You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用JWT令牌连接Apache ActiveMQ Artemis?还有哪些其他连接方式?

一、自定义JWT安全插件实现指导

ActiveMQ Artemis的安全扩展通过实现org.apache.activemq.artemis.spi.core.security.ActiveMQSecurityManager2接口完成,针对JWT认证的核心逻辑是解析客户端传递的令牌、验证有效性,并映射到Artemis的用户权限体系。

1. 依赖准备

项目中引入JWT解析库,以Maven为例,在pom.xml添加:

<dependency>
    <groupId>io.jsonwebtoken</groupId>
    <artifactId>jjwt-api</artifactId>
    <version>0.11.5</version>
</dependency>
<dependency>
    <groupId>io.jsonwebtoken</groupId>
    <artifactId>jjwt-impl</artifactId>
    <version>0.11.5</version>
    <scope>runtime</scope>
</dependency>
<dependency>
    <groupId>io.jsonwebtoken</groupId>
    <artifactId>jjwt-jackson</artifactId>
    <version>0.11.5</version>
    <scope>runtime</scope>
</dependency>

2. 实现自定义安全管理器

创建类继承ActiveMQSecurityManager2,重写认证与授权方法:

import io.jsonwebtoken.*;
import org.apache.activemq.artemis.spi.core.security.ActiveMQSecurityManager2;
import org.apache.activemq.artemis.core.security.Role;
import java.security.Key;
import java.util.Set;

public class JwtSecurityManager implements ActiveMQSecurityManager2 {

    private final Key secretKey;

    public JwtSecurityManager(Key secretKey) {
        this.secretKey = secretKey;
    }

    @Override
    public boolean validateUser(String user, String password) {
        // 这里password实际是客户端传递的JWT令牌
        try {
            Jwts.parserBuilder()
                .setSigningKey(secretKey)
                .build()
                .parseClaimsJws(password);
            return true;
        } catch (JwtException | IllegalArgumentException e) {
            return false;
        }
    }

    @Override
    public boolean validateUserAndRole(String user, String password, Set<Role> roles, String address) {
        if (!validateUser(user, password)) {
            return false;
        }
        // 解析JWT中的角色声明,匹配Artemis要求的角色
        Claims claims = Jwts.parserBuilder()
                .setSigningKey(secretKey)
                .build()
                .parseClaimsJws(password)
                .getBody();
        Set<String> userRoles = claims.get("roles", Set.class);
        return roles.stream().anyMatch(role -> userRoles.contains(role.getName()));
    }

    // 按需实现其他方法,如getUserRoles等
}

3. 配置插件到broker.xml

在broker.xml的<core>节点内添加安全管理器配置:

<core>
    ...
    <security-manager class-name="com.yourpackage.JwtSecurityManager">
        <property key="secretKey" value="your-256-bit-secret-key"/>
        <!-- 若密钥从文件加载,可替换为路径配置 -->
        <!-- <property key="secretKeyPath" value="/etc/artemis/secret.key"/> -->
    </security-manager>
    ...
</core>

4. Web客户端传递JWT连接

以STOMP over WebSocket为例,客户端将JWT作为passcode字段传递:

const client = new StompJs.Client({
    brokerURL: 'ws://your-artemis-host:61614/ws',
    connectHeaders: {
        login: 'web-client', // 可填任意非空值,认证逻辑以JWT为准
        passcode: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...'
    }
});

二、除AMQPS外的其他连接方式

ActiveMQ Artemis支持多种协议连接,常见类型包括:

  • STOMP over WebSocket:专为Web前端设计,通过标准WebSocket传输STOMP消息,兼容性强。
  • STOMP over TCP:轻量级TCP协议,适配多语言客户端,实现简单。
  • OpenWire:兼容传统ActiveMQ 5.x客户端,方便旧系统迁移。
  • MQTT:物联网场景首选,低带宽、高延迟环境下表现优异。
  • Core Protocol:Artemis原生高性能协议,Java客户端专属,支持完整特性。
  • REST API:通过HTTP/HTTPS接口收发消息,无需MQ客户端,适合简单集成场景。

各协议的端口配置可在broker.xml的<acceptors>节点中查看或修改,例如:

<acceptors>
    <acceptor name="stomp-ws-acceptor">tcp://0.0.0.0:61614?protocols=STOMP;httpEnabled=true;httpUpgradeEnabled=true</acceptor>
    <acceptor name="mqtt-acceptor">tcp://0.0.0.0:1883?protocols=MQTT</acceptor>
</acceptors>

内容的提问来源于stack exchange,提问作者IngeniouSeven

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 21:22:43