¶Ô±ÈÐÂÎļþ |
| | |
| | | /* |
| | | * Copyright (c) 2018-2028, Chill Zhuang All rights reserved. |
| | | * |
| | | * Redistribution and use in source and binary forms, with or without |
| | | * modification, are permitted provided that the following conditions are met: |
| | | * |
| | | * Redistributions of source code must retain the above copyright notice, |
| | | * this list of conditions and the following disclaimer. |
| | | * Redistributions in binary form must reproduce the above copyright |
| | | * notice, this list of conditions and the following disclaimer in the |
| | | * documentation and/or other materials provided with the distribution. |
| | | * Neither the name of the dreamlu.net developer nor the names of its |
| | | * contributors may be used to endorse or promote products derived from |
| | | * this software without specific prior written permission. |
| | | * Author: Chill åºéª (smallchill@163.com) |
| | | */ |
| | | package org.springblade.core.secure.interceptor; |
| | | |
| | | import lombok.AllArgsConstructor; |
| | | import lombok.extern.slf4j.Slf4j; |
| | | import org.springblade.core.secure.props.SignSecure; |
| | | import org.springblade.core.secure.provider.HttpMethod; |
| | | import org.springblade.core.secure.provider.ResponseProvider; |
| | | import org.springblade.core.tool.jackson.JsonUtil; |
| | | import org.springblade.core.tool.utils.DateUtil; |
| | | import org.springblade.core.tool.utils.DigestUtil; |
| | | import org.springblade.core.tool.utils.Func; |
| | | import org.springblade.core.tool.utils.WebUtil; |
| | | import org.springframework.lang.NonNull; |
| | | import org.springframework.util.AntPathMatcher; |
| | | import org.springframework.web.servlet.handler.HandlerInterceptorAdapter; |
| | | |
| | | import javax.servlet.http.HttpServletRequest; |
| | | import javax.servlet.http.HttpServletResponse; |
| | | import java.time.Duration; |
| | | import java.util.Date; |
| | | import java.util.List; |
| | | |
| | | /** |
| | | * ç¾åè®¤è¯æ¦æªå¨æ ¡éª |
| | | * |
| | | * @author Chill |
| | | */ |
| | | @Slf4j |
| | | @AllArgsConstructor |
| | | public class SignInterceptor extends HandlerInterceptorAdapter { |
| | | |
| | | /** |
| | | * 表达å¼å¹é
|
| | | */ |
| | | private static final AntPathMatcher ANT_PATH_MATCHER = new AntPathMatcher(); |
| | | |
| | | /** |
| | | * ææéå |
| | | */ |
| | | private final List<SignSecure> signSecures; |
| | | |
| | | /** |
| | | * è¯·æ±æ¶é´ |
| | | */ |
| | | private final static String TIMESTAMP = "timestamp"; |
| | | |
| | | /** |
| | | * éæºæ° |
| | | */ |
| | | private final static String NONCE = "nonce"; |
| | | |
| | | /** |
| | | * æ¶é´éæºæ°ç»åå å¯ä¸² |
| | | */ |
| | | private final static String SIGNATURE = "signature"; |
| | | |
| | | /** |
| | | * sha1å 坿¹å¼ |
| | | */ |
| | | private final static String SHA1 = "sha1"; |
| | | |
| | | /** |
| | | * md5å 坿¹å¼ |
| | | */ |
| | | private final static String MD5 = "md5"; |
| | | |
| | | /** |
| | | * æ¶é´å·®æå°å¼ |
| | | */ |
| | | private final static Integer SECOND_MIN = 0; |
| | | |
| | | /** |
| | | * æ¶é´å·®æå¤§å¼ |
| | | */ |
| | | private final static Integer SECOND_MAX = 10; |
| | | |
| | | @Override |
| | | public boolean preHandle(@NonNull HttpServletRequest request, @NonNull HttpServletResponse response, @NonNull Object handler) { |
| | | boolean check = signSecures.stream().filter(signSecure -> checkAuth(request, signSecure)).findFirst().map( |
| | | authSecure -> checkSign(authSecure.getCrypto()) |
| | | ).orElse(Boolean.TRUE); |
| | | if (!check) { |
| | | log.warn("ææè®¤è¯å¤±è´¥ï¼è¯·æ±æ¥å£ï¼{}ï¼è¯·æ±IPï¼{}ï¼è¯·æ±åæ°ï¼{}", request.getRequestURI(), WebUtil.getIP(request), JsonUtil.toJson(request.getParameterMap())); |
| | | ResponseProvider.write(response); |
| | | return false; |
| | | } |
| | | return true; |
| | | } |
| | | |
| | | /** |
| | | * æ£æµææ |
| | | */ |
| | | private boolean checkAuth(HttpServletRequest request, SignSecure signSecure) { |
| | | return checkMethod(request, signSecure.getMethod()) && checkPath(request, signSecure.getPattern()); |
| | | } |
| | | |
| | | /** |
| | | * æ£æµè¯·æ±æ¹æ³ |
| | | */ |
| | | private boolean checkMethod(HttpServletRequest request, HttpMethod method) { |
| | | return method == HttpMethod.ALL || ( |
| | | method != null && method == HttpMethod.of(request.getMethod()) |
| | | ); |
| | | } |
| | | |
| | | /** |
| | | * æ£æµè·¯å¾å¹é
|
| | | */ |
| | | private boolean checkPath(HttpServletRequest request, String pattern) { |
| | | String servletPath = request.getServletPath(); |
| | | String pathInfo = request.getPathInfo(); |
| | | if (pathInfo != null && pathInfo.length() > 0) { |
| | | servletPath = servletPath + pathInfo; |
| | | } |
| | | return ANT_PATH_MATCHER.match(pattern, servletPath); |
| | | } |
| | | |
| | | /** |
| | | * æ£æµè¡¨è¾¾å¼ |
| | | */ |
| | | private boolean checkSign(String crypto) { |
| | | try { |
| | | HttpServletRequest request = WebUtil.getRequest(); |
| | | if (request == null) { |
| | | return false; |
| | | } |
| | | // è·å头é¨å¨æç¾åä¿¡æ¯ |
| | | String timestamp = request.getHeader(TIMESTAMP); |
| | | // 夿æ¯å¦å¨åæ³æ¶é´æ®µ |
| | | long seconds = Duration.between(new Date(Func.toLong(timestamp)).toInstant(), DateUtil.now().toInstant()).getSeconds(); |
| | | if (seconds < SECOND_MIN || seconds > SECOND_MAX) { |
| | | log.warn("ææè®¤è¯å¤±è´¥ï¼é误信æ¯ï¼{}", "è¯·æ±æ¶é´æ³éæ³"); |
| | | return false; |
| | | } |
| | | String nonce = request.getHeader(NONCE); |
| | | String signature = request.getHeader(SIGNATURE); |
| | | // å å¯ç¾åæ¯å¯¹ï¼å¯èªè¡æå±å å¯è§å |
| | | String sign; |
| | | if (crypto.equals(MD5)) { |
| | | sign = DigestUtil.md5Hex(timestamp + nonce); |
| | | } else if (crypto.equals(SHA1)) { |
| | | sign = DigestUtil.sha1Hex(timestamp + nonce); |
| | | } else { |
| | | sign = DigestUtil.sha1Hex(timestamp + nonce); |
| | | } |
| | | return sign.equalsIgnoreCase(signature); |
| | | } catch (Exception e) { |
| | | log.warn("ææè®¤è¯å¤±è´¥ï¼é误信æ¯ï¼{}", e.getMessage()); |
| | | return false; |
| | | } |
| | | } |
| | | |
| | | |
| | | } |