SecurityConfig.java 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240
  1. package com.zsElectric.boot.config;
  2. import cn.binarywang.wx.miniapp.api.WxMaService;
  3. import cn.hutool.captcha.generator.CodeGenerator;
  4. import cn.hutool.core.util.ArrayUtil;
  5. import com.zsElectric.boot.common.util.electric.queryToken.ThirdPartyJwtAuthFilter;
  6. import com.zsElectric.boot.config.property.SecurityProperties;
  7. import com.zsElectric.boot.core.filter.RateLimiterFilter;
  8. import com.zsElectric.boot.security.filter.CaptchaValidationFilter;
  9. import com.zsElectric.boot.security.filter.TokenAuthenticationFilter;
  10. import com.zsElectric.boot.security.handler.MyAccessDeniedHandler;
  11. import com.zsElectric.boot.security.handler.MyAuthenticationEntryPoint;
  12. import com.zsElectric.boot.security.provider.SmsAuthenticationProvider;
  13. import com.zsElectric.boot.security.provider.WxMiniAppCodeAuthenticationProvider;
  14. import com.zsElectric.boot.security.provider.WxMiniAppPhoneAuthenticationProvider;
  15. import com.zsElectric.boot.security.provider.WxMiniAppPhoneCodeAuthenticationProvider;
  16. import com.zsElectric.boot.security.token.TokenManager;
  17. import com.zsElectric.boot.security.service.SysUserDetailsService;
  18. import com.zsElectric.boot.system.service.ConfigService;
  19. import com.zsElectric.boot.system.service.UserService;
  20. import lombok.RequiredArgsConstructor;
  21. import lombok.extern.slf4j.Slf4j;
  22. import org.springframework.context.annotation.Bean;
  23. import org.springframework.context.annotation.Configuration;
  24. import org.springframework.core.annotation.Order;
  25. import org.springframework.data.redis.core.RedisTemplate;
  26. import org.springframework.security.authentication.AuthenticationManager;
  27. import org.springframework.security.authentication.ProviderManager;
  28. import org.springframework.security.authentication.dao.DaoAuthenticationProvider;
  29. import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity;
  30. import org.springframework.security.config.annotation.web.builders.HttpSecurity;
  31. import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
  32. import org.springframework.security.config.annotation.web.configuration.WebSecurityCustomizer;
  33. import org.springframework.security.config.annotation.web.configurers.AbstractHttpConfigurer;
  34. import org.springframework.security.config.annotation.web.configurers.HeadersConfigurer;
  35. import org.springframework.security.config.http.SessionCreationPolicy;
  36. import org.springframework.security.crypto.password.PasswordEncoder;
  37. import org.springframework.security.web.SecurityFilterChain;
  38. import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter;
  39. /**
  40. * Spring Security 配置类
  41. *
  42. * @author Ray.Hao
  43. * @since 2023/2/17
  44. */
  45. @Slf4j
  46. @Configuration
  47. @EnableWebSecurity
  48. @EnableMethodSecurity
  49. @RequiredArgsConstructor
  50. public class SecurityConfig {
  51. private final RedisTemplate<String, Object> redisTemplate;
  52. private final PasswordEncoder passwordEncoder;
  53. private final TokenManager tokenManager;
  54. private final WxMaService wxMaService;
  55. private final UserService userService;
  56. private final SysUserDetailsService userDetailsService;
