1. 程式人生 > >Windows 下Maven+Tomcat 8 使用JAVA以及 Json Web Token 實現 單點登入demo

Windows 下Maven+Tomcat 8 使用JAVA以及 Json Web Token 實現 單點登入demo

0.準備工作

如果你本地環境都OK,可以跳過。

1.簡介

json web token(JWT)是一種新的使用者認證方式,不同與以前的Session.

JWT不需要伺服器端儲存使用者資訊,當用戶登入後,伺服器將使用者資訊放入加密放入token(token會被客戶端儲存),需要時再通過對token解密獲取(客戶請求時攜帶token)

2.程式碼

下面提供一種JWT的簡單實現.這個例子實現的功能是:

1) 使用者訪問login.jsp進行登入操作.

這裡寫圖片描述
這裡寫圖片描述
則發放給使用者本地瀏覽器的token為:

eyJhbGciOiJIUzI1NiJ9.eyJqdGkiOiIxIiwiaWF
0IjoxNTIyMjUzMTIwLCJzdWIiOiLmtYvor5XnlKjmiLcxIiwiZXhwIjoxNTIyMjUzNzIwfQ.5jWbc4yP11Qfz1T5HHAjFpgNWCtYyTwOmMB8rTZAY4s

在本地客戶端查詢 Chrome 瀏覽器 F12
這裡寫圖片描述

與伺服器傳送一致,且有失效時間標註,證明發放成功。

2) 使用者訪問myServlet時,若使用者已登入則跳轉至info.jsp顯示使用者名稱,未登入則跳轉至login.jsp.

等待一分鐘後,token失效,再次訪問此路徑。
返回登入頁面

這裡寫圖片描述

ps:這個demo是基於最基本的serlvet,jsp實現的,僅供參考,實際開發中並不會這麼玩~

login.jsp

<%@ page language="java" contentType="text/html; charset=UTF-8"  
    pageEncoding="UTF-8"%>  
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">  
<html>  
<head>  
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8"
>
<title>Insert title here</title> </head> <body> <form action="Servlet/myServlet" method="post"> 帳號:<input type="text" name="account"> 密碼:<input type="password" name="password"> <input type="submit" value="登入"> </form> </body> </html>

MyServlet.java

package com.hxuhao.servlet;  

import java.io.IOException;  
import java.io.PrintWriter;  
import java.util.HashMap;  
import java.util.Map.Entry;  

import javax.servlet.ServletException;  
import javax.servlet.annotation.WebServlet;  
import javax.servlet.http.Cookie;  
import javax.servlet.http.HttpServlet;  
import javax.servlet.http.HttpServletRequest;  
import javax.servlet.http.HttpServletResponse;  

import com.hxuhao.model.User;  
import com.hxuhao.utils.JWTUtil;  

import io.jsonwebtoken.Claims;  

/** 
 * Servlet implementation class MyServlet 
 */  
@WebServlet("/MyServlet")  
public class MyServlet extends HttpServlet {  
    private static final long serialVersionUID = 1L;  
       <span style="white-space:pre;">  </span>// 模擬的資料庫  
    private HashMap<Integer,User> users = new HashMap<>();  
    @Override  
    public void init() throws ServletException {  
        // TODO Auto-generated method stub  
        super.init();  
        users.put(Integer.valueOf(1), new User(1,"test1","123","測試使用者1"));  
        users.put(Integer.valueOf(2), new User(2,"test2","123","測試使用者2"));  
    }  

    /** 
     * @see HttpServlet#service(HttpServletRequest request, HttpServletResponse response) 
     */  
    protected void service(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {  
        // TODO Auto-generated method stub  
        request.setCharacterEncoding("utf-8");  
        response.setCharacterEncoding("utf-8");  
        if(request.getMethod().equals("POST")){  
            doPost(request, response);  
        }else{  
            doGet(request, response);  
        }  
    }  

    /** 
     * 檢視資訊 
     * @see HttpServlet#doGet(HttpServletRequest request, HttpServletResponse response) 
     */  
    protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {  
        // TODO Auto-generated method stub  
        //response.getWriter().append("Served at: ").append(request.getContextPath());  
        // 驗證使用者  
        Cookie[] cookies =  request.getCookies();  
        //User user=null;  
        String username = null;  
        if(cookies!=null){  
            for(int i=0;i<cookies.length;i++){  
                System.out.println(cookies[i].getName() + " : " + cookies[i].getValue());  
                if(cookies[i].getName().equals("JWT")){  
                    Cookie cookie = cookies[i];  
                    try {  
                        // 檢查token  
                        Claims  claims = JWTUtil.parseJWT(cookie.getValue());  
                        username = claims.getSubject();  
                        System.out.println("name : " + username);  
                    } catch (Exception e) {  
                        // TODO Auto-generated catch block  
                        e.printStackTrace();  
                    }  
                }  
            }  
        }  
        if(username!=null){  
            request.setAttribute("username", username);  
            request.getRequestDispatcher("../info.jsp").forward(request, response);  
        }else{  
            //System.out.println("SendRedirect");  
            response.sendRedirect("../login.jsp");  
        }  
    }  

