SHIRO学习系列

使用spring的AOP时候,想要过滤掉某些路径或者忽略指定注解,怎么做?

背景:项目使用shiro做安全框架的。现在需要使用SpringAOP切面记录日志。切入点:  @Pointcut("execution(public*com.kaigejava.business..controller..*.*(..))")这样配置会有问题。因为有些地方需要忽略shiro认证。比如在shiroConfig中,我配置了很多。如下: 

背景:

项目使用shiro做安全框架的。现在需要使用Spring AOP切面记录日志。

切入点:

    @Pointcut("execution(public * com.kaigejava.business..controller..*.*(..))")

这样配置会有问题。因为有些地方需要忽略shiro认证。比如在shiroConfig中,我配置了很多。如下:

 filterChainDefinitionMap.put("/diagram-viewer/**", "anon");

        filterChainDefinitionMap.put("/editor-app/**", "anon");

        filterChainDefinitionMap.put("/riskNotificationLetter/download/**", "anon"); //草稿箱下载权限放开

        filterChainDefinitionMap.put("/login/toLogin", "anon");

        filterChainDefinitionMap.put("/homePageSimulationData/**", "anon");

        filterChainDefinitionMap.put("/synchronizationEdataController/**", "anon");

        filterChainDefinitionMap.put("/dayReportController/**", "anon");


同时我在JwtFilter中配置了

   //校验类上有没有此注解。如果类类存在此注解,整个类的url都不会被拦截

            ShiroIgnoreAuth anonymousAccess = AnnotationUtils.getAnnotation(nowClass, ShiroIgnoreAuth.class);

那么我上面的的切入点表达式应该怎么写?

1. 基于路径排除

使用within来指定包,并且使用@annotation或!@annotation来排除带有特定注解的方法。由于你列出的路径在AOP切面中无法直接匹配(因为路径是URL模式,而不是Java包路径),你需要在AOP切面中手动添加排除逻辑。

2. 排除带有注解的类或方法

你可以在AOP中检查方法或类是否带有特定注解,然后根据需要进行处理。

切入点表达式

要只切入controller包中的方法,同时排除特定路径和注解,你可以结合使用多个切入点表达式。

示例代码:

import org.aspectj.lang.JoinPoint;
import org.aspectj.lang.annotation.Aspect;
import org.aspectj.lang.annotation.Before;
import org.aspectj.lang.annotation.Pointcut;
import org.springframework.core.annotation.AnnotationUtils;
import org.springframework.stereotype.Component;
import javax.servlet.http.HttpServletRequest;
import org.springfra

原创不易,完成人机校验,阅读全文

相关推荐