Shiro內(nèi)置Realm
- IniRealm
-
JdbcRealm
happy
IniRealm
主要是將數(shù)據(jù)存放到相應(yīng)的xxx.ini即文件系統(tǒng)中,從文件中查找相應(yīng)的數(shù)據(jù)是否存在。
本文中文件放置在系統(tǒng)類路徑下
認(rèn)證userAuthenticator.ini
#用來認(rèn)證
#============================
#設(shè)置用戶,可設(shè)置多名用戶
[users]
jarworker=123
小明=1234
授權(quán)userAuthorizer.ini
#用來授權(quán)
#===========================
#設(shè)置用戶及用戶角色
[users]
jarworker=123,admin
#設(shè)置角色與角色權(quán)限
[roles]
admin=user:delete,user:update
tourist=user:query
maven依賴
<dependency>
<groupId>org.apache.shiro</groupId>
<artifactId>shiro-core</artifactId>
<version>1.4.0</version>
</dependency>
<dependency>
<groupId>junit</groupId>
<artifactId>junit</artifactId>
<version>4.12</version>
</dependency>
測試用例
package com.jarworker.test;
import org.apache.shiro.SecurityUtils;
import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.mgt.DefaultSecurityManager;
import org.apache.shiro.realm.text.IniRealm;
import org.apache.shiro.subject.Subject;
import org.junit.Before;
import org.junit.Test;
/**
* Shiro的IniRealm
*/
public class IniRealmTest {
IniRealm iniRealm;
IniRealm iniRealm_1;
@Before
public void addIniRealmTestUser() throws Exception {
iniRealm=new IniRealm("classpath:userAuthenticator.ini");//認(rèn)證
iniRealm_1=new IniRealm("classpath:userAuthorizer.ini");//授權(quán)
}
/**
* 認(rèn)證過程
* @throws Exception
*/
@Test
public void testIniRealmAuthenticator() throws Exception {
//構(gòu)建DefaultSecurityManager 環(huán)境
DefaultSecurityManager defaultSecurityManager = new DefaultSecurityManager();
defaultSecurityManager.setRealm(iniRealm);
//主體提交認(rèn)證請求
SecurityUtils.setSecurityManager(defaultSecurityManager);
Subject subject = SecurityUtils.getSubject();
UsernamePasswordToken token = new UsernamePasswordToken("小明","1234");
subject.login(token);
System.out.println("是否認(rèn)證:"+subject.isAuthenticated());
}
/**
* 授權(quán)過程
* @throws Exception
*/
@Test
public void testIniRealmAuthorizer() throws Exception {
//構(gòu)建DefaultSecurityManager 環(huán)境
DefaultSecurityManager defaultSecurityManager = new DefaultSecurityManager();
defaultSecurityManager.setRealm(iniRealm_1);
//主體提交認(rèn)證請求
SecurityUtils.setSecurityManager(defaultSecurityManager);
Subject subject = SecurityUtils.getSubject();
UsernamePasswordToken token = new UsernamePasswordToken("jarworker","123");
subject.login(token);
System.out.println("是否認(rèn)證:"+subject.isAuthenticated());
subject.checkRoles("admin");
subject.checkPermission("user:delete");//是否擁有刪除的權(quán)限
subject.checkPermission("user:update");//是否擁有更新的權(quán)限
}
}
