登錄校驗邏輯
用戶登錄的校驗邏輯分為三個主要步驟,分別是校驗驗證碼,校驗用戶狀態和校驗密碼,具體邏輯如下
- 前端發送
username
、password
、captchaKey
、captchaCode
請求登錄。 - 判斷
captchaCode
是否為空,若為空,則直接響應驗證碼為空
;若不為空進行下一步判斷。 - 根據
captchaKey
從Redis中查詢之前保存的code
,若查詢出來的code
為空,則直接響應驗證碼已過期
;若不為空進行下一步判斷。 - 比較
captchaCode
和code
,若不相同,則直接響應驗證碼不正確
;若相同則進行下一步判斷。 - 根據
username
查詢數據庫,若查詢結果為空,則直接響應賬號不存在
;若不為空則進行下一步判斷。 - 查看用戶狀態,判斷是否被禁用,若禁用,則直接響應
賬號被禁
;若未被禁用,則進行下一步判斷。 - 比對
password
和數據庫中查詢的密碼,若不一致,則直接響應賬號或密碼錯誤
,若一致則進行入最后一步。 - 創建JWT,并響應給瀏覽器。
請求數據結構
package com.orchids.springmybatisplus.model.entity;import io.swagger.v3.oas.annotations.media.Schema;
import lombok.Data;/*** @Author qwh* @Date 2024/6/2 22:31*/
@Data
@Schema(description = "后臺管理系統登錄信息")
public class LoginVo {@Schema(description="用戶名")private String username;@Schema(description="密碼")private String password;@Schema(description="驗證碼key")private String captchaKey;@Schema(description="驗證碼code")private String captchaCode;
}
枚舉類
package com.orchids.lovehouse.common.result;import lombok.Getter;/*** 統一返回結果狀態信息類*/
@Getter
public enum ResultCodeEnum {SUCCESS(200, "成功"),FAIL(201, "失敗"),PARAM_ERROR(202, "參數不正確"),SERVICE_ERROR(203, "服務異常"),DATA_ERROR(204, "數據異常"),ILLEGAL_REQUEST(205, "非法請求"),REPEAT_SUBMIT(206, "重復提交"),DELETE_ERROR(207, "請先刪除子集"),ADMIN_ACCOUNT_EXIST_ERROR(301, "賬號已存在"),ADMIN_CAPTCHA_CODE_ERROR(302, "驗證碼錯誤"),ADMIN_CAPTCHA_CODE_EXPIRED(303, "驗證碼已過期"),ADMIN_CAPTCHA_CODE_NOT_FOUND(304, "未輸入驗證碼"),ADMIN_ACCOUNT_NOT_EXIST(330,"用戶不存在"),ADMIN_LOGIN_AUTH(305, "未登陸"),ADMIN_ACCOUNT_NOT_EXIST_ERROR(306, "賬號不存在"),ADMIN_ACCOUNT_ERROR(307, "用戶名或密碼錯誤"),ADMIN_ACCOUNT_DISABLED_ERROR(308, "該用戶已被禁用"),ADMIN_ACCESS_FORBIDDEN(309, "無訪問權限"),APP_LOGIN_AUTH(501, "未登陸"),APP_LOGIN_PHONE_EMPTY(502, "手機號碼為空"),APP_LOGIN_CODE_EMPTY(503, "驗證碼為空"),APP_SEND_SMS_TOO_OFTEN(504, "驗證法發送過于頻繁"),APP_LOGIN_CODE_EXPIRED(505, "驗證碼已過期"),APP_LOGIN_CODE_ERROR(506, "驗證碼錯誤"),APP_ACCOUNT_DISABLED_ERROR(507, "該用戶已被禁用"),TOKEN_EXPIRED(601, "token過期"),TOKEN_INVALID(602, "token非法");private final Integer code;private final String message;ResultCodeEnum(Integer code, String message) {this.code = code;this.message = message;}
}
全局異常處理
package com.orchids.lovehouse.common.exception;import com.orchids.lovehouse.common.result.ResultCodeEnum;
import lombok.Data;/*** @Author qwh* @Date 2024/6/1 20:18*/
@Data
public class LovehouseException extends RuntimeException {//異常狀態碼private Integer code;/*** 通過狀態碼和錯誤消息創建異常對象* @param message* @param code*/public LovehouseException(String message, Integer code) {super(message);this.code = code;}/*** 根據響應結果枚舉對象創建異常對象* @param resultCodeEnum*/public LovehouseException(ResultCodeEnum resultCodeEnum) {super(resultCodeEnum.getMessage());this.code = resultCodeEnum.getCode();}@Overridepublic String toString() {return "LovehouseException{" +"code=" + code +", message=" + this.getMessage() +'}';}
}
配置所需依賴
登錄接口需要為登錄成功的用戶創建并返回JWT,本項目使用開源的JWT工具Java-JWT,配置如下,具體內容可參考官方文檔。
- 引入Maven依賴
<!-- https://mvnrepository.com/artifact/io.jsonwebtoken/jjwt-api -->
<dependency><groupId>io.jsonwebtoken</groupId><artifactId>jjwt-api</artifactId><version>0.11.2</version>
</dependency><dependency><!-- https://mvnrepository.com/artifact/io.jsonwebtoken/jjwt-impl -->
<dependency><groupId>io.jsonwebtoken</groupId><artifactId>jjwt-impl</artifactId><version>0.11.2</version><scope>runtime</scope>
