如何使用JWT令牌连接Apache ActiveMQ Artemis?还有哪些其他连接方式?
一、自定义JWT安全插件实现指导
ActiveMQ Artemis的安全扩展通过实现org.apache.activemq.artemis.spi.core.security.ActiveMQSecurityManager2接口完成,针对JWT认证的核心逻辑是解析客户端传递的令牌、验证有效性,并映射到Artemis的用户权限体系。
1. 依赖准备
项目中引入JWT解析库,以Maven为例,在pom.xml添加:
<dependency> <groupId>io.jsonwebtoken</groupId> <artifactId>jjwt-api</artifactId> <version>0.11.5</version> </dependency> <dependency> <groupId>io.jsonwebtoken</groupId> <artifactId>jjwt-impl</artifactId> <version>0.11.5</version> <scope>runtime</scope> </dependency> <dependency> <groupId>io.jsonwebtoken</groupId> <artifactId>jjwt-jackson</artifactId> <version>0.11.5</version> <scope>runtime</scope> </dependency>
2. 实现自定义安全管理器
创建类继承ActiveMQSecurityManager2,重写认证与授权方法:
import io.jsonwebtoken.*; import org.apache.activemq.artemis.spi.core.security.ActiveMQSecurityManager2; import org.apache.activemq.artemis.core.security.Role; import java.security.Key; import java.util.Set; public class JwtSecurityManager implements ActiveMQSecurityManager2 { private final Key secretKey; public JwtSecurityManager(Key secretKey) { this.secretKey = secretKey; } @Override public boolean validateUser(String user, String password) { // 这里password实际是客户端传递的JWT令牌 try { Jwts.parserBuilder() .setSigningKey(secretKey) .build() .parseClaimsJws(password); return true; } catch (JwtException | IllegalArgumentException e) { return false; } } @Override public boolean validateUserAndRole(String user, String password, Set<Role> roles, String address) { if (!validateUser(user, password)) { return false; } // 解析JWT中的角色声明,匹配Artemis要求的角色 Claims claims = Jwts.parserBuilder() .setSigningKey(secretKey) .build() .parseClaimsJws(password) .getBody(); Set<String> userRoles = claims.get("roles", Set.class); return roles.stream().anyMatch(role -> userRoles.contains(role.getName())); } // 按需实现其他方法,如getUserRoles等 }
3. 配置插件到broker.xml
在broker.xml的<core>节点内添加安全管理器配置:
<core> ... <security-manager class-name="com.yourpackage.JwtSecurityManager"> <property key="secretKey" value="your-256-bit-secret-key"/> <!-- 若密钥从文件加载,可替换为路径配置 --> <!-- <property key="secretKeyPath" value="/etc/artemis/secret.key"/> --> </security-manager> ... </core>
4. Web客户端传递JWT连接
以STOMP over WebSocket为例,客户端将JWT作为passcode字段传递:
const client = new StompJs.Client({ brokerURL: 'ws://your-artemis-host:61614/ws', connectHeaders: { login: 'web-client', // 可填任意非空值,认证逻辑以JWT为准 passcode: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...' } });
二、除AMQPS外的其他连接方式
ActiveMQ Artemis支持多种协议连接,常见类型包括:
- STOMP over WebSocket:专为Web前端设计,通过标准WebSocket传输STOMP消息,兼容性强。
- STOMP over TCP:轻量级TCP协议,适配多语言客户端,实现简单。
- OpenWire:兼容传统ActiveMQ 5.x客户端,方便旧系统迁移。
- MQTT:物联网场景首选,低带宽、高延迟环境下表现优异。
- Core Protocol:Artemis原生高性能协议,Java客户端专属,支持完整特性。
- REST API:通过HTTP/HTTPS接口收发消息,无需MQ客户端,适合简单集成场景。
各协议的端口配置可在broker.xml的<acceptors>节点中查看或修改,例如:
<acceptors> <acceptor name="stomp-ws-acceptor">tcp://0.0.0.0:61614?protocols=STOMP;httpEnabled=true;httpUpgradeEnabled=true</acceptor> <acceptor name="mqtt-acceptor">tcp://0.0.0.0:1883?protocols=MQTT</acceptor> </acceptors>
内容的提问来源于stack exchange,提问作者IngeniouSeven
相关产品推荐
相关产品推荐

