天天看点

第9章 保护Web应用--Spring Security 之 HelloWord

概述:

Web安全保驾护航,涉及面很广,从前端到数据库都有,先简单用一下Spring Security Demo 来感受一下功能

1、开发环境:

JDK 1.8

maven 3.5

eclipse Neon

2、工程结构:

第9章 保护Web应用--Spring Security 之 HelloWord

3、web.xml

<?xml version="1.0" encoding="UTF-8"?>
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://java.sun.com/xml/ns/javaee" xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_3_0.xsd" version="3.0">
  <display-name>spring-security-helloworld</display-name>
  <servlet>
  	<servlet-name>mvc-dispatcher</servlet-name>
  	<servlet-class>org.springframework.web.servlet.DispatcherServlet</servlet-class>
  	<load-on-startup>1</load-on-startup>
  	
  </servlet>
  <servlet-mapping>
  	<servlet-name>mvc-dispatcher</servlet-name>
  	<url-pattern>/</url-pattern>
  	
  </servlet-mapping>
  <listener>
  	<listener-class>org.springframework.web.context.ContextLoaderListener</listener-class>
  </listener>
  <context-param>
  	<param-name>contextConfigLocation</param-name>
  	<param-value>classpath:spring-security.xml</param-value>
  </context-param>
  <filter>
  	<filter-name>springSecurityFilterChain</filter-name>
  	<filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
  </filter>
  <filter-mapping>
  	<filter-name>springSecurityFilterChain</filter-name>
  	<url-pattern>/*</url-pattern>
  </filter-mapping>
  
</web-app>
           

总结:

1、在没有显示引入Springmvc.xml 配置文件,默认是WEB-INF/{servlet-name}-servlet.xml  例如上面自动寻找 WEB-INF/mvc-dispatcher-servlet.xml,当然也可以显示指定

2、配置spring-security.xml 安全策略相关的

3、配置一个过滤器代理,通过代理去关联具体的过滤器

4、pom.xml

<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
  <modelVersion>4.0.0</modelVersion>
  <groupId>com.jack</groupId>
  <artifactId>spring-security-helloworld</artifactId>
  <version>0.0.1-SNAPSHOT</version>
  <name>spring-security-helloworld</name>

	<licenses>
		<license>
			<name>The Apache Software License, Version 2.0</name>
			<url>http://www.apache.org/licenses/LICENSE-2.0.txt</url>
			<distribution>repo</distribution>
		</license>
	</licenses>
	<properties>
		<jdk.version>1.8</jdk.version>
		<spring.version>4.3.8.RELEASE</spring.version>
		<spring.security.version>3.2.3.RELEASE</spring.security.version>
		<jstl.version>1.2</jstl.version>
	</properties>

	<dependencies>

		<!-- Spring 3 dependencies -->
		<dependency>
			<groupId>org.springframework</groupId>
			<artifactId>spring-core</artifactId>
			<version>${spring.version}</version>
		</dependency>

		<dependency>
			<groupId>org.springframework</groupId>
			<artifactId>spring-web</artifactId>
			<version>${spring.version}</version>
		</dependency>

		<dependency>
			<groupId>org.springframework</groupId>
			<artifactId>spring-webmvc</artifactId>
			<version>${spring.version}</version>
		</dependency>

		<!-- Spring Security -->
		<dependency>
			<groupId>org.springframework.security</groupId>
			<artifactId>spring-security-web</artifactId>
			<version>${spring.security.version}</version>
		</dependency>

		<dependency>
			<groupId>org.springframework.security</groupId>
			<artifactId>spring-security-config</artifactId>
			<version>${spring.security.version}</version>
		</dependency>

		<!-- jstl for jsp page -->
		<dependency>
			<groupId>jstl</groupId>
			<artifactId>jstl</artifactId>
			<version>${jstl.version}</version>
		</dependency>

	</dependencies>

	<build>
		<finalName>SpringSecurityHelloWorld</finalName>
		<plugins>

			<plugin>
				<groupId>org.apache.maven.plugins</groupId>
				<artifactId>maven-compiler-plugin</artifactId>
				<version>2.3.2</version>
				<configuration>
					<source>${jdk.version}</source>
					<target>${jdk.version}</target>
				</configuration>
			</plugin>

			<plugin>
				<groupId>org.apache.maven.plugins</groupId>
				<artifactId>maven-eclipse-plugin</artifactId>
				<version>2.9</version>
				<configuration>
					<downloadSources>true</downloadSources>
					<downloadJavadocs>false</downloadJavadocs>
					<wtpversion>2.0</wtpversion>
				</configuration>
			</plugin>

		</plugins>
	</build>
	
</project>
           

总结:

