CONGRESS
This commit is contained in:
+44
-9
@@ -25,14 +25,30 @@ import org.maxkey.authn.SignPrincipal;
|
||||
import org.springframework.security.core.Authentication;
|
||||
import org.springframework.security.core.GrantedAuthority;
|
||||
|
||||
import com.fasterxml.jackson.annotation.JsonProperty;
|
||||
|
||||
public class AuthJwt implements Serializable {
|
||||
|
||||
private static final long serialVersionUID = -914373258878811144L;
|
||||
|
||||
public static final String ACCESS_TOKEN = "access_token";
|
||||
|
||||
public static final String REFRESH_TOKEN = "refresh_token";
|
||||
|
||||
public static final String EXPIRES_IN = "expired";
|
||||
|
||||
private String ticket;
|
||||
private String token;
|
||||
private String refreshToken;
|
||||
|
||||
private String type = "Bearer";
|
||||
|
||||
private String token;
|
||||
|
||||
@JsonProperty(REFRESH_TOKEN)
|
||||
private String refreshToken;
|
||||
|
||||
@JsonProperty(EXPIRES_IN)
|
||||
private int expiresIn;
|
||||
|
||||
private String remeberMe;
|
||||
private String id;
|
||||
private String name;
|
||||
@@ -44,27 +60,36 @@ public class AuthJwt implements Serializable {
|
||||
private int passwordSetType;
|
||||
private List<String> authorities;
|
||||
|
||||
|
||||
public AuthJwt(String token, String id, String username, String displayName, String email, String instId,
|
||||
String instName, List<String> authorities) {
|
||||
public AuthJwt(String ticket, String type, String token, String refreshToken, int expiresIn, String remeberMe,
|
||||
String id, String name, String username, String displayName, String email, String instId, String instName,
|
||||
int passwordSetType, List<String> authorities) {
|
||||
super();
|
||||
this.ticket = ticket;
|
||||
this.type = type;
|
||||
this.token = token;
|
||||
this.refreshToken = refreshToken;
|
||||
this.expiresIn = expiresIn;
|
||||
this.remeberMe = remeberMe;
|
||||
this.id = id;
|
||||
this.name = username;
|
||||
this.name = name;
|
||||
this.username = username;
|
||||
this.displayName = displayName;
|
||||
this.email = email;
|
||||
this.instId = instId;
|
||||
this.instName = instName;
|
||||
this.passwordSetType = passwordSetType;
|
||||
this.authorities = authorities;
|
||||
}
|
||||
|
||||
public AuthJwt(String token,String refreshToken, Authentication authentication) {
|
||||
|
||||
|
||||
public AuthJwt(String token, Authentication authentication,int expiresIn,String refreshToken) {
|
||||
SignPrincipal principal = ((SignPrincipal)authentication.getPrincipal());
|
||||
|
||||
this.token = token;
|
||||
this.expiresIn = expiresIn;
|
||||
this.refreshToken = refreshToken;
|
||||
this.ticket = principal.getSession().getId();
|
||||
|
||||
this.ticket = principal.getSession().getId();
|
||||
this.id = principal.getUserInfo().getId();
|
||||
this.username = principal.getUserInfo().getUsername();
|
||||
this.name = this.username;
|
||||
@@ -175,6 +200,16 @@ public class AuthJwt implements Serializable {
|
||||
public void setRefreshToken(String refreshToken) {
|
||||
this.refreshToken = refreshToken;
|
||||
}
|
||||
|
||||
public int getExpiresIn() {
|
||||
return expiresIn;
|
||||
}
|
||||
|
||||
|
||||
public void setExpiresIn(int expiresIn) {
|
||||
this.expiresIn = expiresIn;
|
||||
}
|
||||
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
|
||||
+10
-7
@@ -7,6 +7,7 @@ import org.joda.time.DateTime;
|
||||
import org.maxkey.authn.SignPrincipal;
|
||||
import org.maxkey.crypto.jwt.HMAC512Service;
