">
  43. <!-- 必须改为true,即使用cglib方式为Action创建代理对象。默认值为false,使用JDK创建代理对象,会造成问题 -->
  44. <property name="proxyTargetClass" value="true"></property>
  45. </bean>
  46.  
  47. <!-- 使用shiro框架提供的切面类,用于创建代理对象 -->
  48. <bean class="org.apache.shiro.spring.security.interceptor.AuthorizationAttributeSourceAdvisor"></bean>
  49.  
  50. </beans>

6.jdbc.properties

  1. jdbc_driverClassName=com.mysql.jdbc.Driver
  2. jdbc_url=jdbc:mysql://localhost:3306/shirodemo
  3. jdbc_username=root
  4. jdbc_password=123456

7.log4j.properties

  1. ### set log levels ###
  2. #log4j.rootLogger = debug , stdout , D , E
  3. log4j.rootLogger = debug , stdout , D
  4.  
  5. ### output to the console ###
  6. log4j.appender.stdout = org.apache.log4j.ConsoleAppender
  7. log4j.appender.stdout.Target = System.out
  8. log4j.appender.stdout.layout = org.apache.log4j.PatternLayout
  9. #log4j.appender.stdout.layout.ConversionPattern = %d{ABSOLUTE} %5p %c{ 1 }:%L - %m%n
  10. log4j.appender.stdout.layout.ConversionPattern = %-d{yyyy-MM-dd HH:mm:ss} [%c]-[%p] %m%n
  11.  
  12. ### Output to the log file ###
  13. log4j.appender.D = org.apache.log4j.DailyRollingFileAppender
  14. log4j.appender.D.File = ${springmvc.root}/WEB-INF/logs/log.log
  15. log4j.appender.D.Append = true
  16. log4j.appender.D.Threshold = DEBUG
  17. log4j.appender.D.layout = org.apache.log4j.PatternLayout
  18. log4j.appender.D.layout.ConversionPattern = %-d{yyyy-MM-dd HH:mm:ss} [ %t:%r ] - [ %p ] %m%n
  19.  
  20. ### Save exception information to separate file ###
  21. log4j.appender.D = org.apache.log4j.DailyRollingFileAppender
  22. log4j.appender.D.File = ${springmvc.root}/WEB-INF/logs/error.log
  23. log4j.appender.D.Append = true
  24. log4j.appender.D.Threshold = ERROR
  25. log4j.appender.D.layout = org.apache.log4j.PatternLayout
  26. log4j.appender.D.layout.ConversionPattern = %-d{yyyy-MM-dd HH:mm:ss} [ %t:%r ] - [ %p ] %m%n

