springboot 拦截器

拦截器

bash 复制代码
import org.springframework.http.HttpStatus;
import org.springframework.stereotype.Component;
import org.springframework.util.StringUtils;
import org.springframework.web.servlet.HandlerInterceptor;

import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

/**
 * 内部微服务调用密钥校验拦截器
 */
@Component
public class InnerServiceAuthInterceptor implements HandlerInterceptor {

    // 建议配置在 application.yml 中,通过 @Value("${inner.service.secret}") 注入
    private static final String INNER_SECRET = "your-pre-shared-key-2026";

    @Override
    public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception {
        String secret = request.getHeader("X-Internal-Secret");

        // 校验 Header 中是否包含合法密钥
        if (StringUtils.hasText(secret) && INNER_SECRET.equals(secret)) {
            return true; // 校验通过,放行
        }

        // 校验失败,直接拒绝访问
        response.setStatus(HttpStatus.FORBIDDEN.value());
        response.setContentType("application/json;charset=UTF-8");
        response.getWriter().write("{\"code\": 403, \"msg\": \"非法访问:缺少或无效的内部服务调用凭证\"}");
        return false;
    }
}

拦截器配置

bash 复制代码
import cn.dev33.satoken.stp.StpUtil;
import com.huayi.iepms.common.interceptor.FileSecurityInterceptor;
import com.huayi.iepms.common.config.IepmsConfig;
import com.huayi.iepms.common.constant.GenConstants;
import com.huayi.iepms.common.interceptor.InnerServiceAuthInterceptor;
import com.huayi.security.authentication.AuthorizationInterceptor;
import com.huayi.security.authentication.SecurityUserContext;
import com.huayi.web.utils.utils.CommonUtils;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.context.annotation.Lazy;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.web.servlet.config.annotation.InterceptorRegistry;
import org.springframework.web.servlet.config.annotation.ResourceHandlerRegistry;
import org.springframework.web.servlet.config.annotation.WebMvcConfigurer;

import javax.annotation.Resource;

/**
 * @Author:zrf
 * @Date:2023/09/04 15:00
 * @description:配置 Spring MVC 拦截器
 */
@Configuration
public class WebMvcConfiguration implements WebMvcConfigurer {

    @Resource
    private InnerServiceAuthInterceptor innerServiceAuthInterceptor;

    @Override
    public void addResourceHandlers(ResourceHandlerRegistry registry) {
        registry.addResourceHandler(GenConstants.RESOURCE_PREFIX + "/**")
                .addResourceLocations("file:" + IepmsConfig.getProfile() + "/");
    }

    /**
     * 注册权限认证拦截器
     *
     * @param registry 拦截器注册器
     **/
    @Override
    public void addInterceptors(InterceptorRegistry registry) {
        registry.addInterceptor(innerServiceAuthInterceptor)
                // 只拦截指定路径下的接口
                .addPathPatterns("/file/**");

        WebMvcConfigurer.super.addInterceptors(registry);
    }

}
相关推荐
小辰爱喝汤3 小时前
新闻管理系统|SpringBoot + Vue 毕业设计完整方案
spring boot·毕业设计·课程设计
FYKJ_20103 小时前
springboot助农产品销售商城05829-计算机课程设计、毕业设计
java·spring boot·python·mysql·spark·django
Ticnix4 小时前
RAG 烂大街?烂大街的只是那条流水线——真正的分水岭在这五处
后端·python·agent
Wx-bishekaifayuan4 小时前
springboot社区扶贫救助管理系统13300-计算机课程设计、毕业设计
spring boot·后端·python·django·课程设计·express·旅游
DolphinDB5 小时前
数据库自带 Agent:10 分钟搭起 DolphinX-Web 数据入库与分析框架
后端·架构
弈栈录5 小时前
基于 Spring Boot 构建生产级 AI 应用平台
后端·面试·架构
小小张说故事5 小时前
LightGBM 入门指南:更快的梯度提升树,Python 实战
后端·python·机器学习
站大爷IP5 小时前
Python的默认参数把我坑惨了,原来写[]和写None的区别这么大
后端
Ticnix5 小时前
RAG 检索不准,九成的锅不在向量——不同文件,就该有不同的入库方案
后端·python·agent
福兮说5 小时前
Go 优雅退出:Shutdown 之后,后台 goroutine 还在跑(四个实测的坑)
后端·go