我们在平常使用Shrio进行身份认证时,经常通过获取Subject 对象中保存的Session、Principal等信息,来获取认证用户的信息,也就是说Shiro会把认证后的用户信息保存在Subject 中供程序使用

  1. public static Subject getSubject()
  2. {
  3. return SecurityUtils.getSubject();
  4. }

Subject 是Shiro中核心的也是我们经常用到的一个对象,那么Subject 对象是怎么构造创建,并如何存储绑定供程序调用的,下面我们就对其流程进行一下探究,首先是Subject 接口本身的继承与实现,这里我们需要特别关注下WebDelegatingSubject这个实现类,这个就是最终返回的具体实现类



  1. protected void doFilterInternal(ServletRequest servletRequest, ServletResponse servletResponse, final FilterChain chain)
  2. throws ServletException, IOException {
  4. Throwable t = null;
  6. try {
  7. final ServletRequest request = prepareServletRequest(servletRequest, servletResponse, chain);
  8. final ServletResponse response = prepareServletResponse(request, servletResponse, chain);
  10. //创建Subject
  11. final Subject subject = createSubject(request, response);
  13. //执行Subject绑定
  14. //noinspection unchecked
  15. subject.execute(new Callable() {
  16. public Object call() throws Exception {
  17. updateSessionLastAccessTime(request, response);
  18. executeChain(request, response, chain);
  19. return null;
  20. }
  21. });
  22. } catch (ExecutionException ex) {
  23. t = ex.getCause();
  24. } catch (Throwable throwable) {
  25. t = throwable;
  26. }
  28. if (t != null) {
  29. if (t instanceof ServletException) {
  30. throw (ServletException) t;
  31. }
  32. if (t instanceof IOException) {
  33. throw (IOException) t;
  34. }
  35. //otherwise it's not one of the two exceptions expected by the filter method signature - wrap it in one:
  36. String msg = "Filtered request failed.";
  37. throw new ServletException(msg, t);
  38. }
  39. }


  1. protected WebSubject createSubject(ServletRequest request, ServletResponse response) {
  2. return new WebSubject.Builder(getSecurityManager(), request, response).buildWebSubject();
  3. }


Builder()中主要用于初始化SecurityManager 、ServletRequest 、ServletResponse 等对象,构建SubjectContext上下文关系对象

  1. */
  2. public Builder(SecurityManager securityManager, ServletRequest request, ServletResponse response) {
  3. super(securityManager);
  4. if (request == null) {
  5. throw new IllegalArgumentException("ServletRequest argument cannot be null.");
  6. }
  7. if (response == null) {
  8. throw new IllegalArgumentException("ServletResponse argument cannot be null.");
  9. }
  10. setRequest(request);
  11. setResponse(response);
  12. }


  1. public WebSubject buildWebSubject() {
  2. Subject subject = super.buildSubject();//父类build方法
  3. if (!(subject instanceof WebSubject)) {
  4. String msg = "Subject implementation returned from the SecurityManager was not a " +
  5. WebSubject.class.getName() + " implementation. Please ensure a Web-enabled SecurityManager " +
  6. "has been configured and made available to this builder.";
  7. throw new IllegalStateException(msg);
  8. }
  9. return (WebSubject) subject;
  10. }


  1. public Subject buildSubject() {
  2. return this.securityManager.createSubject(this.subjectContext);
  3. }


  1. public Subject createSubject(SubjectContext subjectContext) {
  2. //create a copy so we don't modify the argument's backing map:
  3. SubjectContext context = copy(subjectContext); //复制一个SubjectContext对象
  5. //ensure that the context has a SecurityManager instance, and if not, add one:
  6. context = ensureSecurityManager(context); // 检查并初始化SecurityManager对象
  8. //Resolve an associated Session (usually based on a referenced session ID), and place it in the context before
  9. //sending to the SubjectFactory. The SubjectFactory should not need to know how to acquire sessions as the
  10. //process is often environment specific - better to shield the SF from these details:
  11. context = resolveSession(context);//解析获取Sesssion信息
  13. //Similarly, the SubjectFactory should not require any concept of RememberMe - translate that here first
  14. //if possible before handing off to the SubjectFactory:
  15. context = resolvePrincipals(context);//解析获取resolvePrincipals信息
  17. Subject subject = doCreateSubject(context);//创建Subject
  19. //save this subject for future reference if necessary:
  20. //(this is needed here in case rememberMe principals were resolved and they need to be stored in the
  21. //session, so we don't constantly rehydrate the rememberMe PrincipalCollection on every operation).
  22. //Added in 1.2:
  23. save(subject);
  25. return subject;
  26. }


  1. protected Subject doCreateSubject(SubjectContext context) {
  2. return getSubjectFactory().createSubject(context);
  3. }


