| | |
| | | package com.moon.server.interceptor; |
| | | |
| | | import com.alibaba.fastjson.JSON; |
| | | import com.moon.server.entity.all.HttpStatus; |
| | | import com.moon.server.entity.all.ResAuthEntity; |
| | | import com.moon.server.entity.all.ResponseMsg; |
| | | import com.moon.server.entity.all.StaticData; |
| | | import com.moon.server.entity.sys.TokenEntity; |
| | | import com.moon.server.entity.sys.UserEntity; |
| | |
| | | |
| | | private final static int LEN = "/proxy/".length(); |
| | | |
| | | public static final String ILLEGAL_RESOURCE = JSON.toJSONString(new ResponseMsg<String>(HttpStatus.UNAUTHORIZED, "没有资源访问权限")); |
| | | |
| | | @Override |
| | | public void init(FilterConfig filterConfig) { |
| | | } |
| | |
| | | HttpServletRequest req = (HttpServletRequest) request; |
| | | HttpServletResponse res = (HttpServletResponse) response; |
| | | |
| | | // 2.获取令牌 |
| | | String token = getToken(req); |
| | | if (!check(req, res, token)) { |
| | | int resId = getResId(req.getRequestURI(), LEN + token.length() + 1); |
| | | if (!check(req, res, token, resId)) { |
| | | return; |
| | | } |
| | | |
| | | String uri = req.getRequestURI(); |
| | | int resId = getResId(uri, LEN + token.length() + 1); |
| | | |
| | | // |
| | | insertLog(req, res); |
| | | } |
| | | |
| | |
| | | /** |
| | | * 检查 |
| | | */ |
| | | private boolean check(HttpServletRequest req, HttpServletResponse res, String token) { |
| | | private boolean check(HttpServletRequest req, HttpServletResponse res, String token, int resId) { |
| | | // 3.获取用户 |
| | | UserEntity ue = sysService.tokenService.getUserByToken(token); |
| | | if (ue == null) { |
| | |
| | | // 5.检查黑名单 |
| | | if (!checkBlackList(ip, req)) { |
| | | return WebHelper.writeStr2Page(res, AuthInterceptor.BLACK_LIST); |
| | | } |
| | | |
| | | // 9.检查资源权限 |
| | | if (!checkResPerms(ue, resId)) { |
| | | return WebHelper.writeStr2Page(res, ILLEGAL_RESOURCE); |
| | | } |
| | | |
| | | // 6.admin跳过权限检测 |
| | |
| | | return te.getIp().equals(ip); |
| | | } |
| | | |
| | | private boolean checkPerms(UserEntity ue, int resId){ |
| | | /** |
| | | * 检查资源权限 |
| | | */ |
| | | private boolean checkResPerms(UserEntity ue, int resId) { |
| | | String uid = StaticData.ADMIN.equals(ue.getUid()) ? null : ue.getUid(); |
| | | List<ResAuthEntity> rs = permsService.selectRes(uid); |
| | | List<Integer> rs = permsService.selectResList(uid); |
| | | if (null == rs || rs.isEmpty()) { |
| | | return false; |
| | | } |
| | | |
| | | return true; |
| | | return rs.contains(resId); |
| | | } |
| | | |
| | | /** |