  57. private final CodeGenerator codeGenerator;
  58. private final ConfigService configService;
  59. private final SecurityProperties securityProperties;
  60. private final ThirdPartyJwtAuthFilter thirdPartyAuthFilter;
  61. // 注入 UserInfoService 用于小程序认证
  62. private final com.zsElectric.boot.business.service.UserInfoService userInfoService;
  63. // 仅针对第三方URL的安全过滤链,只挂第三方认证过滤器
  64. @Bean
  65. @Order(1)
  66. public SecurityFilterChain thirdPartySecurityFilterChain(HttpSecurity http) throws Exception {
  67. log.info("第三方认证过滤器: {}", thirdPartyAuthFilter);
  68. String[] thirdPartyUrls = securityProperties.getThirdPartyUrls();
  69. if (thirdPartyUrls == null || thirdPartyUrls.length == 0) {
  70. log.warn("第三方URL未配置或为空,使用占位符避免匹配所有请求");
  71. thirdPartyUrls = new String[]{"/__thirdparty_noop__"};
  72. }
  73. log.info("========== 配置第三方 SecurityFilterChain, urls: {} ==========", (Object) thirdPartyUrls);
  74. http
  75. .securityMatcher(thirdPartyUrls) // 只匹配第三方URL
  76. .authorizeHttpRequests(registry -> registry
  77. .anyRequest().authenticated()
  78. )
  79. .exceptionHandling(configurer ->
  80. configurer
  81. .authenticationEntryPoint(new MyAuthenticationEntryPoint())
  82. .accessDeniedHandler(new MyAccessDeniedHandler())
  83. )
  84. .sessionManagement(configurer ->
  85. configurer.sessionCreationPolicy(SessionCreationPolicy.STATELESS)
  86. )
  87. .csrf(AbstractHttpConfigurer::disable)
  88. .formLogin(AbstractHttpConfigurer::disable)
  89. .httpBasic(AbstractHttpConfigurer::disable)
  90. .headers(headers -> headers.frameOptions(HeadersConfigurer.FrameOptionsConfig::disable))
  91. // 只加第三方认证过滤器
  92. .addFilterBefore(thirdPartyAuthFilter, UsernamePasswordAuthenticationFilter.class);
  93. return http.build();
  94. }
  95. /**
  96. * 配置安全过滤链 SecurityFilterChain
  97. */
  98. @Bean
  99. @Order(2)
  100. public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
  101. log.info("========== 配置 SecurityFilterChain ==========");
  102. return http
  103. .authorizeHttpRequests(requestMatcherRegistry -> {
  104. // 配置无需登录即可访问的公开接口
  105. String[] ignoreUrls = securityProperties.getIgnoreUrls();
  106. log.info("安全白名单 ignore-urls: {}", (Object) ignoreUrls);
  107. if (ArrayUtil.isNotEmpty(ignoreUrls)) {
  108. requestMatcherRegistry.requestMatchers(ignoreUrls).permitAll();
  109. }
  110. // 配置完全绕过安全检查的路径(原 unsecuredUrls)
  111. String[] unsecuredUrls = securityProperties.getUnsecuredUrls();
  112. log.info("非安全端点 unsecured-urls: {}", (Object) unsecuredUrls);
  113. if (ArrayUtil.isNotEmpty(unsecuredUrls)) {
  114. requestMatcherRegistry.requestMatchers(unsecuredUrls).permitAll();
  115. }
  116. // 其他所有请求需登录后访问
  117. requestMatcherRegistry.anyRequest().authenticated();
  118. }
  119. )
  120. .exceptionHandling(configurer ->
  121. configurer
  122. .authenticationEntryPoint(new MyAuthenticationEntryPoint()) // 未认证异常处理器
  123. .accessDeniedHandler(new MyAccessDeniedHandler()) // 无权限访问异常处理器
  124. )
  125. // 禁用默认的 Spring Security 特性,适用于前后端分离架构
  126. .sessionManagement(configurer ->
  127. configurer.sessionCreationPolicy(SessionCreationPolicy.STATELESS) // 无状态认证,不使用 Session
  128. )
  129. .csrf(AbstractHttpConfigurer::disable) // 禁用 CSRF 防护,前后端分离无需此防护机制
  130. .formLogin(AbstractHttpConfigurer::disable) // 禁用默认的表单登录功能,前后端分离采用 Token 认证方式
