【问题标题】:Restlet how to decode secret in HTTP basic authenticationRestlet如何在HTTP基本身份验证中解码秘密
【发布时间】:2015-05-24 10:02:01
【问题描述】:

我有以下类处理我的一条路线:

public class HotelsSrv extends ServerResource implements 
   HotelsListResource {
   private String hotelId;

   @Override
   protected void doInit() throws ResourceException {
       super.doInit();
       String str;
       String secret = getRequest().getChallengeResponse().getSecret().toString();
       byte[] bytes = new BASE64Decoder().decodeBuffer(secret)
       str = new String(bytes);

       System.out.println("user: "+getRequest().getChallengeResponse().getIdentifier());

       System.out.println("password: "+str);
}

我正在尝试对秘密进行解码,以便可以使用自定义程序对其进行验证,但这一行引发了未知异常:

    byte[] bytes = new BASE64Decoder().decodeBuffer(secret)

【问题讨论】:

  • 你试过下面的代码了吗?

标签: java rest base64 jax-rs restlet


【解决方案1】:

试试这个代码

public void authenticate(HttpServletRequest req) {
    String authhead = req.getHeader("Authorization");

        if (authhead != null) {
            // *****Decode the authorisation String*****
            byte[] e = Base64.decode(authhead.substring(6));
            String usernpass = new String(e);
            // *****Split the username from the password*****
            String user = usernpass.substring(0, usernpass.indexOf(":"));
            String password = usernpass.substring(usernpass.indexOf(":") + 1);
            // check username and password
        }
}

【讨论】:

  • 我对上面的代码做了一点调整,它就像魅力一样工作:Series headers = HttpRequest.getCurrent().getHeaders(); String auth = headers.getFirstValue("Authorization"); if (auth != null) { // 解码授权字符串 byte[] e = Base64.decode(auth.substring(6)); String usernpass = new String(e); // 从密码中拆分用户名 user = usernpass.substring(0, usernpass.indexOf(":"));密码 = usernpass.substring(usernpass.indexOf(":") + 1); }
【解决方案2】:

无需对秘密进行编码/解码。它在 ChallengeResponse 类中存储为 char 表,仅出于安全原因(参见 javadocs,以及此链接以获取更多解释 http://www.careercup.com/question?id=14955419)

String secret = new String(getRequest().getChallengeResponse().getSecret());

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2013-04-06
    • 1970-01-01
    • 2015-12-08
    • 1970-01-01
    • 2013-10-26
    • 2021-06-02
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多