SpringBoot框架接口数据加密(base64)传输(前后分离版本)

技术采用Filter+HttpServletRequestWrapper+HttpServletResponseWrapper+base64

1、前端加解密

1.1 vue引入开源的base64

复制代码
1、下载依赖
$ npm install --save js-base64
 
2、使用方法:
import {Base64} from 'js-base64'
 
Base64.encode('hellow world'); // 编码  aGVsbG93IFdvcmxk
Base64.decode('aGVsbG93IFdvcmxk'); // 解码  hellow World

1.2 在若依系统的request.js中引入base64

1.3 修改若依系统的request.js中的request拦截器-对config.data进行加密处理

1.4 修改若依系统的response.js中的响应拦截器-对后端传入的数据进行解密并转成json

2、后端加解密

2.1 新增过滤器ResponseDataFilter(名字可以随便来,但是要在注册Bean的时候,要统一)

复制代码
import com.ruoyi.common.utils.sign.Base64;
import javax.servlet.Filter;
import javax.servlet.FilterChain;
import javax.servlet.FilterConfig;
import javax.servlet.ServletException;
import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.BufferedReader;
import java.io.IOException;
import java.io.PrintWriter;
 
public class ResponseDataFilter implements Filter {
 
    @Override
    public void init(FilterConfig filterConfig) throws ServletException {
        // 初始化操作,可留空
    }
 
    @Override
    public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException {
        HttpServletRequest requests =  (HttpServletRequest) request;
        String requestBody = getRequestBody(requests);
        System.out.println(requestBody);
        //解密请求报文
        String requestBodyMw = new String(Base64.decode(requestBody), "utf-8");
        System.out.println("解密请求数据:"+requestBodyMw);
        WrapperedRequest wrapRequest = new WrapperedRequest( (HttpServletRequest) request, requestBodyMw);
        WrapperedResponse wrapResponse = new WrapperedResponse((HttpServletResponse) response);
        chain.doFilter(wrapRequest, wrapResponse);
        byte[] data = wrapResponse.getResponseData();
        System.out.println("原始返回数据: " + new String(data, "utf-8"));
        // 加密返回报文
        String responseBodyMw = Base64.encode(data);
        System.out.println("加密返回数据: " + responseBodyMw);
        response.getOutputStream().write(responseBodyMw.getBytes());
    }
 
    @Override
    public void destroy() {
        // 销毁操作,可留空
    }
 
    private String getRequestBody(HttpServletRequest req) {
        try {
            BufferedReader reader = req.getReader();
            StringBuffer sb = new StringBuffer();
            String line = null;
            while ((line = reader.readLine()) != null) {
                sb.append(line);
            }
            String json = sb.toString();
            return json;
        } catch (IOException e) {
            System.out.println("请求体读取失败"+e.getMessage());
        }
        return "";
    }
 
 
}

2.2 把自己添加过滤器注册为bean(在FilterConfig.java文件写,也可以自己写配置文件)

复制代码
复制代码
   @Bean
       public FilterRegistrationBean requestDataFilter()
       {
           FilterRegistrationBean registration = new FilterRegistrationBean();
           //自己的过滤器叫什么名字就写上什么名字
           registration.setFilter(new ResponseDataFilter());
           registration.addUrlPatterns("/*");
           registration.setName("responseDataFilter");
           //过滤器的顺序,数字越小,越先执行,反之亦然
           registration.setOrder(FilterRegistrationBean.LOWEST_PRECEDENCE);
           return registration;
       }

2.3 继承HttpServletRequestWrapper和继承HttpServletResponseWrapper

复制代码
复制代码
   import java.io.ByteArrayOutputStream;
   import java.io.IOException;
   import java.io.OutputStreamWriter;
   import java.io.PrintWriter;
   import java.io.UnsupportedEncodingException;
   import javax.servlet.ServletOutputStream;
   import javax.servlet.WriteListener;
   import javax.servlet.http.HttpServletResponse;
   import javax.servlet.http.HttpServletResponseWrapper;
   public class WrapperedResponse extends HttpServletResponseWrapper {
    
       private ByteArrayOutputStream buffer = null;
       private ServletOutputStream out = null;
       private PrintWriter writer = null;
    
       public WrapperedResponse(HttpServletResponse resp) throws IOException {
           super(resp);
           // 真正存储数据的流
           buffer = new ByteArrayOutputStream();
           out = new WapperedOutputStream(buffer);
           writer = new PrintWriter(new OutputStreamWriter(buffer,
                   this.getCharacterEncoding()));
       }
    
       /** 重载父类获取outputstream的方法 */
       @Override
       public ServletOutputStream getOutputStream() throws IOException {
           return out;
       }
    
