我在雨中静思
2018-08-05 11:31
public class IniRealmTest {
//Realm:领域,范围
@Test
public void testAuthentication() {
//路径
IniRealm realm=new IniRealm("classpath:user.ini");
//获取安全管理者对象------DefaultSecurityManager默认管理者
DefaultSecurityManager defaultSecurityManager = new DefaultSecurityManager();
//设置管理者的管理领域
defaultSecurityManager.setRealm(realm);
//SecurityUtils操作securityManager的工具类,提供了getSecurityManager和setSecurityManger,getSubject的方法
//此处是给工具类默认管理者对象
SecurityUtils.setSecurityManager(defaultSecurityManager);
//获取Subject对象,可以进行login 登陆 和logout 登出方法
Subject subject = SecurityUtils.getSubject();
//用户+密码的token令牌
UsernamePasswordToken token = new UsernamePasswordToken("mark", "123");
//登入
subject.login(token);
//如果token中的密码和用户名,在上面的用户中,那么会返回true,反之则是false
System.out.println("isAuthenticated:" + subject.isAuthenticated());
subject.checkRole("admin");
subject.checkPermission("user:delete");
//登出
subject.logout();
//因为登出了,会返回false
System.out.println("isAuthenticated:" + subject.isAuthenticated());
}
}
user.ini
[users]
mark=123,admin
[roles]
admin=user:delete
在ini文件中用户、角色、权限的配置规则是:“用户名=密码,角色1,角色2...” “角色=权限1,权限2...”,首先根据用户名找角色,再根据角色找权限,角色是权限集合。
配置里要这样配
UsernamePasswordToken token =new UsernamePasswordToken("hyz","123456",false);
在token中设置不记住密码
楼主解决这个问题了吗?我也出现了同样的问题,求解!
我的代码和你差不多,在eclipse中没问题啊。。。
你的代码粘贴到我IDEA里面是好用的!!
没看出来有错!!神奇了
异常是:
org.apache.shiro.authz.UnauthorizedException: Subject does not have role [admin]
at org.apache.shiro.authz.ModularRealmAuthorizer.checkRole(ModularRealmAuthorizer.java:421)
at org.apache.shiro.mgt.AuthorizingSecurityManager.checkRole(AuthorizingSecurityManager.java:165)
at org.apache.shiro.subject.support.DelegatingSubject.checkRole(DelegatingSubject.java:245)
at com.work.com.shiro.IniRealmTest.testAuthentication(IniRealmTest.java:37)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
at java.lang.reflect.Method.invoke(Method.java:601)
at org.junit.runners.model.FrameworkMethod$1.runReflectiveCall(FrameworkMethod.java:50)
at org.junit.internal.runners.model.ReflectiveCallable.run(ReflectiveCallable.java:12)
at org.junit.runners.model.FrameworkMethod.invokeExplosively(FrameworkMethod.java:47)
at org.junit.internal.runners.statements.InvokeMethod.evaluate(InvokeMethod.java:17)
at org.junit.runners.ParentRunner.runLeaf(ParentRunner.java:325)
at org.junit.runners.BlockJUnit4ClassRunner.runChild(BlockJUnit4ClassRunner.java:78)
at org.junit.runners.BlockJUnit4ClassRunner.runChild(BlockJUnit4ClassRunner.java:57)
at org.junit.runners.ParentRunner$3.run(ParentRunner.java:290)
at org.junit.runners.ParentRunner$1.schedule(ParentRunner.java:71)
at org.junit.runners.ParentRunner.runChildren(ParentRunner.java:288)
at org.junit.runners.ParentRunner.access$000(ParentRunner.java:58)
at org.junit.runners.ParentRunner$2.evaluate(ParentRunner.java:268)
at org.junit.runners.ParentRunner.run(ParentRunner.java:363)
at org.eclipse.jdt.internal.junit4.runner.JUnit4TestReference.run(JUnit4TestReference.java:86)
at org.eclipse.jdt.internal.junit.runner.TestExecution.run(TestExecution.java:38)
at org.eclipse.jdt.internal.junit.runner.RemoteTestRunner.runTests(RemoteTestRunner.java:459)
at org.eclipse.jdt.internal.junit.runner.RemoteTestRunner.runTests(RemoteTestRunner.java:675)
at org.eclipse.jdt.internal.junit.runner.RemoteTestRunner.run(RemoteTestRunner.java:382)
at org.eclipse.jdt.internal.junit.runner.RemoteTestRunner.main(RemoteTestRunner.java:192)
控制台打印:
[main] INFO org.apache.shiro.session.mgt.AbstractValidatingSessionManager - Enabling session validation scheduler...
isAuthenticated:true
Shiro安全框架入门
48040 学习 · 332 问题
相似问题