    /** 
     * 登入 
     * @see HttpServlet#doPost(HttpServletRequest request, HttpServletResponse response) 
     */  
    protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {  
        // TODO Auto-generated method stub  
        String account = request.getParameter("account");  
        String password = request.getParameter("password");  
        System.out.println(account + " : " + password);  
        String token = "";   
        for(Entry<Integer, User> item : users.entrySet()){  
            User u = item.getValue();  
            if(u.getAccount().equals(account)  
                    &&u.getPassword().equals(password)){  
                try {  
                    System.out.println(u.getName());  
                    token = JWTUtil.createJWT(String.valueOf(u.getId()), u.getName(), 1000*60*10);  
                    // 將token放進Cookie  
                    Cookie cookie = new Cookie("JWT", token);  
                    cookie.setPath("/");  
                    // 過期時間設為10min  
                    cookie.setMaxAge(60*10);  
                    response.addCookie(cookie);  
                } catch (Exception e) {  
                    // TODO Auto-generated catch block  
                    e.printStackTrace();  
                }  
            }  
        }  
        PrintWriter pw = response.getWriter();  
        if(!token.equals("")){  
            System.out.println(token);  
            pw.print("login succeed : " + token);  
        }  
        else{  
            pw.print("login failed : error account or password");  
        }  
        pw.flush();  
        pw.close();  
    }  

}  

info.jsp

<%@ page language="java" contentType="text/html; charset=UTF-8"  
    pageEncoding="UTF-8"%>  
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">  
<html>  
<head>  
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">  
<title>Insert title here</title>  
</head>  
<body>  
<h2>Hello,<%=request.getAttribute("username") %></h2>  
</body>  
</html>  

JWTUtil.java

package com.hxuhao.utils;  
import java.util.Date;  

import javax.crypto.SecretKey;  
import javax.crypto.spec.SecretKeySpec;  

import org.apache.commons.codec.binary.Base64;  



import io.jsonwebtoken.Claims;  
import io.jsonwebtoken.JwtBuilder;  
import io.jsonwebtoken.Jwts;  
import io.jsonwebtoken.SignatureAlgorithm;  


public class JWTUtil {  


    private static final String profiles="hxhxhxhxh";  

    /** 
     * 由字串生成加密key 
     * @return 
     */  
    private static SecretKey generalKey(){  
        String stringKey = profiles;  
        byte[] encodedKey = Base64.decodeBase64(stringKey);  
        SecretKey key = new SecretKeySpec(encodedKey, 0, encodedKey.length, "AES");  
        return key;  
    }  

    /** 
     * 建立jwt 
     * @param id 
     * @param subject 
     * @param ttlMillis 
     * @return 
     * @throws Exception 
     */  
    public static String createJWT(String id, String subject, long ttlMillis) throws Exception {  
        SignatureAlgorithm signatureAlgorithm = SignatureAlgorithm.HS256;  
        long nowMillis = System.currentTimeMillis();  
        Date now = new Date(nowMillis);  
        SecretKey key = generalKey();  
        JwtBuilder builder = Jwts.builder()  
            .setId(id)  
            .setIssuedAt(now)  
            .setSubject(subject)  
            .signWith(signatureAlgorithm, key);  
        if (ttlMillis >= 0) {  
            long expMillis = nowMillis + ttlMillis;  
            Date exp = new Date(expMillis);  
            builder.setExpiration(exp);  
        }  
        return builder.compact();  
    }  

    /** 
     * 解析jwt 
     * @param jwt 
     * @return 
     * @throws Exception 
     */  
    public static Claims parseJWT(String jwt) throws Exception{  
        SecretKey key = generalKey();  
        Claims claims = Jwts.parser()           
           .setSigningKey(key)  
           .parseClaimsJws(jwt).getBody();  

        return claims;  
    }  
}  

web.xml

<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xmlns:web="http://xmlns.jcp.org/xml/ns/javaee"
    xsi:schemaLocation="http://xmlns.jcp.org/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd">
    <display-name>Archetype Created Web Application</display-name>
    <servlet>
        <servlet-name>myServlet</servlet-name>
        <servlet-class>com.hxuhao.servlet.MyServlet</servlet-class>
    </servlet>
    <servlet-mapping>
        <servlet-name>myServlet</servlet-name>
        <url-pattern>/Servlet/myServlet</url-pattern>
    </servlet-mapping>

</web-app>