       /** 重载父类获取writer的方法 */
       @Override
       public PrintWriter getWriter() throws UnsupportedEncodingException {
           return writer;
       }
    
       /** 重载父类获取flushBuffer的方法 */
       @Override
       public void flushBuffer() throws IOException {
           if (out != null) {
               out.flush();
           }
           if (writer != null) {
               writer.flush();
           }
       }
    
       @Override
       public void reset() {
           buffer.reset();
       }
    
       /** 将out、writer中的数据强制输出到WapperedResponse的buffer里面,否则取不到数据 */
       public byte[] getResponseData() throws IOException {
           flushBuffer();
           return buffer.toByteArray();
       }
    
       /** 内部类,对ServletOutputStream进行包装 */
       private class WapperedOutputStream extends ServletOutputStream {
           private ByteArrayOutputStream bos = null;
    
           public WapperedOutputStream(ByteArrayOutputStream stream)
                   throws IOException {
               bos = stream;
           }
    
           @Override
           public void write(int b) throws IOException {
               bos.write(b);
           }
    
           @Override
           public void write(byte[] b) throws IOException {
               bos.write(b, 0, b.length);
           }
    
           @Override
           public boolean isReady() {
               // TODO Auto-generated method stub
               return false;
           }
    
           @Override
           public void setWriteListener(WriteListener writeListener) {
               // TODO Auto-generated method stub
    
           }
       }
   }

   import java.io.BufferedReader;
   import java.io.ByteArrayInputStream;
   import java.io.IOException;
   import java.io.InputStream;
   import java.io.StringReader;
   import javax.servlet.ReadListener;
   import javax.servlet.ServletInputStream;
   import javax.servlet.http.HttpServletRequest;
   import javax.servlet.http.HttpServletRequestWrapper;
   public class WrapperedRequest extends HttpServletRequestWrapper {
    
       private String requestBody = null;
       HttpServletRequest req = null;
    
       public WrapperedRequest(HttpServletRequest request) {
           super(request);
           this.req = request;
       }
    
       public WrapperedRequest(HttpServletRequest request, String requestBody) {
           super(request);
           this.requestBody = requestBody;
           this.req = request;
       }
    
       /**
        * (non-Javadoc)
        *
        * @see javax.servlet.ServletRequestWrapper#getReader()
        */
       @Override
       public BufferedReader getReader() throws IOException {
           return new BufferedReader(new StringReader(requestBody));
       }
    
       /**
        * (non-Javadoc)
        *
        * @see javax.servlet.ServletRequestWrapper#getInputStream()
        */
       @Override
       public ServletInputStream getInputStream() throws IOException {
           return new ServletInputStream() {
               private InputStream in = new ByteArrayInputStream(
                       requestBody.getBytes(req.getCharacterEncoding()));
               @Override
               public int read() throws IOException {
                   return in.read();
               }
               @Override
               public boolean isFinished() {
                   // TODO Auto-generated method stub
                   return false;
               }
               @Override
               public boolean isReady() {
                   // TODO Auto-generated method stub
                   return false;
               }
               @Override
               public void setReadListener(ReadListener readListener) {
                   // TODO Auto-generated method stub
    
               }
           };
       }
   }

记录技术,留下痕迹。如果有什么不合适的地方,请各位大佬留言指出,小弟改进!!!!

相关推荐
ezl1fe3 分钟前
RAG 每日一技(七):只靠检索还不够?用Re-ranking给你的结果精修一下
后端
猫猫的小茶馆17 分钟前
【STM32】FreeRTOS 任务的删除(三)
java·linux·stm32·单片机·嵌入式硬件·mcu·51单片机
天天摸鱼的java工程师22 分钟前
🔧 MySQL 索引的设计原则有哪些?【原理 + 业务场景实战】
java·后端·面试
snakeshe101027 分钟前
Maven核心功能与IDEA高效调试技巧全解析
后端
空影学Java40 分钟前
Day44 Java数组08 冒泡排序
java
*愿风载尘*1 小时前
ksql连接数据库免输入密码交互
数据库·后端
追风少年浪子彦1 小时前
mybatis-plus实体类主键生成策略
java·数据库·spring·mybatis·mybatis-plus
溟洵1 小时前
Qt 窗口 工具栏QToolBar、状态栏StatusBar
开发语言·前端·数据库·c++·后端·qt
GEM的左耳返1 小时前
Java面试实战:从基础到架构的全方位技术交锋
spring boot·微服务·云原生·java面试·技术解析·ai集成
ppo921 小时前
MCP简单应用:使用SpringAI + Cline + DeepSeek实现AI创建文件并写入内容
人工智能·后端