Commit 03c44fd8 authored by AfirSraftGarrier's avatar AfirSraftGarrier

Merge branch 'for-yx' of http://120.77.240.215:9701/tianlai3/ioc_sixiang_license into for-yx

parents 1ded2b7a 0d1e7daa
...@@ -4,6 +4,7 @@ import com.auth0.jwt.interfaces.Claim; ...@@ -4,6 +4,7 @@ import com.auth0.jwt.interfaces.Claim;
import com.auth0.jwt.interfaces.DecodedJWT; import com.auth0.jwt.interfaces.DecodedJWT;
import iot.sixiang.license.xss.XssUtil; import iot.sixiang.license.xss.XssUtil;
import lombok.extern.slf4j.Slf4j; import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Value;
import org.springframework.util.StringUtils; import org.springframework.util.StringUtils;
import javax.servlet.*; import javax.servlet.*;
...@@ -34,9 +35,9 @@ public class JwtFilter implements Filter { ...@@ -34,9 +35,9 @@ public class JwtFilter implements Filter {
public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException { public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {
final HttpServletRequest request = (HttpServletRequest) servletRequest; final HttpServletRequest request = (HttpServletRequest) servletRequest;
final HttpServletResponse response = (HttpServletResponse) servletResponse; final HttpServletResponse response = (HttpServletResponse) servletResponse;
response.setHeader("Set-Cookie","cookiename=cookievalue; path=/; Domain=domainvaule; Max-age=seconds; HttpOnly"); response.setHeader("Set-Cookie", "cookiename=cookievalue; path=/; Domain=domainvaule; Max-age=seconds; HttpOnly");
response.setContentType("text/html; charset=utf-8"); response.setContentType("text/html; charset=utf-8");
if ("OPTIONS".equals(request.getMethod()) || "HEAD".equals(request.getMethod())) { if (!"GET".equals(request.getMethod()) && !"POST".equals(request.getMethod())) {
response.setStatus(HttpServletResponse.SC_METHOD_NOT_ALLOWED); response.setStatus(HttpServletResponse.SC_METHOD_NOT_ALLOWED);
ServletOutputStream outputStream = response.getOutputStream(); ServletOutputStream outputStream = response.getOutputStream();
outputStream.write(new String("不安全的请求".getBytes(), StandardCharsets.UTF_8).getBytes()); outputStream.write(new String("不安全的请求".getBytes(), StandardCharsets.UTF_8).getBytes());
...@@ -48,7 +49,7 @@ public class JwtFilter implements Filter { ...@@ -48,7 +49,7 @@ public class JwtFilter implements Filter {
boolean check = true; boolean check = true;
String uri = request.getRequestURI(); String uri = request.getRequestURI();
if (uri.contains(url1)|| uri.contains(url2) || uri.contains(url3) || uri.contains(url4) || uri.contains(url7) || uri.contains(url8)) { if (uri.contains(url1) || uri.contains(url2) || uri.contains(url3) || uri.contains(url4) || uri.contains(url7) || uri.contains(url8)) {
if (uri.contains(url1)) { if (uri.contains(url1)) {
uri = XssUtil.checkXSS(uri); uri = XssUtil.checkXSS(uri);
UserUtils.setUri(uri); UserUtils.setUri(uri);
...@@ -61,18 +62,18 @@ public class JwtFilter implements Filter { ...@@ -61,18 +62,18 @@ public class JwtFilter implements Filter {
} }
if (StringUtils.isEmpty(token)) { if (StringUtils.isEmpty(token)) {
request.setAttribute("msg","认证信息不能为空"); request.setAttribute("msg", "认证信息不能为空");
request.getRequestDispatcher("/fail").forward(request, response); request.getRequestDispatcher("/iot_license/fail").forward(request, response);
} else { } else {
DecodedJWT jwt = JwtUtil.verifyToken(token); DecodedJWT jwt = JwtUtil.verifyToken(token);
if (jwt == null) { if (jwt == null) {
request.setAttribute("msg","认证信息非法"); request.setAttribute("msg", "认证信息非法");
request.getRequestDispatcher("/fail").forward(request, response); request.getRequestDispatcher("/iot_license/fail").forward(request, response);
} else { } else {
Map<String, Claim> userData = jwt.getClaims(); Map<String, Claim> userData = jwt.getClaims();
if (userData == null) { if (userData == null) {
request.setAttribute("msg","认证信息非法"); request.setAttribute("msg", "认证信息非法");
request.getRequestDispatcher("/fail").forward(request, response); request.getRequestDispatcher("/iot_license/fail").forward(request, response);
return; return;
} }
String userId = userData.get("userId").asString(); String userId = userData.get("userId").asString();
...@@ -88,8 +89,8 @@ public class JwtFilter implements Filter { ...@@ -88,8 +89,8 @@ public class JwtFilter implements Filter {
} else { } else {
UserUtils.removeToken(userId); UserUtils.removeToken(userId);
UserUtils.removeTokenExp(userId); UserUtils.removeTokenExp(userId);
request.setAttribute("msg","token已失效"); request.setAttribute("msg", "token已失效");
request.getRequestDispatcher("/fail").forward(request, response); request.getRequestDispatcher("/iot_license/fail").forward(request, response);
} }
} }
} }
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment