Under springboot custom sessionId of shiro generation strategy

View source

Custom SessionIdGenerator

Configuration:

verification

important point

  • Not 100% reliable algorithm, brute force, exhaustive
  • Ip within the time limit the number of login errors
  • Increasing pattern codes can not be too simple, conventional OCR codes can be identified
  • Recommendation: micro-services which, in particular, the application of the C-terminal user, do not do too complex permission check, particularly those affecting the performance of this

Source address: https: //github.com/woxbwo/is-rbac-shiro-service/tree/master/src/main/java/com/is/shiro/service/config

carry out! ! !

Guess you like

Origin www.cnblogs.com/woxbwo/p/11427456.html