8.spring-shiro.xml

  1. <?xml version="1.0" encoding="UTF-8"?>
  2. <beans xmlns="http://www.springframework.org/schema/beans"
  3. xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
  4. xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-3.1.xsd">
  5. <!-- 配置 ShiroFilter bean: 该 bean 的 id 必须和 web.xml 文件中配置的 shiro filter 的 name 一致 -->
  6. <bean id="shiroFilter" class="org.apache.shiro.spring.web.ShiroFilterFactoryBean">
  7. <!-- 装配 securityManager:shiro核心安全接口,这个属性是必须的-->
  8. <property name="securityManager" ref="securityManager"/>
  9. <!-- 配置登陆页面 非必须,若没有指定shiro会在web工程下寻找indexjsp页面-->
  10. <property name="loginUrl" value="/login.jsp"/>
  11. <!-- 登陆成功后的页面 -->
  12. <property name="successUrl" value="/success.jsp"/>
  13. <!--用户访问未对其授权的页面时所跳转的页面-->
  14. <property name="unauthorizedUrl" value="WEB-INF/file/500.jsp"/>
  15. <!--代表需要完成的shiro过滤器的具体配置-->
  16.  
  17. <!-- 具体配置需要拦截哪些 URL, 以及访问对应的 URL 时使用 Shiro 的什么 Filter 进行拦截.
  18. 不同的filter有不同的拦截级别
  19. anon:不需要登入
  20. authc:必须需要登入
  21. 应用
  22. /**=authc,都必须登入才能访问
  23. -->
  24. <property name="filterChainDefinitions">
  25. <value>
  26. /WEB-INF/index.jsp=anon
  27. /WEB-INF/fail/*.jsp=anon
  28. /login=anon
  29. /**=authc
  30. </value>
  31. </property>
  32. </bean>
  33.  
  34. <!-- 配置 Shiro 的 SecurityManager Bean. -->
  35. <!--配置安全管理器-->
  36. <bean id="securityManager" class="org.apache.shiro.web.mgt.DefaultWebSecurityManager">
  37. <!--引入缓存管理器-->
  38. <property name="cacheManager" ref="cacheManager"/>
  39. <!-- 目标realm的实现-->
  40. <property name="realm" ref="myRealm"/>
  41. <!-- <property name="sessionMode" value="native"/>-->
  42. </bean>
  43.  
  44. <!-- 配置缓存管理器 -->
  45. <bean id="cacheManager" class="org.apache.shiro.cache.ehcache.EhCacheManager">
  46. <!-- 指定 ehcache 的配置文件 -->
  47. <property name="cacheManagerConfigFile" value="classpath:ehcache-shiro.xml"/>
  48. </bean>
  49.  
  50. <!-- 配置进行授权和认证的 Realm -->
  51. <bean id="myRealm" class="com.xingshang.realm.MyRealm">
  52. <property name="credentialsMatcher">
  53. <bean class="org.apache.shiro.authc.credential.HashedCredentialsMatcher">
  54. <!-- 加密算法为MD5 -->
  55. <property name="hashAlgorithmName" value="MD5"></property>
  56. <!-- 加密次数 -->
  57. <property name="hashIterations" value="2"></property>
  58. </bean>
  59. </property>
  60.  
  61. </bean>
  62.  
  63. <!-- 配置 Bean 后置处理器: 会自动的调用和 Spring 整合后各个组件的生命周期方法. -->
  64. <bean id="lifecycleBeanPostProcessor" class="org.apache.shiro.spring.LifecycleBeanPostProcessor"/>
  65.  
  66. </beans>

9.ehcache-shiro.xml

  1. <ehcache updateCheck="false" name="shiroCache">
  2.  
  3. <defaultCache
  4. maxElementsInMemory="10000"
  5. eternal="false"
  6. timeToIdleSeconds="120"
  7. timeToLiveSeconds="120"
  8. overflowToDisk="false"
  9. diskPersistent="false"
  10. diskExpiryThreadIntervalSeconds="120"
  11. />
  12. </ehcache>

10.mybatis-config.xml

  1. <?xml version="1.0" encoding="UTF-8" ?>
  2. <!DOCTYPE configuration
  3. PUBLIC "-//mybatis.org//DTD Config 3.0//EN"
  4. "http://mybatis.org/dtd/mybatis-3-config.dtd">
  5. <configuration>
  6. <!-- 命名空间 -->
  7.  
  8. </configuration>

