| | |
| | | package com.ruoyi.gateway.filter; |
| | | |
| | | import java.util.Arrays; |
| | | import javax.annotation.Resource; |
| | | import org.slf4j.Logger; |
| | | import org.slf4j.LoggerFactory; |
| | | import org.springframework.beans.factory.annotation.Autowired; |
| | | import org.springframework.cloud.gateway.filter.GatewayFilterChain; |
| | | import org.springframework.cloud.gateway.filter.GlobalFilter; |
| | | import org.springframework.core.Ordered; |
| | |
| | | import com.alibaba.fastjson.JSON; |
| | | import com.alibaba.fastjson.JSONObject; |
| | | import com.ruoyi.common.core.constant.CacheConstants; |
| | | import com.ruoyi.common.core.constant.Constants; |
| | | import com.ruoyi.common.core.domain.R; |
| | | import com.ruoyi.common.core.utils.ServletUtils; |
| | | import com.ruoyi.common.core.utils.StringUtils; |
| | | import com.ruoyi.common.redis.service.RedisService; |
| | | import com.ruoyi.gateway.config.properties.IgnoreWhiteProperties; |
| | | import reactor.core.publisher.Mono; |
| | | |
| | | /** |
| | |
| | | public class AuthFilter implements GlobalFilter, Ordered |
| | | { |
| | | private static final Logger log = LoggerFactory.getLogger(AuthFilter.class); |
| | | |
| | | private final static long EXPIRE_TIME = Constants.TOKEN_EXPIRE * 60; |
| | | |
| | | // 排除过滤的 uri 地址,swagger排除自行添加 |
| | | private static final String[] whiteList = { "/auth/login", "/code/v2/api-docs", "/schedule/v2/api-docs", |
| | | "/system/v2/api-docs", "/csrf" }; |
| | | // 排除过滤的 uri 地址,nacos自行添加 |
| | | @Autowired |
| | | private IgnoreWhiteProperties ignoreWhite; |
| | | |
| | | @Resource(name = "stringRedisTemplate") |
| | | private ValueOperations<String, String> sops; |
| | | |
| | | @Autowired |
| | | private RedisService redisService; |
| | | |
| | | @Override |
| | | public Mono<Void> filter(ServerWebExchange exchange, GatewayFilterChain chain) |
| | | { |
| | | String url = exchange.getRequest().getURI().getPath(); |
| | | // 跳过不需要验证的路径 |
| | | if (Arrays.asList(whiteList).contains(url)) |
| | | if (StringUtils.matches(url, ignoreWhite.getWhites())) |
| | | { |
| | | return chain.filter(exchange); |
| | | } |
| | |
| | | { |
| | | return setUnauthorizedResponse(exchange, "令牌不能为空"); |
| | | } |
| | | String userStr = sops.get(CacheConstants.LOGIN_TOKEN_KEY + token); |
| | | String userStr = sops.get(getTokenKey(token)); |
| | | if (StringUtils.isNull(userStr)) |
| | | { |
| | | return setUnauthorizedResponse(exchange, "令牌验证失败"); |
| | | return setUnauthorizedResponse(exchange, "登录状态已过期"); |
| | | } |
| | | JSONObject obj = JSONObject.parseObject(userStr); |
| | | String userid = obj.getString("userid"); |
| | |
| | | { |
| | | return setUnauthorizedResponse(exchange, "令牌验证失败"); |
| | | } |
| | | |
| | | // 设置过期时间 |
| | | redisService.expire(getTokenKey(token), EXPIRE_TIME); |
| | | // 设置用户信息到请求 |
| | | ServerHttpRequest mutableReq = exchange.getRequest().mutate().header(CacheConstants.DETAILS_USER_ID, userid) |
| | | .header(CacheConstants.DETAILS_USERNAME, username).build(); |
| | | .header(CacheConstants.DETAILS_USERNAME, ServletUtils.urlEncode(username)).build(); |
| | | ServerWebExchange mutableExchange = exchange.mutate().request(mutableReq).build(); |
| | | |
| | | |
| | | return chain.filter(mutableExchange); |
| | | } |
| | | |
| | |
| | | })); |
| | | } |
| | | |
| | | private String getTokenKey(String token) |
| | | { |
| | | return CacheConstants.LOGIN_TOKEN_KEY + token; |
| | | } |
| | | |
| | | /** |
| | | * 获取请求token |
| | | */ |