Spring Cloud Dataflow JDBC认证实现求助:寻求配置方案及相关文档
Great question! Since Spring Cloud Data Flow (SCDF) is built on top of Spring Security, you can extend its authentication mechanism to support JDBC-based authentication pretty straightforwardly. Here's a step-by-step implementation approach tailored to your needs:
1. Add Required Dependencies
First, ensure your project includes the necessary dependencies for Spring Security JDBC, your database driver, and core SCDF components. For Maven, add these to your pom.xml:
<!-- Spring Security JDBC --> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-jdbc</artifactId> </dependency> <!-- Example: MySQL Driver (replace with your DB driver) --> <dependency> <groupId>mysql</groupId> <artifactId>mysql-connector-java</artifactId> <scope>runtime</scope> </dependency> <!-- Spring Cloud Data Flow Server Core (if not already present) --> <dependency> <groupId>org.springframework.cloud</groupId> <artifactId>spring-cloud-dataflow-server-core</artifactId> <version>${spring-cloud-dataflow.version}</version> </dependency>
2. Set Up Database Schema
Spring Security JDBC provides default table structures for users and authorities. You can use these or customize them. Below is the default DDL (adjust for your database dialect):
-- Users table CREATE TABLE users ( username VARCHAR(50) NOT NULL PRIMARY KEY, password VARCHAR(100) NOT NULL, enabled BOOLEAN NOT NULL ); -- Authorities table (maps users to SCDF roles) CREATE TABLE authorities ( username VARCHAR(50) NOT NULL, authority VARCHAR(50) NOT NULL, FOREIGN KEY (username) REFERENCES users(username), UNIQUE KEY idx_username_authority (username, authority) );
Important: SCDF relies on specific roles like DATAFLOW_ADMIN, DATAFLOW_VIEW, DATAFLOW_CREATE to control access. Make sure to assign these roles to your users in the authorities table.
3. Configure Spring Security for JDBC Authentication
Create a custom security configuration class that integrates Spring Security's JDBC auth with SCDF's security setup.
For Spring Security 5.x (using WebSecurityConfigurerAdapter):
import org.springframework.beans.factory.annotation.Autowired; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; import javax.sql.DataSource; @Configuration @EnableWebSecurity public class JdbcSecurityConfig extends WebSecurityConfigurerAdapter { @Autowired private DataSource dataSource; @Override protected void configure(AuthenticationManagerBuilder auth) throws Exception { auth.jdbcAuthentication() .dataSource(dataSource) .usersByUsernameQuery("SELECT username, password, enabled FROM users WHERE username = ?") .authoritiesByUsernameQuery("SELECT username, authority FROM authorities WHERE username = ?") .passwordEncoder(new BCryptPasswordEncoder()); // Never skip password encoding! } }
For Spring Security 6+ (using SecurityFilterChain):
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.core.userdetails.UserDetailsService; import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; import org.springframework.security.crypto.password.PasswordEncoder; import org.springframework.security.provisioning.JdbcUserDetailsManager; import org.springframework.security.web.SecurityFilterChain; import javax.sql.DataSource; @Configuration @EnableWebSecurity public class JdbcSecurityConfig { @Bean public UserDetailsService userDetailsService(DataSource dataSource) { JdbcUserDetailsManager userDetailsManager = new JdbcUserDetailsManager(dataSource); userDetailsManager.setUsersByUsernameQuery("SELECT username, password, enabled FROM users WHERE username = ?"); userDetailsManager.setAuthoritiesByUsernameQuery("SELECT username, authority FROM authorities WHERE username = ?"); return userDetailsManager; } @Bean public PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); } @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth .anyRequest().authenticated() ) .formLogin(form -> form.permitAll()) .logout(logout -> logout.permitAll()); return http.build(); } }
4. Configure DataSource in SCDF Properties
Update your application.yml or application.properties to point to the database storing your user credentials:
spring: datasource: url: jdbc:mysql://localhost:3306/scdf_auth?useSSL=false&serverTimezone=UTC username: db_user password: db_password driver-class-name: com.mysql.cj.jdbc.Driver
5. Test the Setup
- Insert a test user into your database (ensure the password is BCrypt-encoded; you can generate hashes via online tools or Spring's
BCryptPasswordEncoder):-- Insert admin user (password: 'admin123' encoded with BCrypt) INSERT INTO users (username, password, enabled) VALUES ('admin', '$2a$10$EblZqNptyYvcLm/VwDCVAuBjzZOI7khzdyGPBr08PpIi0na624b8.', true); INSERT INTO authorities (username, authority) VALUES ('admin', 'DATAFLOW_ADMIN'); - Start your SCDF server and access the dashboard. You should be able to log in using the JDBC-stored credentials.
Key Notes
- Never store plain-text passwords: Always use a strong encoder like
BCryptPasswordEncoder. - Customize schema if needed: If you have an existing user database, adjust the
usersByUsernameQueryandauthoritiesByUsernameQueryto match your table/column names. - Secure your database: Ensure proper access controls are in place to protect the user credential tables.
内容的提问来源于stack exchange,提问作者Shaikh Ahmed

