您的位置:首页 > 大数据 > 人工智能

acegi security实践教程—定制userDetailsService

2014-03-18 08:58 513 查看
  前面我们都是使用默认的UserDetailsService,无论是使用InMemoryDaoImpl还是JdbcDaoImpl这种形式。那这篇文章给大家讲解如何自定义userDetailsService,正如咱们前面写过自己的logoutFilter类。

  源码讲解

  UserDetailsService是个对用户信息操作的接口,其中只有一个方法UserDetails loadUserByUsername(String username),若自定义userDetailsService则需要实现acegi中的userDetailsService接口,实现此方法即可。
package org.acegisecurity.userdetails;
import org.springframework.dao.DataAccessException;
public abstract interface UserDetailsService
{
public abstract UserDetails loadUserByUsername(String paramString)
throws UsernameNotFoundException, DataAccessException;
}


  另外,此方法返回的UserDetails也是接口,acegi中实现其接口的类是User,所以若自定义返回结果,也须实现acegi中的UserDetails接口。
package org.acegisecurity.userdetails;
import java.io.Serializable;
import org.acegisecurity.GrantedAuthority;
public abstract interface UserDetails extends Serializable
{
public abstract GrantedAuthority[] getAuthorities();
public abstract String getPassword();
public abstract String getUsername();
public abstract boolean isAccountNonExpired();
public abstract boolean isAccountNonLocked();
public abstract boolean isCredentialsNonExpired();
public abstract boolean isEnabled();
}


  开发步骤:

  开发环境:

MyEclispe10.7.1+tomcat6.0.37+acegi1.0.5+spring2.0+oracle10g+dbcp数据源

  项目目录如下:  

  其中readme主要用来记录本次验证目的



  代码关键:

  jdbcTemplate.queryForList返回的map类型的List,其中map的key值默认是数据库列名。
  实现UserDetail中的GrantedAuthority[] authorities 是个接口形式,主要存放权限信息。获取的list对象转化成数组对象如下:
for(int i=0;i<dbAuths.size();i++){
String auth=(String)dbAuths.get(i).get("AUTHS");
GrantedAuthorityImpl authority = new GrantedAuthorityImpl(auth);
listAuth.add(authority);
}
GrantedAuthority[] arrayAuths = (GrantedAuthority[]) listAuth.toArray(new GrantedAuthority[listAuth.size()]);


  另外注意:实现UserDetail类中方法,默认为false,根据实际情况而定,若不做处理,可以设置为true。
public boolean isAccountNonExpired() {
// TODO Auto-generated method stub
return true;
}
@Override
public boolean isAccountNonLocked() {
// TODO Auto-generated method stub
return true;
}
@Override
public boolean isCredentialsNonExpired() {
// TODO Auto-generated method stub
return true;
}
@Override
public boolean isEnabled() {
// TODO Auto-generated method stub
if("1".equals(enabled)){
return true;
}else{
return false;
}
}


  定制类:

package com.extend;

import java.util.ArrayList;
import java.util.List;
import java.util.Map;

import org.acegisecurity.GrantedAuthority;
import org.acegisecurity.GrantedAuthorityImpl;
import org.acegisecurity.userdetails.User;
import org.acegisecurity.userdetails.UserDetails;
import org.acegisecurity.userdetails.UserDetailsService;
import org.acegisecurity.userdetails.UsernameNotFoundException;
import org.springframework.dao.DataAccessException;
import org.springframework.jdbc.core.JdbcTemplate;

public class MyUserDetailService implements UserDetailsService {

private JdbcTemplate jdbcTemplate;
@Override
public UserDetails loadUserByUsername(String username)
throws UsernameNotFoundException, DataAccessException {
//根据用户名查询用户基本信息
String baseSql="select * from test_user t where t.user_name=?";
List<Map> list=this.jdbcTemplate.queryForList(baseSql,new Object[]{username});
if(list.size()==0){
throw new UsernameNotFoundException("User not Found");
}
Map pMap=(Map)list.get(0);
MyUser myUser=new MyUser();
myUser.setUsername((String)pMap.get("USER_NAME"));
myUser.setPassword((String)pMap.get("PWD"));
myUser.setEnabled((String)pMap.get("ENABLED"));
//根据用户名查询用户权限信息
String authSql="select AUTHS from test_auths t where t.user_name=?";
List<Map> dbAuths=this.jdbcTemplate.queryForList(authSql,new Object[]{username});
if(dbAuths.size()==0){
throw new UsernameNotFoundException("User has no GrantAuthority");
}
List listAuth=new ArrayList();
for(int i=0;i<dbAuths.size();i++){ String auth=(String)dbAuths.get(i).get("AUTHS"); GrantedAuthorityImpl authority = new GrantedAuthorityImpl(auth); listAuth.add(authority); } GrantedAuthority[] arrayAuths = (GrantedAuthority[]) listAuth.toArray(new GrantedAuthority[listAuth.size()]);
myUser.setAuthorities(arrayAuths);
return myUser;
}
public JdbcTemplate getJdbcTemplate() {
return jdbcTemplate;
}
public void setJdbcTemplate(JdbcTemplate jdbcTemplate) {
this.jdbcTemplate = jdbcTemplate;
}

