Shiro中自定义登陆失败,成功操作以及处理重复登陆操作
处理登陆成功和登陆失败后的操作
首先找到,处理表单提交的类
复写其中默认的处理登陆成功,失败后的方法
正常如果登陆失败会进入到controller中 进行登陆后的后续操作,我们可以直接重写shiro的拦截器重新定义拦截器的操作~
public class ExtendFormAuthenticationFiler extends FormAuthenticationFilter { //登陆成功做什么操作,返回true则放行,false则不继续执行后续过滤器,后续过滤器完成一些其他操作 @Override protected boolean onLoginSuccess(AuthenticationToken token, Subject subject, ServletRequest request, ServletResponse response) throws Exception { return super.onLoginSuccess(token, subject, request, response); } //登陆失败做什么操作,返回true则放行,false则不继续执行后续过滤器,后续过滤器完成一些其他操作 @Override protected boolean onLoginFailure(AuthenticationToken token, AuthenticationException e, ServletRequest request, ServletResponse response) { return super.onLoginFailure(token, e, request, response); } }
登陆成功返回怎样的json?失败返回怎样的json都可以在这里进行
处理不能重复登陆问题
不能重复登陆是因为,
public boolean onPreHandle(ServletRequest request, ServletResponse response, Object mappedValue) throws Exception {
//这里已经登陆就返回true后续就不进行登陆操作了~而默认的后方的过滤器会直接跳回login.do 后方的操作是重新执行登陆操作 return isAccessAllowed(request, response, mappedValue) || onAccessDenied(request, response, mappedValue); }
在新建的类中执行复写操作
@Override public boolean onPreHandle(ServletRequest request, ServletResponse response, Object mappedValue) throws Exception { //判断用户是否登陆 如果登陆则注销 让父类重新进行登陆操作 //这个方法主要时进行登陆操作 if (this.isLoginRequest(request, response)) { //如果当前用户已经登陆则注销 然后让用户进行操作 Subject subject = SecurityUtils.getSubject(); //如果用户已经登陆则注销用户登陆 if (subject.isAuthenticated()) { subject.logout(); } }
//这里是执行父类的方法,继续登陆操作 return super.onPreHandle(request, response, mappedValue);
为了让自定义的拦截器生效,需要在xml中声明使用新的拦截器 就是我们自己自定义的拦截器
附上完整源码
<?xml version="1.0" encoding="UTF-8"?> <beans xmlns="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:p="http://www.springframework.org/schema/p" xmlns:context="http://www.springframework.org/schema/context" xmlns:aop="http://www.springframework.org/schema/aop" xmlns:jee="http://www.springframework.org/schema/jee" xmlns:tx="http://www.springframework.org/schema/tx" xmlns:mvc="http://www.springframework.org/schema/mvc" xsi:schemaLocation=" http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd http://www.springframework.org/schema/context http://www.springframework.org/schema/context/spring-context.xsd http://www.springframework.org/schema/jee http://www.springframework.org/schema/jee/spring-jee.xsd http://www.springframework.org/schema/aop http://www.springframework.org/schema/aop/spring-aop.xsd http://www.springframework.org/schema/mvc http://www.springframework.org/schema/mvc/spring-mvc.xsd http://www.springframework.org/schema/tx http://www.springframework.org/schema/tx/spring-tx.xsd"> <!--凭证匹配器--> <bean id="credentialsMatcher" class="org.apache.shiro.authc.credential.HashedCredentialsMatcher"> <property name="hashAlgorithmName" value="md5" /> <property name="hashIterations" value="2" /> </bean> <bean id="myRealm" class="cn.wolfcode.crm.realm.MyRealm"> <property name="credentialsMatcher" ref="credentialsMatcher"/> </bean> <!-- 缓存管理器 --> <bean id="cacheManager" class="org.apache.shiro.cache.ehcache.EhCacheManager"> <property name="cacheManagerConfigFile" value="classpath:shiro-ehcache.xml"></property> </bean> <!-- 配置安全管理器SecurityManager --> <bean id="securityManager" class="org.apache.shiro.web.mgt.DefaultWebSecurityManager"> <property name="realm" ref="myRealm"/> <property name="cacheManager" ref="cacheManager"/> </bean> <!--自定义过滤器--> <bean id="authenticationFilter" class="cn.wolfcode.crm.web.filter.ExtendFormAuthenticationFilter" /> <!--shiro过滤器--> <bean id="shiroFilter" class="org.apache.shiro.spring.web.ShiroFilterFactoryBean"> <property name="securityManager" ref="securityManager"/> <!--登录的表单地址--> <property name="loginUrl" value="/login.do"/> <!--url权限设置--> <property name="filterChainDefinitions"> <value> /static/**=anon /login.jsp=anon /favicon.ico=anon /logout.do=logout /**=authc </value> </property> <!--重新指定过滤器--> <property name="filters"> <map> <entry key="authc" value-ref="authenticationFilter" /> </map> </property> </bean> <!--对注解式的权限控制的配置--> <!-- 开启aop,对类代理 使用cglib的方式来进行代理 --> <aop:config proxy-target-class="true"></aop:config> <!-- 开启shiro注解支持 --> <bean class="org.apache.shiro.spring.security.interceptor.AuthorizationAttributeSourceAdvisor"> <property name="securityManager" ref="securityManager" /> </bean> </beans>
浙公网安备 33010602011771号