|
||||
import org.maxkey.entity.UserInfo;
|
||||
import org.maxkey.util.StringUtils;
|
||||
import org.maxkey.web.WebContext;
|
||||
import org.slf4j.Logger;
|
||||
import org.slf4j.LoggerFactory;
|
||||
@@ -33,7 +34,7 @@ public class AuthJwtService {
|
||||
DateTime currentDateTime = DateTime.now();
|
||||
String subject = principal.getUsername();
|
||||
Date expirationTime = currentDateTime.plusSeconds(expires).toDate();
|
||||
_logger.debug("jwt subject : {} , expiration Time : {}" , subject,expirationTime);
|
||||
_logger.trace("jwt subject : {} , expiration Time : {}" , subject,expirationTime);
|
||||
|
||||
JWTClaimsSet jwtClaims =new JWTClaimsSet.Builder()
|
||||
.issuer(issuer)
|
||||
@@ -102,12 +103,14 @@ public class AuthJwtService {
|
||||
*/
|
||||
public boolean validateJwtToken(String authToken) {
|
||||
try {
|
||||
JWTClaimsSet claims = resolve(authToken);
|
||||
boolean isExpiration = claims.getExpirationTime().after(DateTime.now().toDate());
|
||||
boolean isVerify = hmac512Service.verify(authToken);
|
||||
_logger.debug("JWT Verify {} , now {} , ExpirationTime {} , isExpiration : {}" ,
|
||||
isVerify,DateTime.now().toDate(),claims.getExpirationTime(),isExpiration);
|
||||
return isVerify && isExpiration;
|
||||
if(StringUtils.isNotBlank(authToken)) {
|
||||
JWTClaimsSet claims = resolve(authToken);
|
||||
boolean isExpiration = claims.getExpirationTime().after(DateTime.now().toDate());
|
||||
boolean isVerify = hmac512Service.verify(authToken);
|
||||
_logger.trace("JWT Verify {} , now {} , ExpirationTime {} , isExpiration : {}" ,
|
||||
isVerify,DateTime.now().toDate(),claims.getExpirationTime(),isExpiration);
|
||||
return isVerify && isExpiration;
|
||||
}
|
||||
} catch (ParseException e) {
|
||||
_logger.error("authToken {}",authToken);
|
||||
_logger.error("ParseException ",e);
|
||||
|
||||
+14
-4
@@ -66,13 +66,22 @@ public class AuthTokenService extends AuthJwtService{
|
||||
public AuthJwt genAuthJwt(Authentication authentication) {
|
||||
if(authentication != null) {
|
||||
String refreshToken = refreshTokenService.genRefreshToken(authentication);
|
||||
return new AuthJwt(genJwt(authentication),refreshToken, authentication);
|
||||
String accessToken = genJwt(authentication);
|
||||
AuthJwt authJwt = new AuthJwt(
|
||||
accessToken,
|
||||
authentication,
|
||||
authJwkConfig.getExpires(),
|
||||
refreshToken);
|
||||
return authJwt;
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
public String genJwt(Authentication authentication) {
|
||||
return genJwt( authentication,authJwkConfig.getIssuer(),authJwkConfig.getExpires());
|
||||
return genJwt(
|
||||
authentication,
|
||||
authJwkConfig.getIssuer(),
|
||||
authJwkConfig.getExpires());
|
||||
}
|
||||
|
||||
|
||||
@@ -100,8 +109,9 @@ public class AuthTokenService extends AuthJwtService{
|
||||
congress,
|
||||
new AuthJwt(
|
||||
genJwt(authentication),
|
||||
refreshToken,
|
||||
authentication)
|
||||
authentication,
|
||||
authJwkConfig.getExpires(),
|
||||
refreshToken)
|
||||
);
|
||||
return congress;
|
||||
}
|
||||
|
||||
+23
-8
@@ -37,18 +37,23 @@ import org.springframework.security.core.Authentication;
|
||||
public class AuthorizationUtils {
|
||||
private static final Logger _logger = LoggerFactory.getLogger(AuthorizationUtils.class);
|
||||
|
||||
public static final String Authorization_Cookie = "congress";
|
||||
public static final class BEARERTYPE{
|
||||
|
||||
public static final String CONGRESS = "congress";
