【问题标题】:Control Multiple session for Same User控制同一用户的多个会话
【发布时间】:2020-04-02 04:52:12
【问题描述】:

试图实现并发会话控制,使之前登录的会话无效并注销该会话并让用户在另一个浏览器上登录,这样单个用户就不会同时有多个登录。我在 Web 安全配置中使用了以下 HTTP 配置。但它不起作用。

UaaWebSecurityconfiguration.java

 @Autowired
    public   SessionRegistry sessionRegistry;

    @Bean
    public SessionRegistry sessionRegistry() {
        if (sessionRegistry == null) {
            sessionRegistry = new SessionRegistryImpl();
        }
        return sessionRegistry;
    }

@Override
    public void configure(HttpSecurity http) throws Exception {
        // @formatter:off
        http
            .csrf()
            .disable()
            .addFilterBefore(corsFilter, CsrfFilter.class).exceptionHandling()
            .authenticationEntryPoint(problemSupport).accessDeniedHandler(problemSupport)
            .and()
            .rememberMe()
            .key(jHipsterProperties.getSecurity().getRememberMe()
                .getKey()).and().headers()
            .frameOptions().disable()
            .and()
            .sessionManagement()
            .maximumSessions(1)
            .maxSessionsPreventsLogin(true)
            .sessionRegistry(sessionRegistry)
            .and()
            .sessionFixation()
            .changeSessionId()
            .sessionAuthenticationStrategy(compositeSessionAuthenticationStrategy())
            .and()
            .authorizeRequests().antMatchers("/api/register")
            .permitAll().antMatchers("/api/activate").permitAll().antMatchers("/api/authenticate")
            .permitAll().antMatchers("/api/account/reset-password/init").permitAll()
            .antMatchers("/api/account/reset-password/finish").permitAll()
            .antMatchers("/api/profile-info").permitAll().antMatchers("/api/**").authenticated()
            .antMatchers("/websocket/tracker").hasAuthority(AuthoritiesConstants.ADMIN)
            .antMatchers("/websocket/**").permitAll().antMatchers("/management/health").permitAll()
            .antMatchers("/management/**").hasAuthority(AuthoritiesConstants.ADMIN)
            .antMatchers("/v2/api-docs/**").permitAll()
            .antMatchers("/swagger-resources/configuration/ui").permitAll()
            .antMatchers("/swagger-ui/index.html").hasAuthority(AuthoritiesConstants.ADMIN);
    }

    @Bean
    public ConcurrentSessionControlAuthenticationStrategy concurrentSessionControlAuthenticationStrategy() {
        ConcurrentSessionControlAuthenticationStrategy strategy = new ConcurrentSessionControlAuthenticationStrategy(sessionRegistry());
        strategy.setMaximumSessions(1);
        return strategy;
    }

    @Bean

    public SessionFixationProtectionStrategy sessionFixationProtectionStrategy(){
        return new SessionFixationProtectionStrategy();
    }

    @Bean

    public RegisterSessionAuthenticationStrategy registerSessionAuthenticationStrategy(){
        RegisterSessionAuthenticationStrategy registerSessionAuthenticationStrategy = new RegisterSessionAuthenticationStrategy(sessionRegistry());
        return registerSessionAuthenticationStrategy;
    }


    @Bean
    public CompositeSessionAuthenticationStrategy compositeSessionAuthenticationStrategy(){
        List<SessionAuthenticationStrategy> sessionAuthenticationStrategies = new ArrayList<>();
        sessionAuthenticationStrategies.add(concurrentSessionControlAuthenticationStrategy());
        sessionAuthenticationStrategies.add(sessionFixationProtectionStrategy());
        sessionAuthenticationStrategies.add(registerSessionAuthenticationStrategy());
        CompositeSessionAuthenticationStrategy compositeSessionAuthenticationStrategy = new CompositeSessionAuthenticationStrategy(sessionAuthenticationStrategies);
        return compositeSessionAuthenticationStrategy;
    }

【问题讨论】:

    标签: spring spring-boot spring-security


    【解决方案1】:

    使用此配置,会话将仅在一个浏览器中创建, 只要会话存在,所有登录新浏览器的尝试都不会成功。

    有了这样一个最小的配置:

    
        @Override
        protected void configure(HttpSecurity http) throws Exception {
            http
                .sessionManagement()
                    .maximumSessions(1)
                    .sessionRegistry(sessionRegistry());
        }
    

    每次都会创建会话,旧的会话会过期

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 2012-03-16
      • 2019-03-11
      • 2018-11-03
      • 1970-01-01
      • 2011-06-08
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多