如何在配置VelocityEngine的URLResourceLoader时传入用户名和密码
解决方案
原生URLResourceLoader本身没有提供直接配置鉴权凭证的初始化参数,你可以通过以下两种方式实现需求:
方案一:自定义扩展URLResourceLoader(推荐,灵活性最高)
该方案适配所有鉴权场景,且不会泄露凭证信息,生产环境建议使用:
- 继承
URLResourceLoader类,重写getResourceStream方法,在请求目标URL时添加对应的鉴权请求头 - 初始化VelocityEngine时指定你自定义的资源加载器类,同时传入用户名密码配置即可
自定义资源加载器示例代码:
import org.apache.velocity.runtime.resource.loader.URLResourceLoader; import java.io.InputStream; import java.net.HttpURLConnection; import java.net.URL; import java.util.Base64; public class AuthenticatedURLResourceLoader extends URLResourceLoader { private String username; private String password; @Override public void init(org.apache.velocity.util.ExtProperties configuration) { super.init(configuration); // 读取配置中的鉴权参数 this.username = configuration.getString("username"); this.password = configuration.getString("password"); } @Override protected InputStream getResourceStream(String resourceName) { try { URL url = new URL(rootURL + resourceName); HttpURLConnection connection = (HttpURLConnection) url.openConnection(); // 构造Basic Auth鉴权头,如果你用的是Bearer Token等其他鉴权方式,修改这里的头构造逻辑即可 String auth = username + ":" + password; String encodedAuth = Base64.getEncoder().encodeToString(auth.getBytes()); connection.setRequestProperty("Authorization", "Basic " + encodedAuth); connection.setConnectTimeout(timeout * 1000); connection.setReadTimeout(timeout * 1000); return connection.getInputStream(); } catch (Exception e) { log.error("模板资源请求失败: " + resourceName, e); return null; } } }
修改后的Velocity初始化代码:
// Initialize the Velocity Engine velocityEngine = new VelocityEngine(); velocityEngine.setProperty(VelocityEngine.RESOURCE_LOADER, "url"); velocityEngine.setProperty(VelocityEngine.RESOURCE_LOADER_CHECK_INTERVAL, 2); velocityEngine.setProperty(VelocityEngine.INPUT_ENCODING, StandardCharsets.UTF_8.name()); // 替换为自定义的资源加载器 velocityEngine.setProperty("url.resource.loader.class", AuthenticatedURLResourceLoader.class.getName()); velocityEngine.setProperty("url.resource.loader.root", APPProperties.configServerURL + "/webserver/cgs/templateFiles/"); velocityEngine.setProperty("resource.loader.url.timeout", 20); // 新增鉴权参数配置 velocityEngine.setProperty("url.resource.loader.username", "实际用户名"); velocityEngine.setProperty("url.resource.loader.password", "实际密码"); velocityEngine.init();
方案二:URL嵌入鉴权信息(仅适用于测试场景)
如果你的服务端用的是Basic Auth校验,也可以直接把凭证拼接到root URL中,格式为http://用户名:密码@域名/路径,该方式存在明文泄露凭证的风险,禁止在生产环境使用:
// 对用户名密码做URL编码避免特殊字符报错 String encodedUser = URLEncoder.encode("实际用户名", StandardCharsets.UTF_8); String encodedPwd = URLEncoder.encode("实际密码", StandardCharsets.UTF_8); String authPrefix = encodedUser + ":" + encodedPwd + "@"; // 拼接鉴权前缀到URL String rootUrl = APPProperties.configServerURL.replace("http://", "http://" + authPrefix) .replace("https://", "https://" + authPrefix); velocityEngine.setProperty("url.resource.loader.root", rootUrl + "/webserver/cgs/templateFiles/");
内容的提问来源于stack exchange,提问作者hell_storm2004
相关产品推荐
相关产品推荐

