Shiro集成web配置

                        


                    


                               


                        


    pom.xml文件配置如下


<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
  xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd">
  <modelVersion>4.0.0</modelVersion>
  <groupId>com.hp.shiro</groupId>
  <artifactId>ShiroWeb</artifactId>
  <packaging>war</packaging>
  <version>0.0.1-SNAPSHOT</version>
  <name>ShiroWeb Maven Webapp</name>
  <url>http://maven.apache.org</url>
  <dependencies>
    <dependency>
      <groupId>junit</groupId>
      <artifactId>junit</artifactId>
      <version>3.8.1</version>
      <scope>test</scope>
    </dependency>
       <!-- 添加servlet支持 -->
    
<!-- https://mvnrepository.com/artifact/javax.servlet/javax.servlet-api -->
<dependency>
    <groupId>javax.servlet</groupId>
    <artifactId>javax.servlet-api</artifactId>
    <version>3.1.0</version>
</dependency>

<!-- 添加jstl支持 -->
<dependency> 
  <groupId>jstl</groupId> 
    <artifactId>jstl</artifactId> 
      <version>1.2</version> 
</dependency> 

<dependency> 
    <groupId>taglibs</groupId> 
      <artifactId>standard</artifactId> 
<version>1.1.2</version> 
</dependency> 



<!-- 添加日志支持 -->
<!-- https://mvnrepository.com/artifact/log4j/log4j -->
<dependency>
    <groupId>log4j</groupId>
    <artifactId>log4j</artifactId>
    <version>1.2.17</version>
</dependency>

    
    <!-- https://mvnrepository.com/artifact/commons-logging/commons-logging -->
<dependency>
    <groupId>commons-logging</groupId>
    <artifactId>commons-logging</artifactId>
    <version>1.2</version>
</dependency>
    <!-- 添加jsp支持 -->
    <!-- https://mvnrepository.com/artifact/javax.servlet.jsp/javax.servlet.jsp-api -->
<dependency>
    <groupId>javax.servlet.jsp</groupId>
    <artifactId>javax.servlet.jsp-api</artifactId>
    <version>2.2.1</version>
</dependency>
 
    
  </dependencies>
  <build>
    <finalName>ShiroWeb</finalName>
  </build>
</project>


接下来修改maven项目 修改如下修改web.xml文件和添加META-INF文件


我们可以创建一个普通点的web项目从里面copyweb.xml和META-INF文件,但是需要注意的是俩个版本必须相同,



比如你创建的普通web项目                                                                             这是项目的目录

  



        把maven的index.jsp页面删掉重新创建一个index.jsp重新运行如图说明环境已经搭好




接下来开始web集成

                        


web.xml文件配置如下


<?xml version="1.0" encoding="UTF-8"?>
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://java.sun.com/xml/ns/javaee" xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_3_0.xsd" id="WebApp_ID" version="3.0">
  <display-name>ShiroWeb</display-name>
  <welcome-file-list>
    <welcome-file>index.jsp</welcome-file>
  </welcome-file-list>
  <listener>
    <listener-class>org.apache.shiro.web.env.EnvironmentLoaderListener</listener-class>
  </listener>
  <filter>
    <filter-name>ShiroFilter</filter-name>
    <filter-class>org.apache.shiro.web.servlet.ShiroFilter</filter-class>
    <init-param>
      <param-name>configPath</param-name>
      <param-value>/WEB-INF/shiroweb.ini</param-value>
    </init-param>
  </filter>
  <filter-mapping>
    <filter-name>ShiroFilter</filter-name>
    <url-pattern>/*</url-pattern>
  </filter-mapping>
  
  <!-- servlet -->
  <servlet>
    <servlet-name>LoginServlet</servlet-name>
    <servlet-class>com.hp.servlet.LoginServlet</servlet-class>
  </servlet>
  <servlet-mapping>
    <servlet-name>LoginServlet</servlet-name>
    <url-pattern>/login</url-pattern>
  </servlet-mapping>
  
  
    <servlet>
    <servlet-name>AdminServlet</servlet-name>
    <servlet-class>com.hp.servlet.AdminServlet</servlet-class>
  </servlet>
  <servlet-mapping>
    <servlet-name>AdminServlet</servlet-name>
    <url-pattern>/admin</url-pattern>
  </servlet-mapping>
  