</dependency><!-- https://mvnrepository.com/artifact/io.jsonwebtoken/jjwt-jackson -->
<dependency><groupId>io.jsonwebtoken</groupId><artifactId>jjwt-jackson</artifactId><version>0.11.2</version><scope>runtime</scope>
</dependency>
創建JWT和工具類 common.utils.JwtUtil
package com.orchids.lovehouse.common.utils;import com.orchids.lovehouse.common.exception.LovehouseException;
import com.orchids.lovehouse.common.result.ResultCodeEnum;
import io.jsonwebtoken.*;
import io.jsonwebtoken.security.Keys;
import io.jsonwebtoken.security.SignatureException;import javax.crypto.SecretKey;
import java.util.Date;/*** @Author qwh* @Date 2024/6/2 21:01*/
public class JwtUtil {private static long tokenExpiration = 60 * 60 * 1000L;public static SecretKey secretKey = Keys.hmacShaKeyFor("M0PKKI6pYGVWWfDZw90a0lTpGYX1d4AQ".getBytes());public static String createToken(Long userId,String username){String token = Jwts.builder().setSubject("USER_INFO").setExpiration(new Date(System.currentTimeMillis()+tokenExpiration)).claim("userId",userId).claim("username",username).signWith(secretKey,SignatureAlgorithm.HS256).compact();return token;}public static Claims parsToken(String token){if (token==null) {throw new LovehouseException(ResultCodeEnum.ADMIN_LOGIN_AUTH);}try {JwtParser jwtParser = Jwts.parserBuilder().setSigningKey(secretKey).build();Jws<Claims> claims = jwtParser.parseClaimsJws(token);return claims.getBody();} catch (ExpiredJwtException e) {throw new LovehouseException(ResultCodeEnum.TOKEN_EXPIRED);} catch (JwtException e){throw new LovehouseException(ResultCodeEnum.TOKEN_INVALID);}}public static void main(String[] args) {System.out.println(createToken(2l,"user"));}
}
controller邏輯
package com.orchids.lovehouse.web.admin.controller.login;import com.orchids.lovehouse.common.login.LoginUserHolder;
import com.orchids.lovehouse.common.result.Result;
import com.orchids.lovehouse.common.utils.JwtUtil;
import com.orchids.lovehouse.web.admin.service.LoginService;
import com.orchids.lovehouse.web.admin.vo.login.CaptchaVo;
import com.orchids.lovehouse.web.admin.vo.login.LoginVo;
import com.orchids.lovehouse.web.admin.vo.system.user.SystemUserInfoVo;
import com.orchids.lovehouse.web.admin.vo.system.user.SystemUserItemVo;
import io.jsonwebtoken.Claims;
import io.swagger.v3.oas.annotations.Operation;
import io.swagger.v3.oas.annotations.tags.Tag;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.web.bind.annotation.*;@Tag(name = "后臺管理系統登錄管理")
@RestController
@RequestMapping("/admin")
public class LoginController {@Autowiredprivate LoginService loginService;@Operation(summary = "獲取圖形驗證碼")@GetMapping("login/captcha")public Result<CaptchaVo> getCaptcha() {CaptchaVo captcha = loginService.getCaptcha();return Result.ok(captcha);}@Operation(summary = "登錄")@PostMapping("login")public Result<String> login(@RequestBody LoginVo loginVo) {String token = loginService.login(loginVo);return Result.ok(token);}@Operation(summary = "獲取登陸用戶個人信息")@GetMapping("info")public Result<SystemUserInfoVo> info () {SystemUserInfoVo systemUserInfo = loginService.getLoginUserInfo(LoginUserHolder.getLoginUser().getUserId());return Result.ok(systemUserInfo);}
}
service邏輯
package com.orchids.lovehouse.web.admin.service;import com.orchids.lovehouse.web.admin.vo.login.CaptchaVo;
import com.orchids.lovehouse.web.admin.vo.login.LoginVo;
