Authentication:身份认证,即用户提供一些信息来证明自己的身份。如用户名和密码,licence等。
Authenticator的职责是验证用户帐号,是Shiro API中身份验证核心的入口点:
public AuthenticationInfo authenticate(AuthenticationToken authenticationToken) throws AuthenticationException;
如果验证成功,将返回AuthenticationInfo验证信息;此信息中包含了身份及凭证;如果验证失败将抛出相应的AuthenticationException实现。
SecurityManager接口继承了Authenticator,另外还有一个ModularRealmAuthenticator实现,其委托给多个Realm进行验证,验证规则通过AuthenticationStrategy接口指定,默认提供的实现:
- FirstSuccessfulStrategy:只要有一个Realm验证成功即可,只返回第一个Realm身份验证成功的认证信息,其他的忽略;
- AtLeastOneSuccessfulStrategy:只要有一个Realm验证成功即可,和FirstSuccessfulStrategy不同,返回所有Realm身份验证成功的认证信息;
- AllSuccessfulStrategy:所有Realm验证成功才算成功,且返回所有Realm身份验证成功的认证信息,如果有一个失败就失败了。
ModularRealmAuthenticator默认使用AtLeastOneSuccessfulStrategy策略。
假设我们有三个realm:
- myRealm1: 用户名/密码为xttblog/123时成功,且返回身份/凭据为xttblog/123;
- myRealm2: 用户名/密码为codedq/123时成功,且返回身份/凭据为codedq/123;
- myRealm3: 用户名/密码为xttblog/123时成功,且返回身份/凭据为xttblog@qq.com/123,和myRealm1不同的是返回时的身份变了;
shiro-authenticator-all-success.ini 配置文件:
#指定securityManager的authenticator实现 authenticator=org.apache.shiro.authc.pam.ModularRealmAuthenticator securityManager.authenticator=$authenticator #指定securityManager.authenticator的authenticationStrategy allSuccessfulStrategy=org.apache.shiro.authc.pam.AllSuccessfulStrategy securityManager.authenticator.authenticationStrategy=$allSuccessfulStrategy myRealm1=com.xttblog.realm.XttblogRealm myRealm2=com.xttblog.realm.CodedqRealm myRealm3=com.xttblog.realm.MyRealm securityManager.realms=$myRealm1,$myRealm3
shiro-authenticator-all-fail.ini 配置文件:
#指定securityManager的authenticator实现 authenticator=org.apache.shiro.authc.pam.ModularRealmAuthenticator securityManager.authenticator=$authenticator #指定securityManager.authenticator的authenticationStrategy allSuccessfulStrategy=org.apache.shiro.authc.pam.AllSuccessfulStrategy securityManager.authenticator.authenticationStrategy=$allSuccessfulStrategy myRealm1=com.xttblog.realm.XttblogRealm myRealm2=com.xttblog.realm.CodedqRealm myRealm3=com.xttblog.realm.MyRealm securityManager.realms=$myRealm1,$myRealm2
测试用例代码如下:
package com.xttblog; import org.apache.shiro.SecurityUtils; import org.apache.shiro.authc.UnknownAccountException; import org.apache.shiro.authc.UsernamePasswordToken; import org.apache.shiro.config.IniSecurityManagerFactory; import org.apache.shiro.subject.PrincipalCollection; import org.apache.shiro.subject.Subject; import org.apache.shiro.util.Factory; import org.apache.shiro.util.ThreadContext; import org.junit.After; import org.junit.Assert; import org.junit.Test; public class AuthenticatorTest { @Test public void testAllSuccessfulStrategyWithSuccess() { login("classpath:shiro-authenticator-all-success.ini"); Subject subject = SecurityUtils.getSubject(); //得到一个身份集合,其包含了Realm验证成功的身份信息 PrincipalCollection principalCollection = subject.getPrincipals(); Assert.assertEquals(2, principalCollection.asList().size()); } @Test(expected = UnknownAccountException.class) public void testAllSuccessfulStrategyWithFail() { login("classpath:shiro-authenticator-all-fail.ini"); } @Test public void testAtLeastOneSuccessfulStrategyWithSuccess() { login("classpath:shiro-authenticator-atLeastOne-success.ini"); Subject subject = SecurityUtils.getSubject(); //得到一个身份集合,其包含了Realm验证成功的身份信息 PrincipalCollection