1、这里引入Spring Security 的jar包有

<dependency>

<groupId>org.springframework.security</groupId>

<artifactId>spring-security-web</artifactId>

<version>${spring.security.version}</version>

</dependency>

<dependency>

<groupId>org.springframework.security</groupId>

<artifactId>spring-security-config</artifactId>

<version>${spring.security.version}</version>

</dependency>

5、mvc-dispatcher-servlet.xml

<beans xmlns="http://www.springframework.org/schema/beans"
	xmlns:context="http://www.springframework.org/schema/context"
	xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
	xsi:schemaLocation="
        http://www.springframework.org/schema/beans     
        http://www.springframework.org/schema/beans/spring-beans-3.0.xsd
        http://www.springframework.org/schema/context 
        http://www.springframework.org/schema/context/spring-context-3.0.xsd">
        
   <context:component-scan base-package="com.jack.*"/>     
   
   <bean class="org.springframework.web.servlet.view.InternalResourceViewResolver">
   	<property name="prefix">
   		<value>/WEB-INF/pages/</value>
   	</property>
   	<property name="suffix">
   		<value>.jsp</value>
   	</property>
   </bean>

</beans>
           

6、spring-security.xml 主要配置文件

<beans:beans xmlns="http://www.springframework.org/schema/security"

xmlns:beans="http://www.springframework.org/schema/beans" 

xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:schemaLocation="http://www.springframework.org/schema/beans

http://www.springframework.org/schema/beans/spring-beans-3.0.xsd

http://www.springframework.org/schema/security

http://www.springframework.org/schema/security/spring-security-3.2.xsd">

<http auto-config="true">

<intercept-url pattern="/admin**" access="ROLE_USER"/>

</http>

<authentication-manager>

<authentication-provider>

<user-service>

<user name="jack" password="123456" authorities="ROLE_USER"/>

</user-service>

</authentication-provider>

</authentication-manager>

</beans:beans>

总结:

1、<http>表示拦截http请求, auto-config="true" 表示自动处理请求出现各种情况,例如输错了提示信息

2、<intercept-url > 表示拦截具体url地址 pattern就是正则表达式, access 表示通过角色

3、<authentication-manager>表示验证经理,<authentication-provider>提供通行票

4、<user-service>表示用户登录功能,弹出输入框, authorities 跟 access 值一样

7、HelloController.java 

package com.jack.controller;

import org.springframework.stereotype.Controller;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RequestMethod;
import org.springframework.web.servlet.ModelAndView;

@Controller
public class HelloController {
	
	@RequestMapping(value={"/","/welcome**"}, method=RequestMethod.GET)
	public ModelAndView welcomePage(){
		
		ModelAndView model = new ModelAndView();
		model.addObject("title", "Spring Security Hello World");
		model.addObject("message", "This is welcom page!");
		model.setViewName("hello");
		return model;
	}
	
	@RequestMapping(value ="/admin**", method= RequestMethod.GET)
	public ModelAndView adminPage(){
		ModelAndView model = new ModelAndView();
		model.addObject("title", "SpringSecurity Hello World");
		model.addObject("message", "This is protected page!");
		model.setViewName("admin");
		
		return model;
	}
	
}
           

总结:

1、一般情况返回一个字符串对应jsp,这里可以返回一个视图,model可以带数据,model也可以设置视图名称

2、addObject() 可以直接在jsp通过 ${title} 形式获取数据

8、jsp

hello.jsp

<%@page session="false"%>
<html>
<body>
	<h1>Title : ${title}</h1>	
	<h1>Message : ${message}</h1>	
</body>
</html>
           

admin.jsp

<%@ taglib prefix="c" uri="http://java.sun.com/jsp/jstl/core" %>
<%@ page session="true" %>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Insert title here</title>
</head>
<body>
	<h1>Title: ${title }</h1>
	<h1>Message: ${message }</h1>
	<c:if test="${pageContext.request.userPrincipal.name !=null }">
		 <h2>Welcome : ${pageContext.request.userPrincipal.name}
           | <a href="<c:url value=" target="_blank" rel="external nofollow" /j_spring_security_logout" />" > Logout</a></h2>
	</c:if>
</body>
</html>
           

总结:

1、这里有一个if 判断, pageContext.request.userPrincipal.name 表示作用域为页面Request请求userPrincipal.name 表示通过安全检查姓名

2、Logout注销的意思,/j_spring_security_logout 这句话就是去掉pageContext.request.userPrincipal.name 的值为空,下次需要输入用户名和密码进入

9、效果:

欢迎页

第9章 保护Web应用--Spring Security 之 HelloWord

admin.jsp

第9章 保护Web应用--Spring Security 之 HelloWord

输入错误密码

第9章 保护Web应用--Spring Security 之 HelloWord

输入正确密码

第9章 保护Web应用--Spring Security 之 HelloWord

总结:

本质上AOP切面功能,执行请求进行拦截处理,包括这里输入框界面

参考地址:https://www.mkyong.com/spring-security/spring-security-hello-world-example/