This commit is contained in:
MaxKey
2022-04-30 19:37:08 +08:00
parent eb748ac827
commit 0f912df258
12 changed files with 153 additions and 53 deletions
@@ -25,14 +25,30 @@ import org.maxkey.authn.SignPrincipal;
import org.springframework.security.core.Authentication;
import org.springframework.security.core.GrantedAuthority;
import com.fasterxml.jackson.annotation.JsonProperty;
public class AuthJwt implements Serializable {
private static final long serialVersionUID = -914373258878811144L;
public static final String ACCESS_TOKEN = "access_token";
public static final String REFRESH_TOKEN = "refresh_token";
public static final String EXPIRES_IN = "expired";
private String ticket;
private String token;
private String refreshToken;
private String type = "Bearer";
private String token;
@JsonProperty(REFRESH_TOKEN)
private String refreshToken;
@JsonProperty(EXPIRES_IN)
private int expiresIn;
private String remeberMe;
private String id;
private String name;
@@ -44,27 +60,36 @@ public class AuthJwt implements Serializable {
private int passwordSetType;
private List<String> authorities;
public AuthJwt(String token, String id, String username, String displayName, String email, String instId,
String instName, List<String> authorities) {
public AuthJwt(String ticket, String type, String token, String refreshToken, int expiresIn, String remeberMe,
String id, String name, String username, String displayName, String email, String instId, String instName,
int passwordSetType, List<String> authorities) {
super();
this.ticket = ticket;
this.type = type;
this.token = token;
this.refreshToken = refreshToken;
this.expiresIn = expiresIn;
this.remeberMe = remeberMe;
this.id = id;
this.name = username;
this.name = name;
this.username = username;
this.displayName = displayName;
this.email = email;
this.instId = instId;
this.instName = instName;
this.passwordSetType = passwordSetType;
this.authorities = authorities;
}
public AuthJwt(String token,String refreshToken, Authentication authentication) {
public AuthJwt(String token, Authentication authentication,int expiresIn,String refreshToken) {
SignPrincipal principal = ((SignPrincipal)authentication.getPrincipal());
this.token = token;
this.expiresIn = expiresIn;
this.refreshToken = refreshToken;
this.ticket = principal.getSession().getId();
this.ticket = principal.getSession().getId();
this.id = principal.getUserInfo().getId();
this.username = principal.getUserInfo().getUsername();
this.name = this.username;
@@ -175,6 +200,16 @@ public class AuthJwt implements Serializable {
public void setRefreshToken(String refreshToken) {
this.refreshToken = refreshToken;
}
public int getExpiresIn() {
return expiresIn;
}
public void setExpiresIn(int expiresIn) {
this.expiresIn = expiresIn;
}
@Override
public String toString() {
@@ -7,6 +7,7 @@ import org.joda.time.DateTime;
import org.maxkey.authn.SignPrincipal;
import org.maxkey.crypto.jwt.HMAC512Service;
import org.maxkey.entity.UserInfo;
import org.maxkey.util.StringUtils;
import org.maxkey.web.WebContext;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
@@ -33,7 +34,7 @@ public class AuthJwtService {
DateTime currentDateTime = DateTime.now();
String subject = principal.getUsername();
Date expirationTime = currentDateTime.plusSeconds(expires).toDate();
_logger.debug("jwt subject : {} , expiration Time : {}" , subject,expirationTime);
_logger.trace("jwt subject : {} , expiration Time : {}" , subject,expirationTime);
JWTClaimsSet jwtClaims =new JWTClaimsSet.Builder()
.issuer(issuer)
@@ -102,12 +103,14 @@ public class AuthJwtService {
*/
public boolean validateJwtToken(String authToken) {
try {
JWTClaimsSet claims = resolve(authToken);
boolean isExpiration = claims.getExpirationTime().after(DateTime.now().toDate());
boolean isVerify = hmac512Service.verify(authToken);
_logger.debug("JWT Verify {} , now {} , ExpirationTime {} , isExpiration : {}" ,
isVerify,DateTime.now().toDate(),claims.getExpirationTime(),isExpiration);
return isVerify && isExpiration;
if(StringUtils.isNotBlank(authToken)) {
JWTClaimsSet claims = resolve(authToken);
boolean isExpiration = claims.getExpirationTime().after(DateTime.now().toDate());
boolean isVerify = hmac512Service.verify(authToken);
_logger.trace("JWT Verify {} , now {} , ExpirationTime {} , isExpiration : {}" ,
