Authentication:身份认证,即用户提供一些信息来证明自己的身份。如用户名和密码,licence等。
Authenticator的职责是验证用户帐号,是Shiro API中身份验证核心的入口点:
public AuthenticationInfo authenticate(AuthenticationToken authenticationToken) throws AuthenticationException;
如果验证成功,将返回AuthenticationInfo验证信息;此信息中包含了身份及凭证;如果验证失败将抛出相应的AuthenticationException实现。
SecurityManager接口继承了Authenticator,另外还有一个ModularRealmAuthenticator实现,其委托给多个Realm进行验证,验证规则通过AuthenticationStrategy接口指定,默认提供的实现:
- FirstSuccessfulStrategy:只要有一个Realm验证成功即可,只返回第一个Realm身份验证成功的认证信息,其他的忽略;
- AtLeastOneSuccessfulStrategy:只要有一个Realm验证成功即可,和FirstSuccessfulStrategy不同,返回所有Realm身份验证成功的认证信息;
- AllSuccessfulStrategy:所有Realm验证成功才算成功,且返回所有Realm身份验证成功的认证信息,如果有一个失败就失败了。
ModularRealmAuthenticator默认使用AtLeastOneSuccessfulStrategy策略。
假设我们有三个realm:
- myRealm1: 用户名/密码为xttblog/123时成功,且返回身份/凭据为xttblog/123;
- myRealm2: 用户名/密码为codedq/123时成功,且返回身份/凭据为codedq/123;
- myRealm3: 用户名/密码为xttblog/123时成功,且返回身份/凭据为xttblog@qq.com/123,和myRealm1不同的是返回时的身份变了;
shiro-authenticator-all-success.ini 配置文件:
#指定securityManager的authenticator实现 authenticator=org.apache.shiro.authc.pam.ModularRealmAuthenticator securityManager.authenticator=$authenticator #指定securityManager.authenticator的authenticationStrategy allSuccessfulStrategy=org.apache.shiro.authc.pam.AllSuccessfulStrategy securityManager.authenticator.authenticationStrategy=$allSuccessfulStrategy myRealm1=com.xttblog.realm.XttblogRealm myRealm2=com.xttblog.realm.CodedqRealm myRealm3=com.xttblog.realm.MyRealm securityManager.realms=$myRealm1,$myRealm3
shiro-authenticator-all-fail.ini 配置文件:
#指定securityManager的authenticator实现 authenticator=org.apache.shiro.authc.pam.ModularRealmAuthenticator securityManager.authenticator=$authenticator #指定securityManager.authenticator的authenticationStrategy allSuccessfulStrategy=org.apache.shiro.authc.pam.AllSuccessfulStrategy securityManager.authenticator.authenticationStrategy=$allSuccessfulStrategy myRealm1=com.xttblog.realm.XttblogRealm myRealm2=com.xttblog.realm.CodedqRealm myRealm3=com.xttblog.realm.MyRealm securityManager.realms=$myRealm1,$myRealm2
测试用例代码如下:
package com.xttblog;
import org.apache.shiro.SecurityUtils;
import org.apache.shiro.authc.UnknownAccountException;
import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.config.IniSecurityManagerFactory;
import org.apache.shiro.subject.PrincipalCollection;
import org.apache.shiro.subject.Subject;
import org.apache.shiro.util.Factory;
import org.apache.shiro.util.ThreadContext;
import org.junit.After;
import org.junit.Assert;
import org.junit.Test;
public class AuthenticatorTest {
@Test
public void testAllSuccessfulStrategyWithSuccess() {
login("classpath:shiro-authenticator-all-success.ini");
Subject subject = SecurityUtils.getSubject();
//得到一个身份集合,其包含了Realm验证成功的身份信息
PrincipalCollection principalCollection = subject.getPrincipals();
Assert.assertEquals(2, principalCollection.asList().size());
}
@Test(expected = UnknownAccountException.class)
public void testAllSuccessfulStrategyWithFail() {
login("classpath:shiro-authenticator-all-fail.ini");
}
@Test
public void testAtLeastOneSuccessfulStrategyWithSuccess() {
login("classpath:shiro-authenticator-atLeastOne-success.ini");
Subject subject = SecurityUtils.getSubject();
//得到一个身份集合,其包含了Realm验证成功的身份信息
PrincipalCollection principalCollection = subject.getPrincipals();
