惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Project Zero
Project Zero
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
P
Proofpoint News Feed
量子位
K
Kaspersky official blog
S
SegmentFault 最新的问题
博客园 - 叶小钗
博客园 - 司徒正美
酷 壳 – CoolShell
酷 壳 – CoolShell
Hugging Face - Blog
Hugging Face - Blog
博客园 - Franky
F
Fortinet All Blogs
Scott Helme
Scott Helme
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
Cisco Blogs
T
Tenable Blog
U
Unit 42
S
Schneier on Security
T
The Blog of Author Tim Ferriss
G
Google Developers Blog
C
Cybersecurity and Infrastructure Security Agency CISA
V
Visual Studio Blog
The Hacker News
The Hacker News
Jina AI
Jina AI
Stack Overflow Blog
Stack Overflow Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
I
Intezer
Cyberwarzone
Cyberwarzone
Know Your Adversary
Know Your Adversary
V
Vulnerabilities – Threatpost
L
LINUX DO - 热门话题
Spread Privacy
Spread Privacy
T
The Exploit Database - CXSecurity.com
V
V2EX
Help Net Security
Help Net Security
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 聂微东
大猫的无限游戏
大猫的无限游戏
www.infosecurity-magazine.com
www.infosecurity-magazine.com
PCI Perspectives
PCI Perspectives
腾讯CDC
Webroot Blog
Webroot Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
N
News | PayPal Newsroom
Recorded Future
Recorded Future
D
DataBreaches.Net
阮一峰的网络日志
阮一峰的网络日志
C
Check Point Blog

博客园 - lodestar

一张图掌握数据存储 使用xtrabackup实现mysql定时热备份 开发篇1:使用原生api和Langchain调用大模型 预热篇2:从RNN到Transformmer 预热篇1:大模型训练显卡选型 macbook安装scala、hadoop、saprk环境 centos6.5 squid安装 一次linux服务器黑客入侵后处理 linux上搭建svn服务器 Windows系统下Oracle每天自动备份 android中listView的几点总结 使用template method模式简化android列表页面 andorid进度条使用 andorid定时器应用 - lodestar Android网络应用(第一部分) - lodestar 错误数据导致java.lang.IllegalArgumentException:Unsupported configuration attributes 使用ACEGI搭建权限系统:第三部分 使用ACEGI实现权限控制,第一部分 ajax实现用户名存在校验
acegi安全框架使用:第二部分
lodestar · 2011-12-31 · via 博客园 - lodestar

二、dbms实现鉴权
1.dbms鉴权,修改FilterSecurityInterceptor中的objectDefinitionSource属性,注入rdbmsFilterInvocationDefinitionSource,可加入Ehcahe提高性能
<!-- 权限过滤,基于URL的过滤器,使用RDBMS和Ehcache实现 -->
 <bean id="securityInterceptor"
  class="org.acegisecurity.intercept.web.FilterSecurityInterceptor">
  <!-- 修改默认值,防止没有授权的角色导致的错误 -->
  <property name="validateConfigAttributes" value="true" />
  <property name="authenticationManager" ref="authenticationManager" />
  <property name="accessDecisionManager" ref="accessDecisionManager" />
  <property name="objectDefinitionSource" ref="rdbmsFilterInvocationDefinitionSource" />
 </bean>
 <bean id="rdbmsFilterInvocationDefinitionSource" class="com.hengtian.security.RdbmsFilterInvocationDefinitionSource">
  <property name="dataSource" ref="dataSource" />
  <property name="webresdbCache" ref="webresCacheBackend" />
 </bean>
 
 <bean id="webresCacheBackend" class="org.springframework.cache.ehcache.EhCacheFactoryBean">
  <property name="cacheManager" ref="cacheManager" />
  <property name="cacheName">
   <value>webresdbCache</value>
  </property>
 </bean>

RdbmsFilterInvocationDefinitionSource是objectDefinitionSource的dbms实现,这个要自己实现


2.aop实现方法过滤
 如果不想对action,url等资源过滤,也可对调用方法过滤,实现特定角色只能实现特定方法。在applicationContext.xml中配置,注意这里是用BeanNameAutoProxyCreator实现aop的.
  <bean id="serviceSecurityInterceptor"
  class="org.acegisecurity.intercept.method.aopalliance.MethodSecurityInterceptor">
  <property name="validateConfigAttributes" value="true" /> <property
  name="authenticationManager" ref="authenticationManager" /> <property
  name="accessDecisionManager" ref="accessDecisionManager" /> <property
  name="objectDefinitionSource"> <value>
  com.role.action.RoleAction.operateRole=ROLE_ADMIN </value> </property>
  </bean>
 

 <bean id="serviceSecurityInterceptor"
  class="org.acegisecurity.intercept.method.aopalliance.MethodSecurityInterceptor">
  <property name="validateConfigAttributes" value="true" />
  <property name="authenticationManager" ref="authenticationManager" />
  <property name="accessDecisionManager" ref="accessDecisionManager" />
  <property name="objectDefinitionSource" ref="rdbmsMethodDefinitionSource" />
 </bean>
 <bean id="rdbmsMethodDefinitionSource" class="com.hengtian.security.RdbmsMethodDefinitionSource">
  <property name="dataSource" ref="dataSource" />
  <property name="webresdbCache" ref="webresCacheBackend" />
 </bean>
 <bean id="webresCacheBackend" class="org.springframework.cache.ehcache.EhCacheFactoryBean">
  <property name="cacheManager" ref="cacheManager" />
  <property name="cacheName">
   <value>webresdbCache</value>
  </property>
 </bean>

 <bean id="autoProxyCreator"
  class="org.springframework.aop.framework.autoproxy.BeanNameAutoProxyCreator">
  <property name="interceptorNames">
   <list>
    <value>serviceSecurityInterceptor</value>
   </list>
  </property>
  <property name="beanNames">
   <list>
    <value>*Action</value>
   </list>
  </property>
 </bean>

3.表结构设置
 按照常规的权限模型设计:用户表、角色表、用户角色关系表、角色功能关系表;系统表、模块表、菜单表、按钮表、按钮资源表(在一个操作做个url的情况使用)
 权限这块的表结构所有的系统都查不多,这里只是在功能表里面多加上了url字段。对外显示为特定角色有执行某模块、某菜单、界面中的某个按钮的权限,对内则是某个角色和action的映射关系供acegi鉴权使用