到这一步,配置文件都基本准备好了,接下来要写Realm方法了,新建realm包,在包下新建MyRealm.java文件继承AuthorizingRealm

  1. package com.xingshang.realm;
  2.  
  3. import com.xingshang.dao.UserDao;
  4. import com.xingshang.entity.User;
  5. import org.apache.shiro.authc.*;
  6. import org.apache.shiro.authz.AuthorizationInfo;
  7. import org.apache.shiro.authz.SimpleAuthorizationInfo;
  8. import org.apache.shiro.realm.AuthorizingRealm;
  9. import org.apache.shiro.subject.PrincipalCollection;
  10. import org.springframework.beans.factory.annotation.Autowired;
  11. import org.apache.shiro.util.ByteSource.Util;
  12.  
  13. import java.util.HashSet;
  14. import java.util.List;
  15. import java.util.Set;
  16.  
  17. public class MyRealm extends AuthorizingRealm {
  18.  
  19. @Autowired
  20. private UserDao userDao;
  21.  
  22. /**
  23. * 1、登入认证
  24. * thenticationInfo:获取认证消息,如果数据库中没有,返回null,如果得到正确的用户名和密码
  25. * 2、AuthenticationInfo 可用simpleAuthenticationInfo实现类,封装获取到的正确的账号和密码
  26. * 返回正定类型的对象
  27. *
  28. * @param authenticationToken
  29. * @return
  30. * @throws AuthenticationException
  31. */
  32. protected SimpleAuthenticationInfo doGetAuthenticationInfo(AuthenticationToken authenticationToken) throws AuthenticationException {
  33.  
  34. //1、将token转换为UserNamePasswordToken
  35. UsernamePasswordToken uptoken = (UsernamePasswordToken) authenticationToken;
  36.  
  37. //2、获取用户名
  38. User user = new User();
  39. user.setUsername(uptoken.getUsername());
  40. user.setPassword(uptoken.getPassword().toString());
  41.  
  42. User us = userDao.login(user);
  43. if (us != null) {
  44. SimpleAuthenticationInfo authenticationInfo
  45. = new SimpleAuthenticationInfo(us.getUsername(), us.getPassword(), "a");
  46. authenticationInfo.setCredentialsSalt(Util.bytes(us.getSalt()));
  47. return authenticationInfo;
  48. } else {
  49. throw new ExcessiveAttemptsException("账号密码错误");
  50. }
  51. }
  52.  
  53. /**
  54. * 权限角色认证
  55. *
  56. * @param principalCollection
  57. * @return
  58. */
  59. protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principalCollection) {
  60. String username = principalCollection.getPrimaryPrincipal().toString();
  61.  
  62. List<String> roles = userDao.selectRole(username);
  63. List<String> permissions = userDao.selectPermission(username);
  64.  
  65. Set<String> ro = new HashSet<String>();
  66. Set<String> per = new HashSet<String>();
  67.  
  68. for (String role : roles) {
  69. ro.add(role);
  70. }
  71. for (String permission : permissions) {
  72. per.add(permission);
  73. }
  74.  
  75. SimpleAuthorizationInfo sim = new SimpleAuthorizationInfo();
  76. sim.setRoles(ro);
  77. sim.setStringPermissions(per);
  78.  
  79. return sim;
  80. }
  81. }

好了,接下来我们写一个简单的controller来通过shiro登录验证。

  1. package com.xingshang.controller;
  2.  
  3. import org.apache.shiro.SecurityUtils;
  4. import org.apache.shiro.authc.UsernamePasswordToken;
  5. import org.apache.shiro.subject.Subject;
  6. import org.springframework.stereotype.Controller;
  7. import org.springframework.web.bind.annotation.RequestMapping;
  8. import org.springframework.web.bind.annotation.RequestParam;
  9. import org.springframework.web.bind.annotation.ResponseBody;
  10.  
  11. @Controller
  12. public class LoginController {
  13.  
  14. @RequestMapping("/login")
  15. public String login(@RequestParam("username") String username,@RequestParam("password") String password){
  16. Subject subject = SecurityUtils.getSubject();
  17. if (!subject.isAuthenticated()){
  18. UsernamePasswordToken token = new UsernamePasswordToken(username,password);
  19. try {
              //执行认证操作
  20. subject.login(token);
  21. }catch (Exception e){
  22. return e.getMessage();
  23. }
  24. }
  25. return "success";
  26. }
  27.  
  28. @RequestMapping("/test1")
  29. @ResponseBody
  30. public String test1(){
  31. Subject subject = SecurityUtils.getSubject();
  32. try {
  33. subject.checkRole("admin");
  34. }catch (Exception e){
  35. return "不拥有admin角色";
  36. }
  37. return "拥有admin角色";
  38. }
  39.  
  40. @RequestMapping("/test2")
  41. @ResponseBody
  42. public String test2(){
  43. Subject subject= SecurityUtils.getSubject();
  44. try {
  45. subject.checkRole("CEO");
  46. }catch (Exception e){
  47. return "不拥有CEO角色";
  48. }
  49. return "拥有admin角色";
  50. }
  51. }

