JHipster v8.1.0如何通过Cookie实现请求认证?
JHipster v8基于Spring Security 6重构了认证流程,原7.x版本中的JWTFilter已被整合到Spring Security的OAuth2资源服务器组件中。要实现从Cookie解析JWT的逻辑,你可以通过以下两种方式完成:
方式一:自定义BearerTokenResolver
BearerTokenResolver负责从请求中提取Token,我们可以实现该接口同时支持Header和Cookie两种来源:
import jakarta.servlet.http.Cookie; import jakarta.servlet.http.HttpServletRequest; import org.springframework.security.oauth2.server.resource.web.BearerTokenResolver; import org.springframework.util.StringUtils; import org.springframework.web.util.WebUtils; public class CookieAwareBearerTokenResolver implements BearerTokenResolver { // 替换为你实际使用的Header和Cookie名称 private static final String AUTHORIZATION_HEADER = "Authorization"; private static final String AUTHORIZATION_COOKIE = "JWT_AUTH"; @Override public String resolve(HttpServletRequest request) { // 优先从请求头提取Token String token = resolveFromHeader(request); if (token == null) { // 头中无Token则从Cookie提取 token = resolveFromCookie(request); } return token; } private String resolveFromHeader(HttpServletRequest request) { String bearerToken = request.getHeader(AUTHORIZATION_HEADER); if (StringUtils.hasText(bearerToken) && bearerToken.startsWith("Bearer ")) { return bearerToken.substring(7); } return null; } private String resolveFromCookie(HttpServletRequest request) { Cookie authCookie = WebUtils.getCookie(request, AUTHORIZATION_COOKIE); if (authCookie != null && StringUtils.hasText(authCookie.getValue())) { return authCookie.getValue(); } return null; } }
然后在Security配置类中替换默认的Resolver:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.web.SecurityFilterChain; @Configuration public class SecurityConfiguration { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http // 保留你原有的其他配置(如CSRF、权限规则等) .oauth2ResourceServer(oauth2 -> oauth2 .bearerTokenResolver(new CookieAwareBearerTokenResolver()) .jwt(jwt -> jwt // 配置JWT验证逻辑(如签名密钥、转换器等) ) ); return http.build(); } }
方式二:自定义AuthenticationConverter
如果需要更灵活的认证对象转换逻辑,可以实现AuthenticationConverter接口:
import jakarta.servlet.http.Cookie; import jakarta.servlet.http.HttpServletRequest; import org.springframework.security.core.Authentication; import org.springframework.security.oauth2.jwt.Jwt; import org.springframework.security.oauth2.jwt.JwtAuthenticationToken; import org.springframework.security.web.authentication.AuthenticationConverter; import org.springframework.util.StringUtils; import org.springframework.web.util.WebUtils; public class CookieAndHeaderJwtAuthenticationConverter implements AuthenticationConverter { private static final String AUTHORIZATION_HEADER = "Authorization"; private static final String AUTHORIZATION_COOKIE = "JWT_AUTH"; @Override public Authentication convert(HttpServletRequest request) { String token = resolveToken(request); if (token == null) { return null; } // 生成JWT认证Token,可根据需求扩展自定义逻辑 Jwt jwt = Jwt.withTokenValue(token).build(); return new JwtAuthenticationToken(jwt); } private String resolveToken(HttpServletRequest request) { String bearerToken = request.getHeader(AUTHORIZATION_HEADER); if (StringUtils.hasText(bearerToken) && bearerToken.startsWith("Bearer ")) { return bearerToken.substring(7); } Cookie authCookie = WebUtils.getCookie(request, AUTHORIZATION_COOKIE); if (authCookie != null && StringUtils.hasText(authCookie.getValue())) { return authCookie.getValue(); } return null; } }
在Security配置中配置该Converter:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.authentication.AuthenticationConverter; @Configuration public class SecurityConfiguration { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .oauth2ResourceServer(oauth2 -> oauth2 .jwt(jwt -> jwt .jwtAuthenticationConverter(cookieAndHeaderJwtAuthenticationConverter()) ) ); return http.build(); } @Bean public AuthenticationConverter cookieAndHeaderJwtAuthenticationConverter() { return new CookieAndHeaderJwtAuthenticationConverter(); } }
注意事项
- 替换代码中
AUTHORIZATION_COOKIE的值为你实际使用的Cookie名称; - 如果是JHipster生成的项目,默认已有
SecurityConfiguration类,直接修改其中的oauth2ResourceServer配置即可; - 确保JWT的验证逻辑(如签名密钥、过期时间校验等)已正确配置,可沿用JHipster默认的JWT配置。
内容的提问来源于stack exchange,提问作者Soroush Shemshadi
相关产品推荐
相关产品推荐

