ShiroConfig.java 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186
  1. package com.ygj.yuemum.shiro;
  2. import org.apache.shiro.mgt.SecurityManager;
  3. import org.apache.shiro.session.mgt.SessionManager;
  4. import org.apache.shiro.session.mgt.eis.EnterpriseCacheSessionDAO;
  5. import org.apache.shiro.spring.web.ShiroFilterFactoryBean;
  6. import org.apache.shiro.web.mgt.DefaultWebSecurityManager;
  7. import org.springframework.context.annotation.Bean;
  8. import org.springframework.context.annotation.Configuration;
  9. import java.util.LinkedHashMap;
  10. import java.util.Map;
  11. @Configuration
  12. public class ShiroConfig {
  13. @Bean
  14. public ShiroFilterFactoryBean shirFilter(SecurityManager securityManager) {
  15. ShiroFilterFactoryBean shiroFilterFactoryBean = new ShiroFilterFactoryBean();
  16. // 必须设置 SecurityManager
  17. shiroFilterFactoryBean.setSecurityManager(securityManager);
  18. // setLoginUrl 如果不设置值,默认会自动寻找Web工程根目录下的"/login.jsp"页面 或 "/login" 映射
  19. shiroFilterFactoryBean.setLoginUrl("/webLogin");
  20. // 设置无权限时跳转的 url;
  21. shiroFilterFactoryBean.setUnauthorizedUrl("/unauth");
  22. // 设置拦截器
  23. Map<String, String> filterChainDefinitionMap = new LinkedHashMap<>();
  24. //小程序开放权限
  25. filterChainDefinitionMap.put("/addEquipmenteHireDetail", "anon");
  26. filterChainDefinitionMap.put("/addEquipmenteHireHeadOnline", "anon");
  27. filterChainDefinitionMap.put("/deleteEquipmenteHireHead", "anon");
  28. filterChainDefinitionMap.put("/deleteWXUserDefAddress", "anon");
  29. filterChainDefinitionMap.put("/checkStockDate", "anon");
  30. filterChainDefinitionMap.put("/getBanners", "anon");
  31. filterChainDefinitionMap.put("/getConsultant", "anon");
  32. filterChainDefinitionMap.put("/getCustomerEq", "anon");
  33. filterChainDefinitionMap.put("/getEquipmentTypes", "anon");
  34. filterChainDefinitionMap.put("/getEqUserAddress", "anon");
  35. filterChainDefinitionMap.put("/getIndexs", "anon");
  36. filterChainDefinitionMap.put("/getMktInfos", "anon");
  37. filterChainDefinitionMap.put("/getPackageDetail", "anon");
  38. filterChainDefinitionMap.put("/getPackageLists", "anon");
  39. filterChainDefinitionMap.put("/getPackageShowname", "anon");
  40. filterChainDefinitionMap.put("/getPIClasses", "anon");
  41. filterChainDefinitionMap.put("/getPIGroups", "anon");
  42. filterChainDefinitionMap.put("/getPIServices", "anon");
  43. filterChainDefinitionMap.put("/getPromotions", "anon");
  44. filterChainDefinitionMap.put("/getWXCustomerCoupons", "anon");
  45. filterChainDefinitionMap.put("/getWxDecrypt", "anon");
  46. filterChainDefinitionMap.put("/getWXOpenid", "anon");
  47. filterChainDefinitionMap.put("/getWXUserAddress", "anon");
  48. filterChainDefinitionMap.put("/getYueSuo", "anon");
  49. filterChainDefinitionMap.put("/insertCustomerBooking", "anon");
  50. filterChainDefinitionMap.put("/insertEqCustomerBooking", "anon");
  51. filterChainDefinitionMap.put("/insertWXUserAddress", "anon");
  52. filterChainDefinitionMap.put("/updateWXUser", "anon");
  53. filterChainDefinitionMap.put("/updateWXUserAddress", "anon");
  54. filterChainDefinitionMap.put("/updateWXUserDefAddress", "anon");
  55. filterChainDefinitionMap.put("/WXSendBookingMessage", "anon");
  56. filterChainDefinitionMap.put("/WXSendOrderMessage", "anon");
  57. filterChainDefinitionMap.put("/WXSendYSOrderMessage", "anon");
  58. filterChainDefinitionMap.put("/getEquipmentAmount", "anon");