login.jsp

  1. <%@ page language="java" contentType="text/html; charset=utf-8" %>
  2. <html>
  3. <head>
  4. <title>Title</title>
  5. </head>
  6. <body>
  7. <form action="/login" method="post">
  8. <div>
  9. 账号:<input type="text" name="username">
  10. </div>
  11. <div>
  12. 密码:<input type="password" name="password">
  13. </div>
  14. <div>
  15. <input type="submit" value="登入">
  16. </div>
  17. </form>
  18. </body>
  19. </html>

success.jsp

  1. <%--
  2. Created by IntelliJ IDEA.
  3. User: Administrator
  4. Date: 2018/3/19
  5. Time: 9:31
  6. To change this template use File | Settings | File Templates.
  7. --%>
  8. <%@ page contentType="text/html;charset=UTF-8" language="java" %>
  9. <html>
  10. <head>
  11. <title>Title</title>
  12. </head>
  13. <body>
  14. <a href="/test1">是不是admin</a>
  15. <a href="/test2">是不是ceo</a>
  16. </body>
  17. </html>

UserMapper.xml

  1. <?xml version="1.0" encoding="UTF-8" ?>
  2. <!DOCTYPE mapper PUBLIC "-//mybatis.org//DTD Mapper 3.0//EN" "http://mybatis.org/dtd/mybatis-3-mapper.dtd" >
  3. <mapper namespace="com.xingshang.dao.UserDao" >
  4.  
  5. <select id="login" resultType="com.xingshang.entity.User" parameterType="com.xingshang.entity.User">
  6. SELECT u.username,
  7. u.password,
  8. r.roleId AS "roleid",
  9. CONCAT(u.username,u.password_salt) AS "salt"
  10. FROM users u JOIN user_role r
  11. on u.id=r.userId
  12. WHERE u.username=#{userName}
  13. </select>
  14.  
  15. <select id="selectRole" parameterType="String" resultType="String">
  16. SELECT r.role FROM roles r
  17. where r.id=(select z.roleId FROM users u
  18. join user_role z on u.id=z.userId
  19. where u.username=#{username})
  20. </select>
  21.  
  22. <select id="selectPermission" parameterType="String" resultType="String">
  23. select p.permission from permissions p
  24. join role_permisssion x on p.id=x.permissionId
  25. where x.roleId=(select z.roleId FROM users u
  26. join user_role z on u.id=z.userId
  27. where u.username=#{username})
  28. </select>
  29.  
  30. </mapper>