  131. .httpBasic(AbstractHttpConfigurer::disable) // 禁用 HTTP Basic 认证,避免弹窗式登录
  132. // 禁用 X-Frame-Options 响应头,允许页面被嵌套到 iframe 中
  133. .headers(headers -> headers.frameOptions(HeadersConfigurer.FrameOptionsConfig::disable))
  134. // 限流过滤器
  135. .addFilterBefore(new RateLimiterFilter(redisTemplate, configService), UsernamePasswordAuthenticationFilter.class)
  136. // 验证码校验过滤器
  137. .addFilterBefore(new CaptchaValidationFilter(redisTemplate, codeGenerator), UsernamePasswordAuthenticationFilter.class)
  138. // 验证和解析过滤器
  139. .addFilterBefore(new TokenAuthenticationFilter(tokenManager), UsernamePasswordAuthenticationFilter.class)
  140. .build();
  141. }
  142. /**
  143. * 配置Web安全自定义器,以忽略特定请求路径的安全性检查。
  144. * <p>
  145. * 该配置用于指定哪些请求路径不经过Spring Security过滤器链。通常用于静态资源文件。
  146. * 注意:这些警告可以忽略,因为Swagger等静态资源需要完全绕过过滤器链才能正常访问。
  147. */
  148. @Bean
  149. public WebSecurityCustomizer webSecurityCustomizer() {
  150. return (web) -> {
  151. String[] unsecuredUrls = securityProperties.getUnsecuredUrls();
  152. if (ArrayUtil.isNotEmpty(unsecuredUrls)) {
  153. web.ignoring().requestMatchers(unsecuredUrls);
  154. }
  155. };
  156. }
  157. /**
  158. * 默认密码认证的 Provider
  159. */
  160. @Bean
  161. public DaoAuthenticationProvider daoAuthenticationProvider() {
  162. DaoAuthenticationProvider daoAuthenticationProvider = new DaoAuthenticationProvider(userDetailsService);
  163. daoAuthenticationProvider.setPasswordEncoder(passwordEncoder);
  164. return daoAuthenticationProvider;
  165. }
  166. /**
  167. * 微信小程序Code认证Provider
  168. */
  169. @Bean
  170. public WxMiniAppCodeAuthenticationProvider wxMiniAppCodeAuthenticationProvider() {
  171. return new WxMiniAppCodeAuthenticationProvider(userService, wxMaService);
  172. }
  173. /**
  174. * 微信小程序手机号认证Provider
  175. */
  176. @Bean
  177. public WxMiniAppPhoneAuthenticationProvider wxMiniAppPhoneAuthenticationProvider() {
  178. return new WxMiniAppPhoneAuthenticationProvider(userService, wxMaService);
  179. }
  180. /**
  181. * 微信小程序手机号Code认证Provider(新版接口)
  182. * <p>
  183. * 使用 UserInfoService 直接操作 c_user_info 表
  184. */
  185. @Bean
  186. public WxMiniAppPhoneCodeAuthenticationProvider wxMiniAppPhoneCodeAuthenticationProvider() {
  187. return new WxMiniAppPhoneCodeAuthenticationProvider(userInfoService, wxMaService);
  188. }
  189. /**
  190. * 短信验证码认证 Provider
  191. */
  192. @Bean
  193. public SmsAuthenticationProvider smsAuthenticationProvider() {
  194. return new SmsAuthenticationProvider(userService, redisTemplate);
  195. }
  196. /**
  197. * 认证管理器
  198. */
  199. @Bean
  200. public AuthenticationManager authenticationManager(
  201. DaoAuthenticationProvider daoAuthenticationProvider,
  202. WxMiniAppCodeAuthenticationProvider wxMiniAppCodeAuthenticationProvider,
  203. WxMiniAppPhoneAuthenticationProvider wxMiniAppPhoneAuthenticationProvider,
  204. WxMiniAppPhoneCodeAuthenticationProvider wxMiniAppPhoneCodeAuthenticationProvider,
  205. SmsAuthenticationProvider smsAuthenticationProvider
  206. ) {
  207. return new ProviderManager(
  208. daoAuthenticationProvider,
  209. wxMiniAppCodeAuthenticationProvider,
  210. wxMiniAppPhoneAuthenticationProvider,
  211. wxMiniAppPhoneCodeAuthenticationProvider,
  212. smsAuthenticationProvider
  213. );
  214. }
  215. }