  59. filterChainDefinitionMap.put("/getValidPO", "anon");
  60. filterChainDefinitionMap.put("/getValidPosition", "anon");
  61. filterChainDefinitionMap.put("/getWxPosition", "anon");
  62. filterChainDefinitionMap.put("/insertPromotionUserInfo", "anon");
  63. filterChainDefinitionMap.put("/checkDcIntroducers", "anon");
  64. filterChainDefinitionMap.put("/getDcIntroduceLogs", "anon");
  65. filterChainDefinitionMap.put("/getDcIntroducerExtracts", "anon");
  66. filterChainDefinitionMap.put("/date_DcIntroducerExtracts", "anon");
  67. filterChainDefinitionMap.put("/getAccountNumber", "anon");
  68. filterChainDefinitionMap.put("/queryOneDcIntroducerExtract", "anon");
  69. filterChainDefinitionMap.put("/insertDcIntroducerExtract", "anon");
  70. filterChainDefinitionMap.put("/WXSendExtractMessage", "anon");
  71. filterChainDefinitionMap.put("/insertDcIntroduceLog", "anon");
  72. filterChainDefinitionMap.put("/getDcIntroducerConsultants", "anon");
  73. filterChainDefinitionMap.put("/queryMineOrder", "anon");
  74. filterChainDefinitionMap.put("/getYSOrder", "anon");
  75. filterChainDefinitionMap.put("/insertYsOrderPay", "anon");
  76. filterChainDefinitionMap.put("/checkCustomerPay", "anon");
  77. filterChainDefinitionMap.put("/queryYSOrderReturn", "anon");
  78. filterChainDefinitionMap.put("/updateEquipmenteHireHeadOnline", "anon");
  79. filterChainDefinitionMap.put("/getIndexPromotions", "anon");
  80. filterChainDefinitionMap.put("/CreatePOP", "anon");
  81. filterChainDefinitionMap.put("/getPromotionDC", "anon");
  82. filterChainDefinitionMap.put("/checkMkt", "anon");
  83. filterChainDefinitionMap.put("/getBranches", "anon");
  84. filterChainDefinitionMap.put("/insertPromotionDCUserInfo", "anon");
  85. filterChainDefinitionMap.put("/updateDcIntroducerApplicant", "anon");
  86. filterChainDefinitionMap.put("/updateAccountNumber", "anon");
  87. filterChainDefinitionMap.put("/insertPromotionChannelLog", "anon");
  88. filterChainDefinitionMap.put("/getPromotionTestByPrxID", "anon");
  89. filterChainDefinitionMap.put("/getPromotionTestResultByPtID", "anon");
  90. filterChainDefinitionMap.put("/insertPromotionTestUserScore", "anon");
  91. filterChainDefinitionMap.put("/CreateTestShare", "anon");
  92. filterChainDefinitionMap.put("/getPromotionDCByID", "anon");
  93. filterChainDefinitionMap.put("/getPromotionTestUserScoreByOpenID", "anon");
  94. filterChainDefinitionMap.put("/getPromotionTestResultShowByPrxID", "anon");
  95. filterChainDefinitionMap.put("/getWXDianPing", "anon");
  96. filterChainDefinitionMap.put("/getWXContentTypes", "anon");
  97. filterChainDefinitionMap.put("/queryUserContent", "anon");
  98. filterChainDefinitionMap.put("/getWXUser", "anon");
  99. filterChainDefinitionMap.put("/getWXMMSearchQuestion", "anon");
  100. filterChainDefinitionMap.put("/queryUserMMSearch", "anon");
  101. filterChainDefinitionMap.put("/getMmInfoResume", "anon");
  102. filterChainDefinitionMap.put("/getPackageImagesByID", "anon");
  103. //萌动开放权限
  104. filterChainDefinitionMap.put("/getNewUserCoupon", "anon");
  105. filterChainDefinitionMap.put("/getConsultTaskCoupon", "anon");
  106. filterChainDefinitionMap.put("/getDetectionTaskCoupon", "anon");
  107. filterChainDefinitionMap.put("/getRechargeTaskCoupon", "anon");
  108. //文件上传临时解决方案
  109. filterChainDefinitionMap.put("/uploadPromotionImg","anon");
  110. filterChainDefinitionMap.put("/uploadImg","anon");