shirodemo.sql

  1. /*
  2. Navicat MySQL Data Transfer
  3.  
  4. Source Server : localhost_3306
  5. Source Server Version : 50558
  6. Source Host : localhost:3306
  7. Source Database : shirodemo
  8.  
  9. Target Server Type : MYSQL
  10. Target Server Version : 50558
  11. File Encoding : 65001
  12.  
  13. Date: 2018-03-26 21:27:58
  14. */
  15.  
  16. SET FOREIGN_KEY_CHECKS=0;
  17. -- ----------------------------
  18. -- Table structure for `permissions`
  19. -- ----------------------------
  20. DROP TABLE IF EXISTS `permissions`;
  21. CREATE TABLE `permissions` (
  22. `id` int(11) NOT NULL,
  23. `permission` varchar(255) DEFAULT NULL,
  24. PRIMARY KEY (`id`)
  25. ) ENGINE=InnoDB DEFAULT CHARSET=utf8;
  26.  
  27. -- ----------------------------
  28. -- Records of permissions
  29. -- ----------------------------
  30. INSERT INTO `permissions` VALUES ('', 'add');
  31. INSERT INTO `permissions` VALUES ('', 'delete');
  32. INSERT INTO `permissions` VALUES ('', 'update');
  33. INSERT INTO `permissions` VALUES ('', 'select');
  34.  
  35. -- ----------------------------
  36. -- Table structure for `role_permisssion`
  37. -- ----------------------------
  38. DROP TABLE IF EXISTS `role_permisssion`;
  39. CREATE TABLE `role_permisssion` (
  40. `id` int(11) NOT NULL AUTO_INCREMENT,
  41. `roleId` int(255) DEFAULT NULL,
  42. `permissionId` int(11) DEFAULT NULL,
  43. PRIMARY KEY (`id`)
  44. ) ENGINE=InnoDB AUTO_INCREMENT=3 DEFAULT CHARSET=utf8;
  45.  
  46. -- ----------------------------
  47. -- Records of role_permisssion
  48. -- ----------------------------
  49. INSERT INTO `role_permisssion` VALUES ('', '', '');
  50. INSERT INTO `role_permisssion` VALUES ('', '', '');
  51.  
  52. -- ----------------------------
  53. -- Table structure for `roles`
  54. -- ----------------------------
  55. DROP TABLE IF EXISTS `roles`;
  56. CREATE TABLE `roles` (
  57. `id` int(11) NOT NULL,
  58. `role` varchar(255) DEFAULT NULL,
  59. PRIMARY KEY (`id`)
  60. ) ENGINE=InnoDB DEFAULT CHARSET=utf8;
  61.  
  62. -- ----------------------------
  63. -- Records of roles
  64. -- ----------------------------
  65. INSERT INTO `roles` VALUES ('', 'CEO');
  66. INSERT INTO `roles` VALUES ('', 'CTO');
  67. INSERT INTO `roles` VALUES ('', 'CFO');
  68. INSERT INTO `roles` VALUES ('', 'admin');
  69.  
  70. -- ----------------------------
  71. -- Table structure for `user_role`
  72. -- ----------------------------
  73. DROP TABLE IF EXISTS `user_role`;
  74. CREATE TABLE `user_role` (
  75. `id` int(11) NOT NULL AUTO_INCREMENT,
  76. `userId` int(11) DEFAULT NULL,
  77. `roleId` int(11) DEFAULT NULL,
  78. PRIMARY KEY (`id`)
  79. ) ENGINE=InnoDB AUTO_INCREMENT=6 DEFAULT CHARSET=utf8 ROW_FORMAT=DYNAMIC;
  80.  
  81. -- ----------------------------
  82. -- Records of user_role
  83. -- ----------------------------
  84. INSERT INTO `user_role` VALUES ('', '', '');
  85. INSERT INTO `user_role` VALUES ('', '', '');
  86. INSERT INTO `user_role` VALUES ('', '', '');
  87. INSERT INTO `user_role` VALUES ('', '', '');
  88. INSERT INTO `user_role` VALUES ('', '', '');
  89.  
  90. -- ----------------------------
  91. -- Table structure for `users`
  92. -- ----------------------------
  93. DROP TABLE IF EXISTS `users`;
  94. CREATE TABLE `users` (
  95. `id` bigint(20) NOT NULL AUTO_INCREMENT,
  96. `username` varchar(100) DEFAULT NULL,
  97. `password` varchar(100) DEFAULT NULL,
  98. `password_salt` varchar(100) DEFAULT NULL,
  99. PRIMARY KEY (`id`),
  100. UNIQUE KEY `idx_users_username` (`username`)
  101. ) ENGINE=InnoDB AUTO_INCREMENT=9 DEFAULT CHARSET=utf8;
  102.  
  103. -- ----------------------------
  104. -- Records of users
  105. -- ----------------------------INSERT INTO `users` VALUES ('', 'miaomiao', '2a9c616f5dc6d23329ad4622ff8fa89f', 'b58c47e10cc56807ce31010a41c7fa65');
  106. INSERT INTO `users` VALUES ('', 'admin', '', null);
  1. //执行认证操作.

ssm框架与shiro的整合小demo,用idea开发+maven管理的更多相关文章

  1. 《SSM框架搭建》三.整合spring web

    感谢学习http://blog.csdn.net/zhshulin/article/details/37956105#,还是修改了spring到最新的版本和接口开发示例 根据前一篇日志,已经有了myb ...

  2. Eclipse 整合SpringMybatis,SpringMVC,用Maven管理项目搭建详情

    环境:JDK下载地址 https://pan.baidu.com/s/1UyvEAI-4Ci6TDdVJiYUUiQ 密码:ma51 IDE:eclipse下载地址 https://pan.baidu ...

  3. SSM框架整合搭建教程

    自己配置了一个SSM框架,打算做个小网站,这里把SSM的配置流程详细的写了出来,方便很少接触这个框架的朋友使用,文中各个资源均免费提供! 一. 创建web项目(eclipse) File-->n ...