import com.orchids.lovehouse.web.admin.vo.system.user.SystemUserInfoVo;public interface LoginService {CaptchaVo getCaptcha();String login(LoginVo loginVo);SystemUserInfoVo getLoginUserInfo(Long userId);
}
sreviceImpl
package com.orchids.lovehouse.web.admin.service.impl;import com.orchids.lovehouse.common.constant.RedisConstant;
import com.orchids.lovehouse.common.exception.GlobalExceptionHandler;
import com.orchids.lovehouse.common.exception.LovehouseException;
import com.orchids.lovehouse.common.result.ResultCodeEnum;
import com.orchids.lovehouse.common.utils.JwtUtil;
import com.orchids.lovehouse.model.entity.SystemUser;
import com.orchids.lovehouse.model.enums.BaseStatus;
import com.orchids.lovehouse.web.admin.mapper.SystemUserMapper;
import com.orchids.lovehouse.web.admin.service.LoginService;
import com.orchids.lovehouse.web.admin.vo.login.CaptchaVo;
import com.orchids.lovehouse.web.admin.vo.login.LoginVo;
import com.orchids.lovehouse.web.admin.vo.system.user.SystemUserInfoVo;
import com.orchids.lovehouse.web.admin.vo.system.user.SystemUserItemVo;
import com.wf.captcha.SpecCaptcha;
import com.wf.captcha.base.Captcha;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.data.redis.core.StringRedisTemplate;
import org.springframework.stereotype.Service;
import org.springframework.util.DigestUtils;
import org.springframework.util.StringUtils;import java.util.UUID;
import java.util.concurrent.TimeUnit;@Service
public class LoginServiceImpl implements LoginService {@Autowiredprivate StringRedisTemplate stringRedisTemplate;@Autowiredprivate SystemUserMapper systemUserMapper;@Overridepublic CaptchaVo getCaptcha() {SpecCaptcha specCaptcha = new SpecCaptcha(100, 40, 5);specCaptcha.setCharType(Captcha.TYPE_DEFAULT);String code = specCaptcha.text().toLowerCase();String key = RedisConstant.ADMIN_LOGIN_PREFIX + UUID.randomUUID();String img = specCaptcha.toBase64();stringRedisTemplate.opsForValue().set(key,code,60, TimeUnit.SECONDS);return new CaptchaVo(img,key);}@Overridepublic String login(LoginVo loginVo) {//判斷是否輸入驗證碼if (!StringUtils.hasText(loginVo.getCaptchaCode())) {throw new LovehouseException(ResultCodeEnum.ADMIN_CAPTCHA_CODE_NOT_FOUND);}//校驗驗證碼String code = stringRedisTemplate.opsForValue().get(loginVo.getCaptchaKey());if (code == null){throw new LovehouseException(ResultCodeEnum.APP_LOGIN_CODE_EXPIRED);}if (!code.equals(loginVo.getCaptchaCode())){throw new LovehouseException(ResultCodeEnum.APP_LOGIN_CODE_ERROR);}//校驗用戶是否存在SystemUser systemUser = systemUserMapper.selectOneByUsername(loginVo.getUsername());if (systemUser == null) {throw new LovehouseException(ResultCodeEnum.ADMIN_ACCOUNT_NOT_EXIST);}if (systemUser.getStatus() == BaseStatus.DISABLE) {throw new LovehouseException(ResultCodeEnum.ADMIN_ACCOUNT_DISABLED_ERROR);}// 鏍¢獙鐢ㄦ埛瀵嗙爜if (!systemUser.getPassword().equals(DigestUtils.md5DigestAsHex(loginVo.getPassword().getBytes()))) {throw new LovehouseException(ResultCodeEnum.ADMIN_ACCOUNT_ERROR);}// 鍒涘緩騫惰繑鍥瀟okenreturn JwtUtil.createToken(systemUser.getId(),systemUser.getUsername());}@Overridepublic SystemUserInfoVo getLoginUserInfo(Long userId) {SystemUser systemUser = systemUserMapper.selectById(userId);SystemUserInfoVo systemUserInfoVo = new SystemUserInfoVo();systemUserInfoVo.setName(systemUser.getName());systemUserInfoVo.setAvatarUrl(systemUser.getAvatarUrl());return systemUserInfoVo;}}
