Skip to content

Commit 2a4b7d3

Browse files
Merge pull request #83 from geekidea/dev
Dev
2 parents 9f43ae1 + 32a0a55 commit 2a4b7d3

File tree

5 files changed

+83
-15
lines changed

5 files changed

+83
-15
lines changed
Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
/*
2+
* Copyright 2019-2029 geekidea(https://github.com/geekidea)
3+
*
4+
* Licensed under the Apache License, Version 2.0 (the "License");
5+
* you may not use this file except in compliance with the License.
6+
* You may obtain a copy of the License at
7+
*
8+
* http://www.apache.org/licenses/LICENSE-2.0
9+
*
10+
* Unless required by applicable law or agreed to in writing, software
11+
* distributed under the License is distributed on an "AS IS" BASIS,
12+
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13+
* See the License for the specific language governing permissions and
14+
* limitations under the License.
15+
*/
16+
17+
package io.geekidea.springbootplus.example;
18+
19+
import io.geekidea.springbootplus.common.api.ApiResult;
20+
import io.swagger.annotations.Api;
21+
import io.swagger.annotations.ApiOperation;
22+
import lombok.extern.slf4j.Slf4j;
23+
import org.apache.shiro.authz.annotation.RequiresRoles;
24+
import org.springframework.web.bind.annotation.RequestMapping;
25+
import org.springframework.web.bind.annotation.RequestMethod;
26+
import org.springframework.web.bind.annotation.RestController;
27+
28+
import javax.servlet.http.HttpServletResponse;
29+
import java.io.IOException;
30+
31+
/**
32+
* Shiro Example Controller
33+
*
34+
* @author geekidea
35+
* @date 2019-10-21
36+
**/
37+
@Slf4j
38+
@Api("Shiro Example")
39+
@RestController
40+
@RequestMapping("/shiroExample")
41+
public class ShiroExampleController {
42+
43+
@RequiresRoles("admin")
44+
@RequestMapping(value = "/hello", method = {RequestMethod.GET, RequestMethod.POST})
45+
@ApiOperation(value = "Shiro Example", notes = "Shiro Example", response = String.class)
46+
public ApiResult print(HttpServletResponse response) throws IOException {
47+
log.debug("Shiro Example...");
48+
return ApiResult.ok("Shiro Example");
49+
}
50+
51+
}

src/main/java/io/geekidea/springbootplus/shiro/cache/LoginRedisService.java

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -34,9 +34,17 @@ public interface LoginRedisService {
3434
*
3535
* @param jwtToken
3636
* @param loginSysUserVo
37-
* @param generate true:生成,false:刷新
3837
*/
39-
void cacheLoginInfo(JwtToken jwtToken, LoginSysUserVo loginSysUserVo, boolean generate);
38+
void cacheLoginInfo(JwtToken jwtToken, LoginSysUserVo loginSysUserVo);
39+
40+
41+
/**
42+
* 刷新登陆信息
43+
* @param oldToken
44+
* @param username
45+
* @param newJwtToken
46+
*/
47+
void refreshLoginInfo(String oldToken,String username,JwtToken newJwtToken);
4048

4149
/**
4250
* 通过用户名,从缓存中获取登陆用户LoginSysUserRedisVo

src/main/java/io/geekidea/springbootplus/shiro/cache/impl/LoginRedisServiceImpl.java

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -64,7 +64,7 @@ public class LoginRedisServiceImpl implements LoginRedisService {
6464
* username:num
6565
*/
6666
@Override
67-
public void cacheLoginInfo(JwtToken jwtToken, LoginSysUserVo loginSysUserVo, boolean generate) {
67+
public void cacheLoginInfo(JwtToken jwtToken, LoginSysUserVo loginSysUserVo) {
6868
if (jwtToken == null) {
6969
throw new IllegalArgumentException("jwtToken不能为空");
7070
}
@@ -112,6 +112,15 @@ public void cacheLoginInfo(JwtToken jwtToken, LoginSysUserVo loginSysUserVo, boo
112112
redisTemplate.opsForValue().set(String.format(CommonRedisKey.LOGIN_USER_TOKEN, username, tokenMd5), loginTokenRedisKey, expireDuration);
113113
}
114114

