package com.zy.common.config;
|
|
import com.core.annotations.ManagerAuth;
|
import com.core.common.BaseRes;
|
import com.core.common.Cools;
|
import com.zy.common.utils.Http;
|
import org.springframework.beans.factory.annotation.Value;
|
import org.springframework.lang.Nullable;
|
import org.springframework.stereotype.Component;
|
import org.springframework.web.method.HandlerMethod;
|
import org.springframework.web.servlet.ModelAndView;
|
import org.springframework.web.servlet.handler.HandlerInterceptorAdapter;
|
|
import javax.servlet.http.HttpServletRequest;
|
import javax.servlet.http.HttpServletResponse;
|
import java.lang.reflect.Method;
|
|
/**
|
* Created by vincent on 2019-06-13
|
*/
|
@Component
|
public class AdminInterceptor extends HandlerInterceptorAdapter {
|
|
@Value("${super.pwd}")
|
private String superPwd;
|
|
|
@Override
|
public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception {
|
cors(response);
|
if (handler instanceof org.springframework.web.servlet.resource.ResourceHttpRequestHandler) {
|
return true;
|
}
|
// super账号
|
String token = request.getHeader("token");
|
if (token!=null) {
|
String deToken = Cools.deTokn(token, superPwd);
|
if (deToken!=null){
|
long timestamp = Long.parseLong(deToken.substring(0, 13));
|
// 1天后过期
|
if (System.currentTimeMillis() - timestamp > 86400000){
|
Http.response(response, BaseRes.DENIED);
|
return false;
|
}
|
if ("super".equals(deToken.substring(13))) {
|
request.setAttribute("userId", 9527);
|
return true;
|
}
|
}
|
}
|
// 跨域设置
|
// response.setHeader("Access-Control-Allow-Origin", "*");
|
HandlerMethod handlerMethod = (HandlerMethod) handler;
|
Method method = handlerMethod.getMethod();
|
if (method.isAnnotationPresent(ManagerAuth.class)){
|
ManagerAuth annotation = method.getAnnotation(ManagerAuth.class);
|
if (annotation.value().equals(ManagerAuth.Auth.CHECK)){
|
return check(request, response, annotation.memo());
|
}
|
}
|
return true;
|
}
|
|
@Override
|
public void postHandle(HttpServletRequest request, HttpServletResponse response, Object handler, @Nullable ModelAndView modelAndView) {
|
// Object obj = request.getAttribute("operateLog");
|
// if (obj instanceof OperateLog) {
|
// OperateLog operate = (OperateLog) obj;
|
// operate.setResponse(String.valueOf(response.getStatus()));
|
// operateLogService.insert(operate);
|
// }
|
}
|
|
private boolean check(HttpServletRequest request, HttpServletResponse response, String memo) {
|
return true;
|
}
|
|
|
|
/**
|
* 跨域
|
*/
|
private void cors(HttpServletResponse response){
|
// 跨域设置
|
response.setHeader("Access-Control-Allow-Origin", "*");
|
response.setHeader("Access-Control-Allow-Credentials", "true");
|
response.setHeader("Access-Control-Allow-Methods", "*");
|
response.setHeader("Access-Control-Allow-Headers", "Content-Type,Access-Token");
|
response.setHeader("Access-Control-Expose-Headers", "*");
|
|
}
|
|
}
|