principalCollection = subject.getPrincipals(); Assert.assertEquals(2, principalCollection.asList().size()); } @Test public void testFirstOneSuccessfulStrategyWithSuccess() { login("classpath:shiro-authenticator-first-success.ini"); Subject subject = SecurityUtils.getSubject(); //得到一个身份集合,其包含了第一个Realm验证成功的身份信息 PrincipalCollection principalCollection = subject.getPrincipals(); Assert.assertEquals(1, principalCollection.asList().size()); } @Test public void testAtLeastTwoStrategyWithSuccess() { login("classpath:shiro-authenticator-atLeastTwo-success.ini"); Subject subject = SecurityUtils.getSubject(); //得到一个身份集合,因为myRealm1和myRealm4返回的身份一样所以输出时只返回一个 PrincipalCollection principalCollection = subject.getPrincipals(); Assert.assertEquals(1, principalCollection.asList().size()); } @Test public void testOnlyOneStrategyWithSuccess() { login("classpath:shiro-authenticator-onlyone-success.ini"); Subject subject = SecurityUtils.getSubject(); //得到一个身份集合,因为myRealm1和myRealm4返回的身份一样所以输出时只返回一个 PrincipalCollection principalCollection = subject.getPrincipals(); Assert.assertEquals(1, principalCollection.asList().size()); } private void login(String configFile) { //1、获取SecurityManager工厂,此处使用Ini配置文件初始化SecurityManager Factory<org.apache.shiro.mgt.SecurityManager> factory = new IniSecurityManagerFactory(configFile); //2、得到SecurityManager实例 并绑定给SecurityUtils org.apache.shiro.mgt.SecurityManager securityManager = factory.getInstance(); SecurityUtils.setSecurityManager(securityManager); //3、得到Subject及创建用户名/密码身份验证Token(即用户身份/凭证) Subject subject = SecurityUtils.getSubject(); UsernamePasswordToken token = new UsernamePasswordToken("xttblog", "123"); subject.login(token); } @After public void tearDown() throws Exception { ThreadContext.unbindSubject();//退出时请解除绑定Subject到线程 否则对下次测试造成影响 } }
shiro-authenticator-all-fail.ini与shiro-authenticator-all-success.ini不同的配置是使用了securityManager.realms=$myRealm1,$myRealm2;即myRealm验证失败。
对于AtLeastOneSuccessfulStrategy和FirstSuccessfulStrategy的区别,请参照testAtLeastOneSuccessfulStrategyWithSuccess和testFirstOneSuccessfulStrategyWithSuccess测试方法。唯一不同点一个是返回所有验证成功的Realm的认证信息;另一个是只返回第一个验证成功的Realm的认证信息。
自定义AuthenticationStrategy实现,首先看其API:
//在所有Realm验证之前调用 AuthenticationInfo beforeAllAttempts( Collection<? extends Realm> realms, AuthenticationToken token) throws AuthenticationException; //在每个Realm之前调用 AuthenticationInfo beforeAttempt( Realm realm, AuthenticationToken token, AuthenticationInfo aggregate) throws AuthenticationException; //在每个Realm之后调用 AuthenticationInfo afterAttempt( Realm realm, AuthenticationToken token, AuthenticationInfo singleRealmInfo, AuthenticationInfo aggregateInfo, Throwable t) throws AuthenticationException; //在所有Realm之后调用 AuthenticationInfo afterAllAttempts( AuthenticationToken token, AuthenticationInfo aggregate) throws AuthenticationException;
因为每个AuthenticationStrategy实例都是无状态的,所有每次都通过接口将相应的认证信息传入下一次流程;通过如上接口可以进行如合并/返回第一个验证成功的认证信息。
自定义实现时一般继承org.apache.shiro.authc.pam.AbstractAuthenticationStrategy即可,具体可以参考代码com.github.zhangkaitao.shiro.chapter2.authenticator.strategy包下OnlyOneAuthenticatorStrategy 和AtLeastTwoAuthenticatorStrategy。
相关代码下载链接:http://pan.baidu.com/s/1jH6OmqU 密码:y3qp
: » Shiro 身份认证Authenticator和AuthenticationStrategy
原创文章,作者:3628473679,如若转载,请注明出处:https://blog.ytso.com/251541.html