spring-shiro.xml 4.2 KB
<?xml version="1.0" encoding="UTF-8"?>
<beans xmlns:util="http://www.springframework.org/schema/util"
	   xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
       xmlns:cache="http://www.springframework.org/schema/cache"
       xmlns:p="http://www.springframework.org/schema/p"
       xmlns="http://www.springframework.org/schema/beans"
       xsi:schemaLocation="http://www.springframework.org/schema/beans
       http://www.springframework.org/schema/beans/spring-beans-3.2.xsd
       http://www.springframework.org/schema/util http://www.springframework.org/schema/util/spring-util.xsd">
       
       <description>Shiro 配置文件</description>

       <!-- 缓存管理器 -->
       <bean id="shiroEhcacheManager" class="org.apache.shiro.cache.ehcache.EhCacheManager">
			<property name="cacheManagerConfigFile" value="classpath:security/ehcache-shiro.xml"/>
	   </bean>
	   
	   <!-- 会话Cookie模板 -->  
	   <bean id="sessionIdCookie" class="org.apache.shiro.web.servlet.SimpleCookie">  
	     	<constructor-arg value="sid"/>  
	    	<property name="httpOnly" value="true"/>  
	    	<property name="maxAge" value="-1"/>  
	   </bean>  
	   <bean id="rememberMeCookie" class="org.apache.shiro.web.servlet.SimpleCookie">  
    		<constructor-arg value="rememberMe"/>  
    		<property name="httpOnly" value="true"/>
    		<!-- 30天 -->  
    		<property name="maxAge" value="2592000"/>  
	   </bean>   
	   
	   <!-- rememberMe管理器 -->  
	   <bean id="rememberMeManager" class="org.apache.shiro.web.mgt.CookieRememberMeManager">  
		    <property name="cipherKey" value="#{T(org.apache.shiro.codec.Base64).decode('4AvVhmFLUs0KTA3Kprsdag==')}"/>  
		    <property name="cookie" ref="rememberMeCookie"/>  
	   </bean> 
       
       <!-- Realm实现 -->
	   <bean id="userRealm" class="com.framework.shiro.UserRealm">
	   		<property name="cachingEnabled" value="true"/>
	   </bean>
	   
       <!-- 安全管理器 -->
	   <bean id="securityManager" class="org.apache.shiro.web.mgt.DefaultWebSecurityManager">
	        <property name="realm" ref="userRealm"/>
	        <property name="cacheManager" ref="shiroEhcacheManager"/>
	        <property name="rememberMeManager" ref="rememberMeManager"/>  
	   </bean>

	   <!-- Shiro生命周期处理器-->
       <bean id="lifecycleBeanPostProcessor" class="org.apache.shiro.spring.LifecycleBeanPostProcessor"/>
       
       <!-- AOP式方法级权限检查  -->
	   <bean class="org.springframework.aop.framework.autoproxy.DefaultAdvisorAutoProxyCreator" depends-on="lifecycleBeanPostProcessor">
			<property name="proxyTargetClass" value="true" />
	   </bean>
	   <bean class="org.apache.shiro.spring.security.interceptor.AuthorizationAttributeSourceAdvisor">
	    	<property name="securityManager" ref="securityManager"/>
	   </bean>
	   <bean class="org.springframework.web.servlet.handler.SimpleMappingExceptionResolver">
			<property name="exceptionMappings">
				<props>
					<prop key="org.apache.shiro.authz.UnauthorizedException">/unauthorized</prop>
				</props>
			</property>
		</bean>
	   <!-- Shiro的Web过滤器 -->
	   <bean id="shiroFilter" class="org.apache.shiro.spring.web.ShiroFilterFactoryBean">
	        <property name="securityManager" ref="securityManager"/>
	        <property name="loginUrl" value="/login"/>
	        <property name="unauthorizedUrl" value="/unauthorized" />  
	        <property name="filterChainDefinitions">
	        
	            <value>
	                /login = anon
	                
	                /druid/** = anon
	                /unauthorized = anon
	                /resource/** = anon
	                /doLogin = anon
	                /retrieve/** = anon
	                /reset/password = anon
	                /change/passwd= anon
	                /captcha/** = anon
	                /fileDownload/** = anon
	                
	                /**/cross/** = anon
	                /tracking/detail/** = anon
	                
	                
	                /logout = logout
	                /** = authc
	                
	            </value>
	        </property>
	        
	   </bean>
	   
	   <bean id="logout" class="org.apache.shiro.web.filter.authc.LogoutFilter"> 
        	<property name="redirectUrl" value="/login" /> 
       </bean> 
       

       
</beans>