|
||||
|
||||
public static final String AUTHORIZATION = "Authorization";
|
||||
}
|
||||
|
||||
public static void authenticateWithCookie(
|
||||
HttpServletRequest request,
|
||||
AuthTokenService authTokenService,
|
||||
SessionManager sessionManager
|
||||
) throws ParseException{
|
||||
Cookie authCookie = WebContext.getCookie(request, Authorization_Cookie);
|
||||
Cookie authCookie = WebContext.getCookie(request, BEARERTYPE.CONGRESS);
|
||||
if(authCookie != null ) {
|
||||
String authorization = authCookie.getValue();
|
||||
doJwtAuthenticate(authorization,authTokenService,sessionManager);
|
||||
_logger.debug("congress automatic authenticated .");
|
||||
_logger.trace("Try congress authenticate .");
|
||||
doJwtAuthenticate(BEARERTYPE.CONGRESS,authorization,authTokenService,sessionManager);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -59,13 +64,14 @@ public class AuthorizationUtils {
|
||||
) throws ParseException{
|
||||
String authorization = AuthorizationHeaderUtils.resolveBearer(request);
|
||||
if(authorization != null ) {
|
||||
doJwtAuthenticate(authorization,authTokenService,sessionManager);
|
||||
_logger.debug("Authorization automatic authenticated .");
|
||||
_logger.trace("Try Authorization authenticate .");
|
||||
doJwtAuthenticate(BEARERTYPE.AUTHORIZATION,authorization,authTokenService,sessionManager);
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
public static void doJwtAuthenticate(
|
||||
String bearerType,
|
||||
String authorization,
|
||||
AuthTokenService authTokenService,
|
||||
SessionManager sessionManager) throws ParseException {
|
||||
@@ -75,12 +81,17 @@ public class AuthorizationUtils {
|
||||
Session session = sessionManager.get(sessionId);
|
||||
if(session != null) {
|
||||
setAuthentication(session.getAuthentication());
|
||||
_logger.debug("{} Automatic authenticated .",bearerType);
|
||||
}else {
|
||||
setAuthentication(null);
|
||||
//time out
|
||||
_logger.debug("Session timeout .");
|
||||
clearAuthentication();
|
||||
}
|
||||
}
|
||||
}else {
|
||||
setAuthentication(null);
|
||||
//token invalidate
|
||||
_logger.debug("Token invalidate .");
|
||||
clearAuthentication();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -100,6 +111,10 @@ public class AuthorizationUtils {
|
||||
WebContext.setAttribute(WebConstants.AUTHENTICATION, authentication);
|
||||
}
|
||||
|
||||
public static void clearAuthentication() {
|
||||
WebContext.removeAttribute(WebConstants.AUTHENTICATION);
|
||||
}
|
||||
|
||||
public static boolean isAuthenticated() {
|
||||
return getAuthentication() != null;
|
||||
}
|
||||
|
||||
+2
-1
@@ -33,6 +33,7 @@ public class LoginRefreshPoint {
|
||||
@RequestMapping(value={"/token/refresh"}, produces = {MediaType.APPLICATION_JSON_VALUE})
|
||||
public ResponseEntity<?> refresh(
|
||||
@RequestHeader(name = "refresh_token", required = true) String refreshToken) {
|
||||
_logger.debug("try to refresh token " );
|
||||
_logger.trace("refresh token {} " , refreshToken);
|
||||
try {
|
||||
if(refreshTokenService.validateJwtToken(refreshToken)) {
|
||||
@@ -47,7 +48,7 @@ public class LoginRefreshPoint {
|
||||
_logger.debug("Session is timeout , sessionId [{}]" , sessionId);
|
||||
}
|
||||
}else {
|
||||
_logger.trace("refresh token is not validate .");
|
||||
_logger.debug("refresh token is not validate .");
|
||||
}
|
||||
}catch(Exception e) {
|
||||
_logger.error("Refresh Exception !",e);
|
||||
|
||||
Reference in New Issue
Block a user