【发布时间】:2016-02-29 18:04:17
【问题描述】:
我已经使用 Spring Boot 安全性实现了安全层,并且我使用了 MD5 加密机制来对提供的密码进行编码。它按预期完美运行,但我需要获取用户在 DAO 或服务层中输入的用户名和原始密码。以下是我使用的代码
@Autowired
UserDao userDao;
@Autowired
@Qualifier("userDetailsService")
UserDetailsService userDetailsService;
@Autowired
private RESTAuthenticationEntryPoint authenticationEntryPoint;
@Autowired
private RESTAuthenticationFailureHandler authenticationFailureHandler;
@Autowired
private RESTAuthenticationSuccessHandler authenticationSuccessHandler;
@Override
public void configure(WebSecurity web) throws Exception {
web.ignoring().antMatchers("/css/**", "/fonts/**", "/images/**");
}
/**
* Security implementation to access the services
*/
@Override
protected void configure(HttpSecurity http) throws Exception {
http.authorizeRequests().antMatchers("/", "/index.html","/home.html","/page/*","/home/*", "/login.html","/login","/cms/createPhoneNo").permitAll();
http.authorizeRequests().anyRequest().fullyAuthenticated().and().httpBasic().and().csrf().disable();
http.exceptionHandling().authenticationEntryPoint(authenticationEntryPoint);
http.formLogin().loginProcessingUrl("/login/authenticate").successHandler(authenticationSuccessHandler);
http.formLogin().failureHandler(authenticationFailureHandler);
http.logout().logoutRequestMatcher(new AntPathRequestMatcher("/logout")).invalidateHttpSession(true);
http.exceptionHandling().accessDeniedHandler(accessDeniedHandler());
// CSRF tokens handling
http.addFilterAfter(new CsrfTokenResponseHeaderBindingFilter(), CsrfFilter.class);
}
/**
* Configures the authentication manager bean which processes authentication
* requests.
*/
@Override
protected void configure(AuthenticationManagerBuilder auth) throws Exception {
// Dao based authentication
auth.userDetailsService(userDetailsService).passwordEncoder(new Md5PasswordEncoder());
}
private AccessDeniedHandler accessDeniedHandler() {
return new AccessDeniedHandler() {
@Override
public void handle(HttpServletRequest request, HttpServletResponse response,
AccessDeniedException accessDeniedException) throws IOException, ServletException {
response.getWriter().append("Access denied");
response.setStatus(403);
}
};
}
/**
* This bean is load the user specific data when form login is used.
*/
@Bean
public UserDetailsService userDetailsService() {
return new MyCustomUserDetailsService(userDao);
}
}
有人可以帮我实现这个场景吗?
谢谢,
【问题讨论】:
-
你不能“解码”md5。 Md5 是(非常弱的)单向哈希。我能问你为什么要原始密码吗?散列的重点是没有这个。另外,请考虑至少使用 sha-256 或 bcrypt 或 scrypt,md5 非常弱,除了校验和之外,它并不适合任何东西。
-
@Taylor 实际上,我需要根据用户类型检查两个数据库的用户身份验证。在一个数据库中,如果找不到输入的用户,我会为具有用户类型的用户编码密码该用户类型我需要切换到另一个数据库,我将密码作为原始密码,所以我需要输入原始密码。你对此有任何想法吗?
-
您不需要原始密码。您只需使用与前端相同的方法对数据库中的密码进行哈希处理并比较哈希值。
标签: spring-security spring-boot