美文网首页
Spring Boot + Security-02基于数据库认证

Spring Boot + Security-02基于数据库认证

作者: 听城 | 来源:发表于2020-02-15 19:10 被阅读0次

上文中已经大致说明了基于内存的Security认证方式,但是绝大多数情况下,我们的项目是基于数据库的,那如何基于数据库进行认证呢?

创建数据库

数据库文件已经上传到Github,地址

创建对应用户实体类

用户类继承自Security的UserDetails

public class User implements UserDetails {
    private Integer id;
    private String username;
    private String password;
    private Boolean enabled;
    private Boolean locked;
    private List<Role> roles;

    public Integer getId() {
        return id;
    }

    public void setId(Integer id) {
        this.id = id;
    }

    @Override
    public String getUsername() {
        return username;
    }

    @Override
    public boolean isAccountNonExpired() {
        //账户是否未过期
        return true;
    }

    @Override
    public boolean isAccountNonLocked() {
        //账户是否未没有锁定
        return !locked;
    }

    @Override
    public boolean isCredentialsNonExpired() {
        //密码是否未过期
        return true;
    }

    @Override
    public boolean isEnabled() {
        //是否可用
        return enabled;
    }

    public void setUsername(String username) {
        this.username = username;
    }

    @Override
    public Collection<? extends GrantedAuthority> getAuthorities() {
        List<SimpleGrantedAuthority> authorities = new ArrayList<>();
        for(Role role:roles){
            authorities.add(new SimpleGrantedAuthority("ROLE_"+role.getName()));
        }
        return authorities;
    }

    @Override
    public String getPassword() {
        return password;
    }

    public void setPassword(String password) {
        this.password = password;
    }


    public void setEnabled(Boolean enabled) {
        this.enabled = enabled;
    }

    public void setLocked(Boolean locked) {
        this.locked = locked;
    }

    public List<Role> getRoles() {
        return roles;
    }

    public void setRoles(List<Role> roles) {
        this.roles = roles;
    }


}

创建用户service

public class UserService implements UserDetailsService {
    @Autowired
    UserMapper userMapper;
    @Override
    public UserDetails loadUserByUsername(String username) throws UsernameNotFoundException {
        User user = userMapper.loadUserByUsername(username);
        if (user == null) {
            throw new UsernameNotFoundException("账户不存在!");
        }
        user.setRoles(userMapper.getUserRolesByUid(user.getId()));
        return user;
    }
}

更改SecurityConfig配置

将上一节基于内存的配置交由UserService去处理

    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
//        auth.inMemoryAuthentication().withUser("admin").password("$2a$10$2cPRItUHyE1GSZnrYWHiQevpbxn4ikWgOa1PYL5miWvqK8GFVCWb6").roles("admin")
//        .and().withUser("java").password("$2a$10$rygGQylvmoAFmPcKQP6xvepNVAw9Bxp0sbAphxKQwhAV79Au0ECvq").roles("user");
        auth.userDetailsService(userService);
    }

相关文章

网友评论

      本文标题:Spring Boot + Security-02基于数据库认证

      本文链接:https://www.haomeiwen.com/subject/sboefhtx.html