Assert.assertEquals(2, principalCollection.asList().size());
}
@Test
public void testFirstOneSuccessfulStrategyWithSuccess() {
login("classpath:shiro-authenticator-first-success.ini");
Subject subject = SecurityUtils.getSubject();
//得到一个身份集合,其包含了第一个Realm验证成功的身份信息
PrincipalCollection principalCollection = subject.getPrincipals();
Assert.assertEquals(1, principalCollection.asList().size());
}
@Test
public void testAtLeastTwoStrategyWithSuccess() {
login("classpath:shiro-authenticator-atLeastTwo-success.ini");
Subject subject = SecurityUtils.getSubject();
//得到一个身份集合,因为myRealm1和myRealm4返回的身份一样所以输出时只返回一个
PrincipalCollection principalCollection = subject.getPrincipals();
Assert.assertEquals(1, principalCollection.asList().size());
}
@Test
public void testOnlyOneStrategyWithSuccess() {
login("classpath:shiro-authenticator-onlyone-success.ini");
Subject subject = SecurityUtils.getSubject();
//得到一个身份集合,因为myRealm1和myRealm4返回的身份一样所以输出时只返回一个
PrincipalCollection principalCollection = subject.getPrincipals();
Assert.assertEquals(1, principalCollection.asList().size());
}
private void login(String configFile) {
//1、获取SecurityManager工厂,此处使用Ini配置文件初始化SecurityManager
Factory<org.apache.shiro.mgt.SecurityManager> factory =
new IniSecurityManagerFactory(configFile);
//2、得到SecurityManager实例 并绑定给SecurityUtils
org.apache.shiro.mgt.SecurityManager securityManager = factory.getInstance();
SecurityUtils.setSecurityManager(securityManager);
//3、得到Subject及创建用户名/密码身份验证Token(即用户身份/凭证)
Subject subject = SecurityUtils.getSubject();
UsernamePasswordToken token = new UsernamePasswordToken("xttblog", "123");
subject.login(token);
}
@After
public void tearDown() throws Exception {
ThreadContext.unbindSubject();//退出时请解除绑定Subject到线程 否则对下次测试造成影响
}
}
shiro-authenticator-all-fail.ini与shiro-authenticator-all-success.ini不同的配置是使用了securityManager.realms=$myRealm1,$myRealm2;即myRealm验证失败。
对于AtLeastOneSuccessfulStrategy和FirstSuccessfulStrategy的区别,请参照testAtLeastOneSuccessfulStrategyWithSuccess和testFirstOneSuccessfulStrategyWithSuccess测试方法。唯一不同点一个是返回所有验证成功的Realm的认证信息;另一个是只返回第一个验证成功的Realm的认证信息。
自定义AuthenticationStrategy实现,首先看其API:
//在所有Realm验证之前调用 AuthenticationInfo beforeAllAttempts( Collection<? extends Realm> realms, AuthenticationToken token) throws AuthenticationException; //在每个Realm之前调用 AuthenticationInfo beforeAttempt( Realm realm, AuthenticationToken token, AuthenticationInfo aggregate) throws AuthenticationException; //在每个Realm之后调用 AuthenticationInfo afterAttempt( Realm realm, AuthenticationToken token, AuthenticationInfo singleRealmInfo, AuthenticationInfo aggregateInfo, Throwable t) throws AuthenticationException; //在所有Realm之后调用 AuthenticationInfo afterAllAttempts( AuthenticationToken token, AuthenticationInfo aggregate) throws AuthenticationException;
因为每个AuthenticationStrategy实例都是无状态的,所有每次都通过接口将相应的认证信息传入下一次流程;通过如上接口可以进行如合并/返回第一个验证成功的认证信息。
自定义实现时一般继承org.apache.shiro.authc.pam.AbstractAuthenticationStrategy即可,具体可以参考代码com.github.zhangkaitao.shiro.chapter2.authenticator.strategy包下OnlyOneAuthenticatorStrategy 和AtLeastTwoAuthenticatorStrategy。
相关代码下载链接:http://pan.baidu.com/s/1jH6OmqU 密码:y3qp

: » Shiro 身份认证Authenticator和AuthenticationStrategy
原创文章,作者:3628473679,如若转载,请注明出处:https://blog.ytso.com/tech/pnotes/251541.html