Version: Next

Spring Security 详解

需求

image-20200722104326355

  • 日志管理和用户管理只有管理员才有权限查看
  • 普通用户只能访问业务1和业务2

环境

  • SpringBoot 2.0
  • 集成Mybatis、lombok

Controller

@Controller
public class BizpageController {
@PostMapping("/login")
public String login(String username, String password) {
return "index";
}
@GetMapping("/index")
public String index() {
return "index";
}
@GetMapping("/syslog")
public String syslog() {
return "syslog";
}
@GetMapping("/sysuser")
public String sysuser() {
return "sysuser";
}
@GetMapping("/biz1")
public String biz1() {
return "biz1";
}
@GetMapping("/biz2")
public String biz2() {
return "biz2";
}
}

页面

  • /public/login.html
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>登录</title>
</head>
<body>
<form action="/index">
<span>用户名:<input type="text" name="username"/></span>
<span>密码:<input type="password" name="password"/></span>
<input type="submit" value="登录">
</form>
</body>
</html>
  • /template/syslog.html
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>系统日志</title>
</head>
<body>
<h1>系统日志</h1>
</body>
</html>
  • /template/sysuser.html
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>用户管理</title>
</head>
<body>
<h1>用户管理</h1>
</body>
</html>
  • /template/index.html
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>首页</title>
</head>
<body>
<h1>首页</h1>
<a href="/syslog">系统日志</a>
<a href="/sysuser">用户管理</a>
<a href="/biz1">业务1</a>
<a href="/biz2">业务2</a>
</body>
</html>
  • /template/biz1.html
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>业务1</title>
</head>
<body>
<h1>业务1</h1>
</body>
</html>
  • /template/biz2.html
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>业务2</title>
</head>
<body>
<h1>业务2</h1>
</body>
</html>

pom.xml

<dependencies>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-web</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-freemarker</artifactId>
</dependency>
<dependency>
<groupId>com.alibaba</groupId>
<artifactId>druid</artifactId>
<version>1.1.21</version>
</dependency>
<dependency>
<groupId>mysql</groupId>
<artifactId>mysql-connector-java</artifactId>
<version>5.1.47</version>
<scope>runtime</scope>
</dependency>
<dependency>
<groupId>org.mybatis.spring.boot</groupId>
<artifactId>mybatis-spring-boot-starter</artifactId>
<version>2.1.1</version>
</dependency>
<dependency>
<groupId>org.projectlombok</groupId>
<artifactId>lombok</artifactId>
<version>1.18.8</version>
<scope>provided</scope>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-security</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-test</artifactId>
<scope>test</scope>
<exclusions>
<exclusion>
<groupId>org.junit.vintage</groupId>
<artifactId>junit-vintage-engine</artifactId>
</exclusion>
</exclusions>
</dependency>
</dependencies>

application.yaml

spring:
freemarker:
cache: false # 缓存配置 开发阶段应该配置为false 因为经常会改
suffix: .html # 模版后缀名 默认为ftl / 还是用ftl吧,html没freemarker语法提示
charset: UTF-8 # 文件编码
template-loader-path: classpath:/templates/
datasource:
username: root
password: root
#?serverTimezone=UTC解决时区的报错
url: jdbc:mysql://localhost:3306/oauth?serverTimezone=UTC&useUnicode=true&characterEncoding=utf-8
driver-class-name: com.mysql.jdbc.Driver
type: com.alibaba.druid.pool.DruidDataSource # 配置使用Druid数据源
#Spring Boot 默认是不注入这些属性值的,需要自己绑定
#druid 数据源专有配置
initialSize: 5
minIdle: 5
maxActive: 20
maxWait: 60000
timeBetweenEvictionRunsMillis: 60000
minEvictableIdleTimeMillis: 300000
validationQuery: SELECT 1 FROM DUAL
testWhileIdle: true
testOnBorrow: false
testOnReturn: false
poolPreparedStatements: true
#配置监控统计拦截的filters,stat:监控统计、log4j:日志记录、wall:防御sql注入
#如果允许时报错 java.lang.ClassNotFoundException: org.apache.log4j.Priority
#则导入 log4j 依赖即可,Maven 地址:ttps://mvnrepository.com/artifact/log4j/log4j
filters: stat,wall,log4j
maxPoolPreparedStatementPerConnectionSize: 20
useGlobalDataSourceStat: true
connectionProperties: druid.stat.mergeSql=true;druid.stat.slowSqlMillis=500
# 配置Mybatis
# 也可以不配置,使用全限定类名,然后在resources路径下建立和mapper接口一样的包路径
mybatis:
# type-aliases-package: com.bsx.shiro.pojo # 别名
mapper-locations: classpath:mapper/*.xml # 扫描mapper.xml文件路径