編寫mapper邏輯
SystemUser selectOneByUsername(String username);
mapper.xml
寫入對應的sql到xml文件
編寫HandlerInterceptor
保護所有受保護的接口增加jwt合法性邏輯 custom.interceptor.AuthenticationInterceptor
package com.orchids.lovehouse.web.admin.custom.interceptor;import com.orchids.lovehouse.common.login.LoginUser;
import com.orchids.lovehouse.common.login.LoginUserHolder;
import io.jsonwebtoken.Claims;
import jakarta.servlet.http.HttpServletRequest;
import jakarta.servlet.http.HttpServletResponse;
import org.springframework.stereotype.Component;
import org.springframework.web.servlet.HandlerInterceptor;
import com.orchids.lovehouse.common.utils.JwtUtil;/*** @Author qwh* @Date 2024/6/2 21:55*/
@Component
public class AuthenticationInterceptor implements HandlerInterceptor {@Overridepublic boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception {String token = request.getHeader("access-token");Claims claims = JwtUtil.parsToken(token);Long userId = claims.get("userId", Long.class);String username = claims.get("username", String.class);LoginUserHolder.setLoginUser(new LoginUser(userId,username));return true;}@Overridepublic void afterCompletion(HttpServletRequest request, HttpServletResponse response, Object handler, Exception ex) throws Exception {LoginUserHolder.clear();}
}
我們約定,前端登錄后,后續請求都將JWT,放置于HTTP請求的Header中,其Header的key為access-token
注冊HanderInterceptor config.WebMvcConfiguration
package com.orchids.lovehouse.web.admin.custom.config;import com.orchids.lovehouse.web.admin.custom.converter.StringToBaseEnumConverterFactory;
import com.orchids.lovehouse.web.admin.custom.converter.StringToItemTypeConverter;
import com.orchids.lovehouse.web.admin.custom.interceptor.AuthenticationInterceptor;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.annotation.Configuration;
import org.springframework.format.FormatterRegistry;
import org.springframework.web.servlet.config.annotation.InterceptorRegistry;
import org.springframework.web.servlet.config.annotation.WebMvcConfigurer;@Configuration
public class WebMvcConfiguration implements WebMvcConfigurer {@Autowiredprivate AuthenticationInterceptor authenticationInterceptor;@Overridepublic void addInterceptors(InterceptorRegistry registry) {registry.addInterceptor(this.authenticationInterceptor).addPathPatterns("/admin/**").excludePathPatterns("/admin/login/**");}
}
獲取登錄個人信息
查看請求和響應的數據結構
- 響應的數據結構
@Schema(description = "員工基本信息")
@Data
public class SystemUserInfoVo {@Schema(description = "用戶姓名")private String name;@Schema(description = "用戶頭像")private String avatarUrl;
}
common.login.LoginUserHolder
package com.orchids.lovehouse.common.login;/*** @Author qwh* @Date 2024/6/2 22:15*/
public class LoginUserHolder {public static ThreadLocal<LoginUser> threadLocal = new ThreadLocal<>();public static void setLoginUser(LoginUser loginUser) {threadLocal.set(loginUser);}public static LoginUser getLoginUser() {return threadLocal.get();}public static void clear() {threadLocal.remove();}
}
common.login.LoginUser
package com.orchids.lovehouse.common.login;import lombok.AllArgsConstructor;
import lombok.Data;/*** @Author qwh* @Date 2024/6/2 22:16*/
@Data
@AllArgsConstructor
public class LoginUser {private Long userId;private String username;
}