当前位置: 首页>后端>正文

Shiro - Shiro与Spring整合

  • jar包导入
    shiro-spring.jar

  • web.xml配制

<filter>
    <filter-name>ShiroFilter</filter-name>
    <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
    <init-param>
        <param-name>targetFilterLifecycle</param-name>
        <param-value>true</param-value>
    </init-param>
</filter>
    
<filter-mapping>
    <filter-name>ShiroFilter</filter-name>
    <url-pattern>/*</url-pattern>
</filter-mapping>

注意:DelegatingFilterProxy实际上是一个Filter的代理对象, 默认情况下, Spring会到IOC容器里 找和filter-name对应的bean,可以通过修改targetBeanName属性的值 来修改filter bean在 Spring IOC里的id

  • spring配制文件配制
<aop:aspectj-autoproxy/>
    
 <!-- 配制shiro核心组件  -->
 <!-- 配制SecurityManager
    cacheManager:缓存管理器  
 -->
 <bean id="securityManager" class="org.apache.shiro.web.mgt.DefaultWebSecurityManager"
        p:cacheManager-ref="cacheManager"
        p:sessionMode="native"
        p:realm-ref="jdbcRealm"
        />
    
 <!-- 配制缓存管理器 -->
 <bean id="cacheManager" class="org.apache.shiro.cache.ehcache.EhCacheManager" 
    p:cacheManagerConfigFile="classpath:ehcache-failsafe.xml"
    />
 
 <!-- 配制Realm -->
 <bean id="jdbcRealm" class="ml.cathome.shiro.ShiroRealm"/>
    
 <!-- 配制Spring管理Shiro生命周期的组件
    可以自定义来调用配置在Spring IOC容器中的 bean的生命周期
  -->
 <bean id="lifecycleBeanPostProcessor" class="org.apache.shiro.spring.LifecycleBeanPostProcessor"/>
    
 <!-- 在IOC container 的 bean中使用Shiro注解, 必须先配制LifecycleBeanPostProcessor后才能使用 -->
 <bean class="org.springframework.aop.framework.autoproxy.DefaultAdvisorAutoProxyCreator"
        depends-on="lifecycleBeanPostProcessor"/>
        
 <bean class="org.apache.shiro.spring.security.interceptor.AuthorizationAttributeSourceAdvisor"
        p:securityManager-ref="securityManager"/>
        
 <!-- 配制Shiro过滤器
    注意:id必须与web.xml文件中配置的DelegationFilterProxy的filter-name一致
    否则会抛出NoSuchBeanDefinitionExeption。因为web.xml里配制的DelegationFilterProxy
    会在Spring IOC容器中找id为filter-name的值对应的bean对象。
  -->
 <bean id="ShiroFilter" class="org.apache.shiro.spring.web.ShiroFilterFactoryBean"
    p:securityManager-ref="securityManager" p:loginUrl="/login.jsp"
    p:successUrl="/ok.jsp" p:unauthorizedUrl="/unauthorized.jsp">
        
    <!-- 
        配置哪些页面需要受保护
        以及访问页面时需要的权限
        1.anon可以被匿名访问
        2.authc必须谁后才能访问
     -->
    <property name="filterChainDefinitions">
        <value>
            /login.jsp = anon
            /ok.jsp = authc
        </value>
    </property>
 </bean>
  • 其它配制文件
    在类路径下需导入ehcache配制文件与shiro.ini配制文件。默认配制如下
    ehcache-failsafe.xml
<?xml version="1.0" encoding="UTF-8"?>
<ehcache> 
  <diskStore path="java.io.tmpdir"/> 
  <defaultCache 
     maxEntriesLocalHeap="10000" 
     eternal="false" 
     timeToIdleSeconds="120" 
     timeToLiveSeconds="120" 
     maxEntriesLocalDisk="10000000" 
     diskExpiryThreadIntervalSeconds="120" 
     memoryStoreEvictionPolicy="LRU"> 
     <persistence strategy="localTempSwap"/> 
  </defaultCache> 
</ehcache>

shiro.ini

# =============================================================================
# Tutorial INI configuration
#
# Usernames/passwords are based on the classic Mel Brooks' film "Spaceballs" :)
# =============================================================================

# -----------------------------------------------------------------------------
# Users and their (optional) assigned roles
# username = password, role1, role2, ..., roleN
# -----------------------------------------------------------------------------
[users]
root = secret, admin
guest = guest, guest
presidentskroob = 12345, president
darkhelmet = ludicrousspeed, darklord, schwartz
lonestarr = vespa, goodguy, schwartz

# -----------------------------------------------------------------------------
# Roles with assigned permissions
# roleName = perm1, perm2, ..., permN
# -----------------------------------------------------------------------------
[roles]
admin = *
schwartz = lightsaber:*
goodguy = winnebago:drive:eagle5

https://www.xamrdz.com/backend/3qm1941378.html

相关文章: