From 7ae23e17d8e90dc634f3f86e2eee209cbacaace3 Mon Sep 17 00:00:00 2001 From: xiaoyong931011 <15274802129@163.com> Date: Mon, 30 Nov 2020 17:15:53 +0800 Subject: [PATCH] 20201130 --- src/main/java/com/xcong/excoin/configurations/security/TokenFilter.java | 95 ++++++++++++++++++++++++++++++++++------------- 1 files changed, 69 insertions(+), 26 deletions(-) diff --git a/src/main/java/com/xcong/excoin/configurations/security/TokenFilter.java b/src/main/java/com/xcong/excoin/configurations/security/TokenFilter.java index c15cad7..e98bac2 100644 --- a/src/main/java/com/xcong/excoin/configurations/security/TokenFilter.java +++ b/src/main/java/com/xcong/excoin/configurations/security/TokenFilter.java @@ -4,8 +4,11 @@ import cn.hutool.crypto.asymmetric.KeyType; import cn.hutool.crypto.asymmetric.RSA; import com.alibaba.fastjson.JSONObject; +import com.fasterxml.jackson.databind.ObjectMapper; import com.xcong.excoin.common.LoginUserUtils; import com.xcong.excoin.common.contants.AppContants; +import com.xcong.excoin.common.exception.GlobalException; +import com.xcong.excoin.common.response.Result; import com.xcong.excoin.common.system.bean.LoginUserBean; import com.xcong.excoin.configurations.properties.ApplicationProperties; import com.xcong.excoin.configurations.properties.SecurityProperties; @@ -24,6 +27,7 @@ import javax.servlet.ServletRequest; import javax.servlet.ServletResponse; import javax.servlet.http.HttpServletRequest; +import javax.servlet.http.HttpServletResponse; import java.io.IOException; import java.util.ArrayList; @@ -43,32 +47,72 @@ @Override public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException { HttpServletRequest request = (HttpServletRequest) servletRequest; - String token = resolveToken(request); - log.info("token为-->{}", token); - if (StrUtil.isNotBlank(token)) { - String redisKey = ""; - // 根据user-agent判断pc端还是app端 - if (LoginUserUtils.isBrowser(request)) { - redisKey = AppContants.PC_LOGIN_PREFIX + token; - } else { - redisKey = AppContants.APP_LOGIN_PREFIX + token; - } + HttpServletResponse response = (HttpServletResponse) servletResponse; + String token = resolveTokenOutCenter(request); - String loginStr = (String) redisUtils.get(redisKey); - log.info("当前登陆用户为:{}", loginStr); - if (StrUtil.isNotBlank(loginStr)) { - MemberEntity loginUser = JSONObject.parseObject(loginStr, MemberEntity.class); - Authentication authentication = new UsernamePasswordAuthenticationToken(loginUser, token, new ArrayList<>()); - SecurityContextHolder.getContext().setAuthentication(authentication); - redisUtils.expire(redisKey, 300000); + if (!AppContants.TIME_OUT.equals(token)) { + if (StrUtil.isNotBlank(token)) { + String redisKey = ""; + // 根据user-agent判断pc端还是app端 + if (LoginUserUtils.isBrowser(request)) { + redisKey = token;; + } else { + redisKey = token;; + } + + String loginStr = (String) redisUtils.get(redisKey); + if (StrUtil.isNotBlank(loginStr)) { + MemberEntity loginUser = JSONObject.parseObject(loginStr, MemberEntity.class); + Authentication authentication = new UsernamePasswordAuthenticationToken(loginUser, token, new ArrayList<>()); + SecurityContextHolder.getContext().setAuthentication(authentication); + } else { + log.info("token无法查询:{}", token); + SecurityContextHolder.clearContext(); + } } else { +// log.info("token为空:{}", request.getRequestURI()); SecurityContextHolder.clearContext(); } } else { + response.setHeader("TimeOut", AppContants.TIME_OUT); SecurityContextHolder.clearContext(); } - filterChain.doFilter(servletRequest, servletResponse); + } + + /** + * 解析前端传来的token,md5加密后的地址_设备iD_/api + * + * @param request + * @return + */ + private String resolveTokenOutCenter(HttpServletRequest request) { + try { + String bearerToken = request.getHeader(AppContants.TOKEN_HEADER); + //获取请求的完整路径 + StringBuffer requestURL = request.getRequestURL(); + + if (StringUtils.hasText(bearerToken) && bearerToken.startsWith(AppContants.TOKEN_START_WITH)) { + // 去掉令牌前缀 + String rsaToken = bearerToken.replace(AppContants.TOKEN_START_WITH, ""); + RSA rsa = new RSA(securityProperties.getPrivateKey(), null); + String decryptStr = rsa.decryptStr(rsaToken, KeyType.PrivateKey); + String[] tokens = StrUtil.split(decryptStr, "_"); + + if (StrUtil.isNotEmpty(requestURL) && requestURL.toString().contains(tokens[2])) { + return tokens[0]; + } else { +// log.info("前面token为{}", tokens[0]); +// log.info("时间为:{}, 当前时间为:{}", tokens[1], System.currentTimeMillis()); + return AppContants.TIME_OUT; + } + } +// log.info("bearerToken---->{}", bearerToken); + } catch (Exception e) { + log.error("#解析token异常#", e); + return null; + } + return null; } /** @@ -79,23 +123,22 @@ */ private String resolveToken(HttpServletRequest request) { try { - // TODO debug模式下写死用户 String bearerToken = request.getHeader(AppContants.TOKEN_HEADER); -// if (applicationProperties.isDebug()) { -// bearerToken = "Bearer JSEre1ZUKEu2Ga5ORM+juxXv6yBwmt+FgLhxaeHf1EEJfIb3oRir4pXqe5JDhS6sXfLYOXRIAyBpq+SYBwAtGigxwzGVPn+k4Pt6vNxZ4h8Pk4IeG4+FqbFD0guzvu3WN2eRnnzYqCepl429v9Ju7n4jSG0Hj5ViM3MHQZs3qHo="; -// } else { -// bearerToken = request.getHeader(AppContants.TOKEN_HEADER); -// } if (StringUtils.hasText(bearerToken) && bearerToken.startsWith(AppContants.TOKEN_START_WITH)) { // 去掉令牌前缀 String rsaToken = bearerToken.replace(AppContants.TOKEN_START_WITH, ""); RSA rsa = new RSA(securityProperties.getPrivateKey(), null); String[] tokens = StrUtil.split(rsa.decryptStr(rsaToken, KeyType.PrivateKey), "_"); + if (verifyTokenExpired(Long.parseLong(tokens[1]))) { return tokens[0]; + } else { +// log.info("前面token为{}", tokens[0]); +// log.info("时间为:{}, 当前时间为:{}", tokens[1], System.currentTimeMillis()); + return AppContants.TIME_OUT; } - return null; } +// log.info("bearerToken---->{}", bearerToken); } catch (Exception e) { log.error("#解析token异常#", e); return null; @@ -107,7 +150,7 @@ boolean isDebug = applicationProperties.isDebug(); if (!isDebug) { long currentTime = System.currentTimeMillis(); - return currentTime - time <= 5000; + return currentTime - time <= 30000; } return true; } -- Gitblit v1.9.1