}
package com.extend;

import java.util.ArrayList;
import java.util.List;
import java.util.Map;

import org.acegisecurity.GrantedAuthority;
import org.acegisecurity.GrantedAuthorityImpl;
import org.acegisecurity.userdetails.User;
import org.acegisecurity.userdetails.UserDetails;
import org.acegisecurity.userdetails.UserDetailsService;
import org.acegisecurity.userdetails.UsernameNotFoundException;
import org.springframework.dao.DataAccessException;
import org.springframework.jdbc.core.JdbcTemplate;

public class MyUserDetailService implements UserDetailsService {

private JdbcTemplate jdbcTemplate;
@Override
public UserDetails loadUserByUsername(String username)
throws UsernameNotFoundException, DataAccessException {
//根据用户名查询用户基本信息
String baseSql="select * from test_user t where t.user_name=?";
List<Map> list=this.jdbcTemplate.queryForList(baseSql,new Object[]{username});
if(list.size()==0){
throw new UsernameNotFoundException("User not Found");
}
Map pMap=(Map)list.get(0);
MyUser myUser=new MyUser();
myUser.setUsername((String)pMap.get("USER_NAME"));
myUser.setPassword((String)pMap.get("PWD"));
myUser.setEnabled((String)pMap.get("ENABLED"));
//根据用户名查询用户权限信息
String authSql="select AUTHS from test_auths t where t.user_name=?";
List<Map> dbAuths=this.jdbcTemplate.queryForList(authSql,new Object[]{username});
if(dbAuths.size()==0){
throw new UsernameNotFoundException("User has no GrantAuthority");
}
List listAuth=new ArrayList();
for(int i=0;i<dbAuths.size();i++){ String auth=(String)dbAuths.get(i).get("AUTHS"); GrantedAuthorityImpl authority = new GrantedAuthorityImpl(auth); listAuth.add(authority); } GrantedAuthority[] arrayAuths = (GrantedAuthority[]) listAuth.toArray(new GrantedAuthority[listAuth.size()]);
myUser.setAuthorities(arrayAuths);
return myUser;
}
public JdbcTemplate getJdbcTemplate() {
return jdbcTemplate;
}
public void setJdbcTemplate(JdbcTemplate jdbcTemplate) {
this.jdbcTemplate = jdbcTemplate;
}

}

  acegi配置文件:

>    <!-- 从数据库中读取用户信息验证身份 -->
<bean id="daoAuthenticationProvider"
class="org.acegisecurity.providers.dao.DaoAuthenticationProvider">
<property name="userDetailsService" ref="userDetailsService" />
</bean>

<!-- 把用户信息、权限信息放到数据库中-->
<bean id="userDetailsService"
class="com.extend.MyUserDetailService">
<property name="jdbcTemplate" ref="JdbcTemplate"> </property>
</bean>
<bean id="JdbcTemplate" class="org.springframework.jdbc.core.JdbcTemplate">
<property name="dataSource" ref="dataSource"></property>
</bean>
<!-- 数据源的绑定 -->
<bean id="dataSource" class="org.apache.commons.dbcp.BasicDataSource"
destroy-method="close">
<property name="driverClassName" value="oracle.jdbc.driver.OracleDriver" />
<property name="url" value="jdbc:oracle:thin:@127.0.0.1:1521:orclnew" />
<property name="username" value="drp"/>
<property name="password" value="drp" />
</bean>

  debug流程:













  上述带领大家进入debug调试,是为了通过分析源码进一步了解acegi的调用流程。

 项目下载:

 
  
   
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签:  acegi