</web-app>


shiro.ini 配置如下


[main]
authc.loginUrl=/login
roles.unauthorizedUrl=/error.jsp
perms.unauthorizedUrl=/error.jsp
[users]
zs=123,admin
jack=123,teacher
json=345
[roles]
admin=user:*
teacher=student:*
[urls]
/login=anon
/admin=authc
/student=roles[teacher]
 
 

error.jsp

<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Insert title here</title>
</head>
<body>
权限不足    认证未通过
</body>
</html>


login.jsp


<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Insert title here</title>
</head>
<body>
<form action="login" method="post">
${msg }<br/>
userName:<input type="text" name="userName"/><br/>
password:<input type="password" name="password"/><br/>
<input type="submit" value="提交"/>
</form>
</body>
</html>


success.jsp


<%@ page language="java" contentType="text/html; charset=UTF-8"
    pageEncoding="UTF-8"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Insert title here</title>
</head>
<body>
登录成功 ^_^
</body>
</html>

创建servlet 如下


                    


AdminServlet.java配置如下


package com.hp.servlet;

import java.io.IOException;
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

/**
 * Servlet implementation class AdminServlet
 */
@WebServlet("/AdminServlet")
public class AdminServlet extends HttpServlet {
	private static final long serialVersionUID = 1L;
       

	/**
	 * @see HttpServlet#doGet(HttpServletRequest request, HttpServletResponse response)
	 */
	protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		System.out.println("adminservlet doget 已经执行");
	}

	/**
	 * @see HttpServlet#doPost(HttpServletRequest request, HttpServletResponse response)
	 */
	protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		System.out.println("adminservlet dopost 已经执行");
	}

}


LoginServlet.java配置 如下


package com.hp.servlet;

import java.io.IOException;

import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

import org.apache.shiro.SecurityUtils;
import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.subject.Subject;

/**
 * Servlet implementation class LoginServlet
 */
@WebServlet("/LoginServlet")
public class LoginServlet extends HttpServlet {
	private static final long serialVersionUID = 1L;


	/**
	 * @see HttpServlet#doGet(HttpServletRequest request, HttpServletResponse response)
	 */
	protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
	System.out.println("login do get 方法已经执行");
	request.getRequestDispatcher("login.jsp").forward(request, response);
	}

	/**
	 * @see HttpServlet#doPost(HttpServletRequest request, HttpServletResponse response)
	 */
	protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		String UserName = request.getParameter("userName");
		String password = request.getParameter("password");
		//获取实例化对象
		Subject subject = SecurityUtils.getSubject();
		UsernamePasswordToken token = new UsernamePasswordToken(UserName, password);
		try {
			subject.login(token);
			//跳转路径
			response.sendRedirect("success.jsp");
		} catch (Exception e) {
			e.printStackTrace();
			//跳转登录失败页面
			request.setAttribute("msg", "用户名或者密码不正确");
			request.getRequestDispatcher("login.jsp").forward(request, response);
		}
		

	}

}


接下来可以判断用户的身份认证











接下来判断用户的角色认证


                


我们先用zs 进行登录  








使用jack进行角色验证 








接下来判断用户的权限认证




首先使用jack进行验证 我们发现jack没有user:create这个权限





我们使用zs来进行验证 






url的配置方式


?配置一个字符 /user?  可以匹配/user1或者/user3 但是不能配置 /user 或者1/user12


使用如下


                    


接下来 访问user




访问user5



访问user123




       *是匹配零个或者一个或者多个字符 例如/admin* 可以匹配/admin1  /admin5  /admin121 但是不能匹配/admin/21 不能匹配多路径



访问text  如下






访问text121






访问text/12 这样就访问不到了




        **匹配零个或者多个路径 /admin/**  可以匹配/admin  或者/admin/12/12 但是不能匹配/admin21


配置如下




访问/demo






再次访问/demo/12/12




访问/demo21  就不能被访问



猜你喜欢

转载自blog.csdn.net/qq_40646143/article/details/80103058
今日推荐