  1. public Subject createSubject(SubjectContext context) {
  2. //SHIRO-646
  3. //Check if the existing subject is NOT a WebSubject. If it isn't, then call super.createSubject instead.
  4. //Creating a WebSubject from a non-web Subject will cause the ServletRequest and ServletResponse to be null, which wil fail when creating a session.
  5. boolean isNotBasedOnWebSubject = context.getSubject() != null && !(context.getSubject() instanceof WebSubject);
  6. if (!(context instanceof WebSubjectContext) || isNotBasedOnWebSubject) {
  7. return super.createSubject(context);
  8. }
  9. //获取上下文对象中的信息
  10. WebSubjectContext wsc = (WebSubjectContext) context;
  11. SecurityManager securityManager = wsc.resolveSecurityManager();
  12. Session session = wsc.resolveSession();
  13. boolean sessionEnabled = wsc.isSessionCreationEnabled();
  14. PrincipalCollection principals = wsc.resolvePrincipals();
  15. boolean authenticated = wsc.resolveAuthenticated();
  16. String host = wsc.resolveHost();
  17. ServletRequest request = wsc.resolveServletRequest();
  18. ServletResponse response = wsc.resolveServletResponse();
  20. //构造返回WebDelegatingSubject对象
  21. return new WebDelegatingSubject(principals, authenticated, host, session, sessionEnabled,
  22. request, response, securityManager);
  23. }



Subject对象本质上是与请求所属的线程进行绑定,Shiro底层定义了一个ThreadContext对象,一个基于ThreadLocal的上下文管理容器,里面定义了一个InheritableThreadLocalMap<Map<Object, Object>>(),Subject最后就是被放到这个map当中,我们获取时也是从这个map中获取


  1. //执行Subject绑定
  2. //noinspection unchecked
  3. subject.execute(new Callable() {
  4. public Object call() throws Exception {
  5. updateSessionLastAccessTime(request, response);
  6. executeChain(request, response, chain);
  7. return null;
  8. }
  9. });


  1. public <V> V execute(Callable<V> callable) throws ExecutionException {
  2. Callable<V> associated = associateWith(callable);//初始化一个SubjectCallable对象,并把回调方法传进去
  3. try {
  4. return associated.call();
  5. } catch (Throwable t) {
  6. throw new ExecutionException(t);
  7. }
  8. }
  10. public <V> Callable<V> associateWith(Callable<V> callable) {
  11. return new SubjectCallable<V>(this, callable);
  12. }


  1. public class SubjectCallable<V> implements Callable<V> {
  3. protected final ThreadState threadState;
  4. private final Callable<V> callable;
  6. public SubjectCallable(Subject subject, Callable<V> delegate) {
  7. this(new SubjectThreadState(subject), delegate);//初始化构造方法
  8. }
  10. protected SubjectCallable(ThreadState threadState, Callable<V> delegate) {
  11. if (threadState == null) {
  12. throw new IllegalArgumentException("ThreadState argument cannot be null.");
  13. }
  14. this.threadState = threadState;//SubjectThreadState对象
  15. if (delegate == null) {
  16. throw new IllegalArgumentException("Callable delegate instance cannot be null.");
  17. }
  18. this.callable = delegate;//回调对象
  19. }
  21. public V call() throws Exception {
  22. try {
  23. threadState.bind();//执行绑定操作
  24. return doCall(this.callable);//执行回调操作
  25. } finally {
  26. threadState.restore();
  27. }
  28. }
  30. protected V doCall(Callable<V> target) throws Exception {
  31. return target.call();
  32. }
  33. }


  1. public void bind() {
  2. SecurityManager securityManager = this.securityManager;
  3. if ( securityManager == null ) {
  4. //try just in case the constructor didn't find one at the time:
  5. securityManager = ThreadContext.getSecurityManager();
  6. }
  7. this.originalResources = ThreadContext.getResources();
  8. ThreadContext.remove();//首先执行remove操作
  10. ThreadContext.bind(this.subject);//执行绑定操作
  11. if (securityManager != null) {
  12. ThreadContext.bind(securityManager);
  13. }
  14. }

在上面bind方法中又会执行ThreadContext的bind方法,这里就是之前说到的shiro底层维护了的一个ThreadContext对象,一个基于ThreadLocal的上下文管理容器,bind操作本质上就是把创建的Subject对象维护到resources 这个InheritableThreadLocalMap中, SecurityUtils.getSubject()方法其实就是从InheritableThreadLocalMap中获取所属线程对应的Subject

  1. private static final ThreadLocal<Map<Object, Object>> resources = new InheritableThreadLocalMap<Map<Object, Object>>();//定义一个InheritableThreadLocalMap
  3. public static void bind(Subject subject) {
  4. if (subject != null) {
  5. put(SUBJECT_KEY, subject);//向InheritableThreadLocalMap中放入Subject对象
  6. }
  7. }
  9. public static void put(Object key, Object value) {
  10. if (key == null) {
  11. throw new IllegalArgumentException("key cannot be null");
  12. }
  14. if (value == null) {
  15. remove(key);
  16. return;
  17. }
  19. ensureResourcesInitialized();
  20. resources.get().put(key, value);
  22. if (log.isTraceEnabled()) {
  23. String msg = "Bound value of type [" + value.getClass().getName() + "] for key [" +
  24. key + "] to thread " + "[" + Thread.currentThread().getName() + "]";
  25. log.trace(msg);
  26. }
  27. }




