首页
学习
活动
专区
圈层
工具
发布
社区首页 >专栏 >SpringBoot-08 SpringSecurity

SpringBoot-08 SpringSecurity

作者头像
张小驰出没
发布2021-04-15 15:59:26
发布2021-04-15 15:59:26
5620
举报

SpringBoot-08 SpringSecurity

创建了一个新项目,创建时选择导入starter-web

1.环境搭建

1.1 导入thymeleaf

代码语言:javascript
复制
<dependency>
    <groupId>org.springframework.bootgroupId>
    <artifactId>spring-boot-starter-thymeleafartifactId>
dependency>

1.2 导入静态资源

  • cssjs这样的静态资源导入到static文件夹下
  • 前端页面导入到templates文件夹下

如果需要静态资源,可以私信我或者发邮件 moyu_zc@163.com

1.3 关闭thymeleaf缓存

代码语言:javascript
复制
spring.thymeleaf.cache=false

1.4 测试运行

2.用户认证和授权

2.1 导入依赖

代码语言:javascript
复制
<dependency>
    <groupId>org.springframework.bootgroupId>
    <artifactId>spring-boot-starter-securityartifactId>
dependency>

2.2 创建Config

创建一个config文件夹:

代码语言:javascript
复制
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.authorizeRequests()
                .antMatchers("/").permitAll()                //对于主页面都可以登录
                .antMatchers("/level1/**").hasRole("vip1")   //对于level1文件夹下的页面需要vip1才能登录
                .antMatchers("/level2/**").hasRole("vip2")   //对于level2文件夹下的页面需要vip2才能登录
                .antMatchers("/level3/**").hasRole("vip3");  //对于level3文件夹下的页面需要vip3才能登录
        //如果没有权限,进入登录页面,这是Security内部自带的
        http.formLogin();
    }
}

2.3 认证

就是给予下面这些用户相应的权限。

代码语言:javascript
复制
//认证
@Override
protected void configure(AuthenticationManagerBuilder auth) throws Exception {
    auth.inMemoryAuthentication().passwordEncoder(new BCryptPasswordEncoder())
        .withUser("zc").password(new BCryptPasswordEncoder().encode("123456")).roles("vip1","vip2")
        .and()
        .withUser("root").password(new BCryptPasswordEncoder().encode("123456")).roles("vip1","vip2","vip3")
        .and()
        .withUser("test").password(new BCryptPasswordEncoder().encode("123456")).roles("vip3");
}

大家可以自行测试。

3.注销及权限控制

3.1 注销

1.开启注销功能

代码语言:javascript
复制
@Override
protected void configure(HttpSecurity http) throws Exception {
    http.authorizeRequests()
        .antMatchers("/").permitAll()                //对于主页面都可以登录
        .antMatchers("/level1/**").hasRole("vip1")   //对于level1文件夹下的页面需要vip1才能登录
        .antMatchers("/level2/**").hasRole("vip2")   //对于level2文件夹下的页面需要vip2才能登录
        .antMatchers("/level3/**").hasRole("vip3");  //对于level3文件夹下的页面需要vip3才能登录
    //如果没有权限,进入登录页面,这是Security内部自带的
    http.formLogin();

    //注销功能
    http.logout().logoutSuccessUrl("/");
}

2.添加注销按钮

代码语言:javascript
复制
<div class="right menu">
    
    <a class="item" th:href="@{/toLogin}">
        <i class="address card icon">i> 登录
    a>
    <a class="item" th:href="@{/logout}">
        <i class="address card icon">i> 注销
    a>
div>

3.2 权限控制

springboot 2.1.x版本以上不兼容这个标签,最好使用2.0.7及其以下的

1.加入thymeleaf、springsecurity整合依赖

代码语言:javascript
复制
<dependency>
    <groupId>org.thymeleaf.extrasgroupId>
    <artifactId>thymeleaf-extras-springsecurity4artifactId>
    <version>3.0.2.RELEASEversion>
dependency>

2.增加对应的头部文件

代码语言:javascript
复制
xmlns:th="http://www.thymeleaf.org" 
xmlns:sec="http://www.thymeleaf.org/thymeleaf-extras-springsecurity4">

3.修改前端页面

代码语言:javascript
复制
<div class="right menu">
    
    <div sec:authorize="!isAuthenticated()">
        <a class="item" th:href="@{/toLogin}">
            <i class="address card icon">i> 登录
        a>
    div>
    <div sec:authorize="isAuthenticated()">
        <a class="item" >
            用户名:<span sec:authentication="name">span>
        a>
        <a class="item" th:href="@{/logout}">
            <i class="address card icon">i> 注销
        a>
    div>
div>   

4.首页定制

4.1 登录页面

1.修改Config

代码语言:javascript
复制
http.formLogin().loginPage("/toLogin");

2.修改login页面的路径

代码语言:javascript
复制
<form th:action="@{/toLogin}" method="post">

如果想要自定义action,可以使用: http.formLogin().loginPage("/toLogin").loginProcessingUrl("xxx");

如果前端form表单中的name与后端不一一对应,可以使用: http.formLogin().loginPage("/toLogin").usernameParameter("xxx").passwordParameter("xxx");

4.2 记住我

1.前端添加记住我选框

代码语言:javascript
复制
<div class="field">
    <input type="checkbox" name="remember">
div>

2.修改Config

代码语言:javascript
复制
http.rememberMe().rememberMeParameter("remember");

个人博客为: MoYu’s HomePage MoYu’s Gitee Blog

本文参与 腾讯云自媒体同步曝光计划,分享自作者个人站点/博客。
原始发表:2021/03/29 ,如有侵权请联系 cloudcommunity@tencent.com 删除
目录
  • SpringBoot-08 SpringSecurity
    • 1.环境搭建
      • 1.1 导入thymeleaf
      • 1.2 导入静态资源
      • 1.3 关闭thymeleaf缓存
      • 1.4 测试运行
    • 2.用户认证和授权
      • 2.1 导入依赖
      • 2.2 创建Config
      • 2.3 认证
    • 3.注销及权限控制
      • 3.1 注销
      • 3.2 权限控制
    • 4.首页定制
      • 4.1 登录页面
      • 4.2 记住我
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档