isVerify,DateTime.now().toDate(),claims.getExpirationTime(),isExpiration);
return isVerify && isExpiration;
}
} catch (ParseException e) {
_logger.error("authToken {}",authToken);
_logger.error("ParseException ",e);
@@ -66,13 +66,22 @@ public class AuthTokenService extends AuthJwtService{
public AuthJwt genAuthJwt(Authentication authentication) {
if(authentication != null) {
String refreshToken = refreshTokenService.genRefreshToken(authentication);
return new AuthJwt(genJwt(authentication),refreshToken, authentication);
String accessToken = genJwt(authentication);
AuthJwt authJwt = new AuthJwt(
accessToken,
authentication,
authJwkConfig.getExpires(),
refreshToken);
return authJwt;
}
return null;
}
public String genJwt(Authentication authentication) {
return genJwt( authentication,authJwkConfig.getIssuer(),authJwkConfig.getExpires());
return genJwt(
authentication,
authJwkConfig.getIssuer(),
authJwkConfig.getExpires());
}
@@ -100,8 +109,9 @@ public class AuthTokenService extends AuthJwtService{
congress,
new AuthJwt(
genJwt(authentication),
refreshToken,
authentication)
authentication,
authJwkConfig.getExpires(),
refreshToken)
);
return congress;
}
@@ -37,18 +37,23 @@ import org.springframework.security.core.Authentication;
public class AuthorizationUtils {
private static final Logger _logger = LoggerFactory.getLogger(AuthorizationUtils.class);
public static final String Authorization_Cookie = "congress";
public static final class BEARERTYPE{
public static final String CONGRESS = "congress";
public static final String AUTHORIZATION = "Authorization";
}
public static void authenticateWithCookie(
HttpServletRequest request,
AuthTokenService authTokenService,
SessionManager sessionManager
) throws ParseException{
Cookie authCookie = WebContext.getCookie(request, Authorization_Cookie);
Cookie authCookie = WebContext.getCookie(request, BEARERTYPE.CONGRESS);
if(authCookie != null ) {
String authorization = authCookie.getValue();
doJwtAuthenticate(authorization,authTokenService,sessionManager);
_logger.debug("congress automatic authenticated .");
_logger.trace("Try congress authenticate .");
doJwtAuthenticate(BEARERTYPE.CONGRESS,authorization,authTokenService,sessionManager);
}
}
@@ -59,13 +64,14 @@ public class AuthorizationUtils {
) throws ParseException{
String authorization = AuthorizationHeaderUtils.resolveBearer(request);
if(authorization != null ) {
doJwtAuthenticate(authorization,authTokenService,sessionManager);
_logger.debug("Authorization automatic authenticated .");
_logger.trace("Try Authorization authenticate .");
doJwtAuthenticate(BEARERTYPE.AUTHORIZATION,authorization,authTokenService,sessionManager);
}
}
public static void doJwtAuthenticate(
String bearerType,
String authorization,
AuthTokenService authTokenService,
SessionManager sessionManager) throws ParseException {
@@ -75,12 +81,17 @@ public class AuthorizationUtils {
Session session = sessionManager.get(sessionId);
if(session != null) {
setAuthentication(session.getAuthentication());
_logger.debug("{} Automatic authenticated .",bearerType);
}else {
setAuthentication(null);
//time out
_logger.debug("Session timeout .");
clearAuthentication();
}
}
}else {
setAuthentication(null);
//token invalidate
_logger.debug("Token invalidate .");
clearAuthentication();
}
}
@@ -100,6 +111,10 @@ public class AuthorizationUtils {
WebContext.setAttribute(WebConstants.AUTHENTICATION, authentication);
}
public static void clearAuthentication() {
WebContext.removeAttribute(WebConstants.AUTHENTICATION);
}
public static boolean isAuthenticated() {
return getAuthentication() != null;
}
@@ -33,6 +33,7 @@ public class LoginRefreshPoint {
@RequestMapping(value={"/token/refresh"}, produces = {MediaType.APPLICATION_JSON_VALUE})
public ResponseEntity<?> refresh(
@RequestHeader(name = "refresh_token", required = true) String refreshToken) {
_logger.debug("try to refresh token " );
_logger.trace("refresh token {} " , refreshToken);
try {
if(refreshTokenService.validateJwtToken(refreshToken)) {
@@ -47,7 +48,7 @@ public class LoginRefreshPoint {
_logger.debug("Session is timeout , sessionId [{}]" , sessionId);
}
}else {
_logger.trace("refresh token is not validate .");
_logger.debug("refresh token is not validate .");
}
}catch(Exception e) {
_logger.error("Refresh Exception !",e);