115+
@Override
116+
public void refreshLoginInfo(String oldToken, String username, JwtToken newJwtToken) {
117+
// 删除之前的token信息
118+
deleteLoginInfo(oldToken, username);
119+
// 缓存登陆信息
120+
LoginSysUserRedisVo loginSysUserRedisVo = getLoginSysUserRedisVo(username);
121+
cacheLoginInfo(newJwtToken, loginSysUserRedisVo);
122+
}
123+
115124
@Override
116125
public LoginSysUserRedisVo getLoginSysUserRedisVo(String username) {
117126
if (StringUtils.isBlank(username)) {
@@ -185,4 +194,5 @@ public void deleteUserAllCache(String username) {
185194
redisTemplate.delete(String.format(CommonRedisKey.LOGIN_SALT, username));
186195
}
187196

197+
188198
}

src/main/java/io/geekidea/springbootplus/shiro/jwt/JwtRealm.java

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -61,9 +61,9 @@ public boolean supports(AuthenticationToken token) {
6161
protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principalCollection) {
6262
log.debug("doGetAuthorizationInfo principalCollection...");
6363
// 设置角色/权限信息
64-
String token = principalCollection.toString();
64+
JwtToken jwtToken = (JwtToken) principalCollection.getPrimaryPrincipal();
6565
// 获取username
66-
String username = JwtUtil.getUsername(token);
66+
String username = jwtToken.getUsername();
6767
// 获取登陆用户角色权限信息
6868
LoginSysUserRedisVo loginSysUserRedisVo = loginRedisService.getLoginSysUserRedisVo(username);
6969
SimpleAuthorizationInfo authorizationInfo = new SimpleAuthorizationInfo();

src/main/java/io/geekidea/springbootplus/shiro/service/impl/LoginServiceImpl.java

Lines changed: 9 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -119,7 +119,7 @@ public ApiResult login(LoginParam loginParam, HttpServletResponse response) {
119119
subject.login(jwtToken);
120120

121121
// 缓存登陆信息到Redis
122-
loginRedisService.cacheLoginInfo(jwtToken, loginSysUserVo, true);
122+
loginRedisService.cacheLoginInfo(jwtToken, loginSysUserVo);
123123
// 设置响应头
124124
response.setHeader(JwtTokenUtil.getTokenName(), token);
125125
log.debug("登陆成功,username:{}", username);
@@ -160,16 +160,15 @@ public void refreshToken(JwtToken jwtToken, HttpServletResponse httpServletRespo
160160
throw new AuthenticationException("token已无效,请使用已刷新的token");
161161
}
162162
String username = jwtToken.getUsername();
163-
// 生成新token
164-
String newToken = JwtUtil.generateToken(username, jwtToken.getSalt(), Duration.ofSeconds(jwtProperties.getExpireSecond()));
165-
DecodedJWT decodedJWT = JwtUtil.getJwtInfo(token);
166-
jwtToken.setToken(newToken)
167-
.setCreateDate(decodedJWT.getIssuedAt())
168-
.setExpireDate(decodedJWT.getExpiresAt());
163+
String salt = jwtToken.getSalt();
164+
Long expireSecond = jwtProperties.getExpireSecond();
165+
// 生成新token字符串
166+
String newToken = JwtUtil.generateToken(username, salt, Duration.ofSeconds(expireSecond));
167+
// 生成新JwtToken对象
168+
JwtToken newJwtToken = JwtToken.build(newToken, username, salt, expireSecond);
169169
// 更新redis缓存
170-
LoginSysUserRedisVo loginSysUserRedisVo = loginRedisService.getLoginSysUserRedisVo(username);
171-
loginRedisService.cacheLoginInfo(jwtToken, loginSysUserRedisVo, false);
172-
log.debug("刷新token成功,原token:{},新token:{}", jwtToken.getToken(), newToken);
170+
loginRedisService.refreshLoginInfo(token, username, newJwtToken);
171+
log.debug("刷新token成功,原token:{},新token:{}", token, newToken);
173172
// 设置响应头
174173
// 刷新token
175174
httpServletResponse.setStatus(CommonConstant.JWT_REFRESH_TOKEN_CODE);

0 commit comments

Comments
 (0)