  4. shiro框架整合ssm框架

    下面我通过一个web的maven项目来讲解如何将shiro整合ssm框架,具体结构如下图 一.引入依赖的jar包 <?xml version="1.0" encoding=& ...

  5. shiro权限控制(一):shiro介绍以及整合SSM框架

    shiro安全框架是目前为止作为登录注册最常用的框架,因为它十分的强大简单,提供了认证.授权.加密和会话管理等功能 . shiro能做什么? 认证:验证用户的身份 授权:对用户执行访问控制:判断用户是 ...

  6. SSM框架整合Demo

    目前项目大都开始采用SSM结构进行搭建,因为涉及项目比较多,新来的需求都是从现有项目中迁移一份出来进行修改,有的时候两个项目差别还是比较大,并不完全需要原有项目的东西,进行删减也是一项费神费时的事情, ...

  7. 整合最优雅SSM框架:SpringMVC + Spring + MyBatis

    我们看招聘信息的时候,经常会看到这一点,需要具备SSH框架的技能:而且在大部分教学课堂中,也会把SSH作为最核心的教学内容. 但是,我们在实际应用中发现,SpringMVC可以完全替代Struts,配 ...

  8. 手把手教你整合最优雅SSM框架:SpringMVC + Spring + MyBatis

    在写代码之前我们先了解一下这三个框架分别是干什么的? 相信大以前也看过不少这些概念,我这就用大白话来讲,如果之前有了解过可以跳过这一大段,直接看代码! SpringMVC:它用于web层,相当于con ...

  9. ssm框架整合快速入门

    写在前面: 公司一直都是使用ssh框架(Struts2,Spring,Hibernate)来开发,但是现在外面的公司大多数都是使用的ssm框架,所以也有必要多学习一下外面的新技术.这里就快速搭建一个小 ...

随机推荐

  1. 互联网我来了 -- 2. js中&quot;异步/堵塞&quot;等概念的简析

    一.什么是"异步非堵塞式"? 这个名字听起来非常恶心难懂,但假设以 买内裤 这件事情来比喻运行程序的话就非常easy理解"异步非堵塞式"的涵义了. 比如你是一个 ...

  2. Android API Guides---RenderScript

    RenderScript RenderScript是在Android上的高性能执行计算密集型任务的框架. RenderScript主要面向与数据并行计算的使用.尽管串行计算密集型工作负载能够受益.该R ...

  3. DevOpsDays 活动咨询网站

    站点:http://www.41huiyi.com/event-1452630998.html

  4. OrCAD16.6中对比两份DSN文件的方法

    OrCAD16.6中对比两份改版前后DSN文件的方法 两种方法: (1)第一种用软件对比netlist (2)用orcad自带的对比功能 一.将两份要对比的原理图都生成orTelesis.dll格式的 ...

  5. xgboost 特征选择,筛选特征的正要性

    import pandas as pd import xgboost as xgb import operator from matplotlib import pylab as plt def ce ...

  6. angularjs中的$q

    先说说什么是Promise,什么是$q吧.Promise是一种异步处理模式,有很多的实现方式,比如著名的Kris Kwal's Q还有JQuery的Deffered. 什么是Promise 以前了解过 ...

  7. OpenGL/GLSL数据传递小记(3.x)(转)

    OpenGL/GLSL规范在不断演进着,我们渐渐走进可编程管道的时代的同时,崭新的功能接口也让我们有点缭乱的感觉.本文再次从OpenGL和GLSL之间数据的传递这一点,记录和介绍基于OpenGL3.x ...

  8. jquery的push()

    JavaScript push() 方法 JavaScript Array 对象 定义和用法 push() 方法可向数组的末尾添加一个或多个元素,并返回新的长度. 语法 arrayObject.pus ...

  9. centos7 改变终端背景色

    首先打开终端 2:选择 edit->preferences->profile 3: "model1"是我自己改的名字,最开始是"unname".双击 ...

  10. scala 编写wordCount

    加载文件 scala> var f1=sc.textFile("/tmp/dataTest/followers.txt") scala> f1.flatMap(x=&g ...