| New file |
| | |
| | | package com.zy.common.config; |
| | | |
| | | import com.zy.acs.framework.annotations.ManagerAuth; |
| | | import com.zy.acs.framework.common.BaseRes; |
| | | import com.zy.acs.framework.common.Cools; |
| | | import com.zy.common.utils.Http; |
| | | import org.springframework.beans.factory.annotation.Value; |
| | | import org.springframework.lang.Nullable; |
| | | import org.springframework.stereotype.Component; |
| | | import org.springframework.web.method.HandlerMethod; |
| | | import org.springframework.web.servlet.ModelAndView; |
| | | import org.springframework.web.servlet.handler.HandlerInterceptorAdapter; |
| | | |
| | | import javax.servlet.http.HttpServletRequest; |
| | | import javax.servlet.http.HttpServletResponse; |
| | | import java.lang.reflect.Method; |
| | | |
| | | /** |
| | | * Created by vincent on 2019-06-13 |
| | | */ |
| | | @Component |
| | | public class AdminInterceptor extends HandlerInterceptorAdapter { |
| | | |
| | | @Value("${super.pwd}") |
| | | private String superPwd; |
| | | |
| | | |
| | | @Override |
| | | public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception { |
| | | cors(response); |
| | | if (handler instanceof org.springframework.web.servlet.resource.ResourceHttpRequestHandler) { |
| | | return true; |
| | | } |
| | | // super账号 |
| | | String token = request.getHeader("token"); |
| | | if (token != null) { |
| | | String deToken = Cools.deTokn(token, superPwd); |
| | | if (deToken != null) { |
| | | long timestamp = Long.parseLong(deToken.substring(0, 13)); |
| | | // 1天后过期 |
| | | if (System.currentTimeMillis() - timestamp > 86400000) { |
| | | Http.response(response, BaseRes.DENIED); |
| | | return false; |
| | | } |
| | | if ("super".equals(deToken.substring(13))) { |
| | | request.setAttribute("userId", 9527); |
| | | return true; |
| | | } |
| | | } |
| | | } |
| | | // 跨域设置 |
| | | // response.setHeader("Access-Control-Allow-Origin", "*"); |
| | | HandlerMethod handlerMethod = (HandlerMethod) handler; |
| | | Method method = handlerMethod.getMethod(); |
| | | if (method.isAnnotationPresent(ManagerAuth.class)) { |
| | | ManagerAuth annotation = method.getAnnotation(ManagerAuth.class); |
| | | if (annotation.value().equals(ManagerAuth.Auth.CHECK)) { |
| | | return check(request, response, annotation.memo()); |
| | | } |
| | | } |
| | | return true; |
| | | } |
| | | |
| | | @Override |
| | | public void postHandle(HttpServletRequest request, HttpServletResponse response, Object handler, @Nullable ModelAndView modelAndView) { |
| | | // Object obj = request.getAttribute("operateLog"); |
| | | // if (obj instanceof OperateLog) { |
| | | // OperateLog operate = (OperateLog) obj; |
| | | // operate.setResponse(String.valueOf(response.getStatus())); |
| | | // operateLogService.insert(operate); |
| | | // } |
| | | } |
| | | |
| | | private boolean check(HttpServletRequest request, HttpServletResponse response, String memo) { |
| | | return true; |
| | | } |
| | | |
| | | |
| | | /** |
| | | * 跨域 |
| | | */ |
| | | private void cors(HttpServletResponse response) { |
| | | // 跨域设置 |
| | | response.setHeader("Access-Control-Allow-Origin", "*"); |
| | | response.setHeader("Access-Control-Allow-Credentials", "true"); |
| | | response.setHeader("Access-Control-Allow-Methods", "*"); |
| | | response.setHeader("Access-Control-Allow-Headers", "Content-Type,Access-Token"); |
| | | response.setHeader("Access-Control-Expose-Headers", "*"); |
| | | |
| | | } |
| | | |
| | | } |