  111. filterChainDefinitionMap.put("/uploadPayImg","anon");
  112. filterChainDefinitionMap.put("/uploadMiniImg","anon");
  113. filterChainDefinitionMap.put("/uploadDianPingImg","anon");
  114. //简历分享问题
  115. filterChainDefinitionMap.put("/getWeChatInfo","anon");
  116. //超人妈妈学院
  117. filterChainDefinitionMap.put("/college/queryUserPoints","anon");
  118. filterChainDefinitionMap.put("/college/queryUserLearningCore","anon");
  119. filterChainDefinitionMap.put("/college/queryUserLearningPractice","anon");
  120. filterChainDefinitionMap.put("/college/queryUserLearningExperience","anon");
  121. filterChainDefinitionMap.put("/college/queryUserLearningCoreDetail","anon");
  122. filterChainDefinitionMap.put("/college/queryCoreDetail","anon");
  123. filterChainDefinitionMap.put("/college/queryTests","anon");
  124. filterChainDefinitionMap.put("/college/addTestDetail","anon");
  125. filterChainDefinitionMap.put("/college/queryPracticeDetail","anon");
  126. filterChainDefinitionMap.put("/college/queryExperienceDetail","anon");
  127. filterChainDefinitionMap.put("/college/addCollegeBooking","anon");
  128. filterChainDefinitionMap.put("/college/corePositive","anon");
  129. filterChainDefinitionMap.put("/college/coreLearningUpdate","anon");
  130. filterChainDefinitionMap.put("/college/coreLearningFinish","anon");
  131. filterChainDefinitionMap.put("/college/getCollegeBooking","anon");
  132. filterChainDefinitionMap.put("/college/bookingCancel","anon");
  133. filterChainDefinitionMap.put("/eLearning/index","anon");
  134. filterChainDefinitionMap.put("/eLearning/courseworkList","anon");
  135. filterChainDefinitionMap.put("/eLearning/courseworkDetail","anon");
  136. filterChainDefinitionMap.put("/eLearning/testList","anon");
  137. filterChainDefinitionMap.put("/eLearning/testComplete","anon");
  138. filterChainDefinitionMap.put("/eLearning/courseworkComplete","anon");
  139. filterChainDefinitionMap.put("/eLearning/courseworkUpdate","anon");
  140. // //用户,需要角色权限 “user”
  141. // filterChainDefinitionMap.put("/user/**", "roles[user]");
  142. // //管理员,需要角色权限 “admin”
  143. // filterChainDefinitionMap.put("/admin/**", "roles[admin]");
  144. //开放登陆接口
  145. filterChainDefinitionMap.put("/login", "anon");
  146. //其余接口一律拦截
  147. //主要这行代码必须放在所有权限设置的最后,不然会导致所有 url 都被拦截
  148. filterChainDefinitionMap.put("/**", "authc");
  149. shiroFilterFactoryBean.setFilterChainDefinitionMap(filterChainDefinitionMap);
  150. return shiroFilterFactoryBean;
  151. }
  152. /**
  153. * 自定义身份认证 realm;
  154. * <p>
  155. * 必须写这个类,并加上 @Bean 注解,目的是注入 CustomRealm,
  156. * 否则会影响 CustomRealm类 中其他类的依赖注入
  157. */
  158. @Bean
  159. public CustomRealm customRealm() {
  160. return new CustomRealm();
  161. }
  162. @Bean
  163. public SessionManager sessionManager(){
  164. ShiroSessionManager shiroSessionManager = new ShiroSessionManager();
  165. //这里可以不设置。Shiro有默认的session管理。如果缓存为Redis则需改用Redis的管理
  166. shiroSessionManager.setSessionDAO(new EnterpriseCacheSessionDAO());
  167. return shiroSessionManager;
  168. }
  169. @Bean
  170. public SecurityManager securityManager(){
  171. DefaultWebSecurityManager securityManager = new DefaultWebSecurityManager();
  172. securityManager.setRealm(customRealm());
  173. //自定义session管理
  174. securityManager.setSessionManager(sessionManager());
  175. //自定义缓存实现
  176. // securityManager.setCacheManager(ehCacheManager());
  177. return securityManager;
  178. }
  179. }