diff --git a/lab-30/《芋道 Dubbo Admin 快速入门》.md b/lab-30/《芋道 Dubbo Admin 快速入门》.md index a0b594c7..b79d611b 100644 --- a/lab-30/《芋道 Dubbo Admin 快速入门》.md +++ b/lab-30/《芋道 Dubbo Admin 快速入门》.md @@ -1 +1 @@ - + diff --git a/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/pom.xml b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/pom.xml new file mode 100644 index 00000000..692176d7 --- /dev/null +++ b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/pom.xml @@ -0,0 +1,68 @@ + + + + lab-68 + cn.iocoder.springboot.labs + 1.0-SNAPSHOT + + 4.0.0 + + lab-68-demo11-authorization-server-by-jdbc-store + + + + 2.2.4.RELEASE + + 1.8 + 1.8 + + + + + + org.springframework.boot + spring-boot-starter-parent + ${spring.boot.version} + pom + import + + + + + + + + org.springframework.boot + spring-boot-starter-web + + + + + + + + + + + org.springframework.security.oauth.boot + spring-security-oauth2-autoconfigure + ${spring.boot.version} + + + + + org.springframework.boot + spring-boot-starter-jdbc + + + mysql + mysql-connector-java + 5.1.48 + + + + + + diff --git a/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/java/cn/iocoder/springboot/lab68/authorizationserverdemo/AuthorizationServerApplication.java b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/java/cn/iocoder/springboot/lab68/authorizationserverdemo/AuthorizationServerApplication.java new file mode 100644 index 00000000..d08ae7c8 --- /dev/null +++ b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/java/cn/iocoder/springboot/lab68/authorizationserverdemo/AuthorizationServerApplication.java @@ -0,0 +1,13 @@ +package cn.iocoder.springboot.lab68.authorizationserverdemo; + +import org.springframework.boot.SpringApplication; +import org.springframework.boot.autoconfigure.SpringBootApplication; + +@SpringBootApplication +public class AuthorizationServerApplication { + + public static void main(String[] args) { + SpringApplication.run(AuthorizationServerApplication.class, args); + } + +} diff --git a/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/java/cn/iocoder/springboot/lab68/authorizationserverdemo/config/OAuth2AuthorizationServerConfig.java b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/java/cn/iocoder/springboot/lab68/authorizationserverdemo/config/OAuth2AuthorizationServerConfig.java new file mode 100644 index 00000000..2d74d8f5 --- /dev/null +++ b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/java/cn/iocoder/springboot/lab68/authorizationserverdemo/config/OAuth2AuthorizationServerConfig.java @@ -0,0 +1,68 @@ +package cn.iocoder.springboot.lab68.authorizationserverdemo.config; + +import org.springframework.beans.factory.annotation.Autowired; +import org.springframework.context.annotation.Bean; +import org.springframework.context.annotation.Configuration; +import org.springframework.security.authentication.AuthenticationManager; +import org.springframework.security.oauth2.config.annotation.configurers.ClientDetailsServiceConfigurer; +import org.springframework.security.oauth2.config.annotation.web.configuration.AuthorizationServerConfigurerAdapter; +import org.springframework.security.oauth2.config.annotation.web.configuration.EnableAuthorizationServer; +import org.springframework.security.oauth2.config.annotation.web.configurers.AuthorizationServerEndpointsConfigurer; +import org.springframework.security.oauth2.config.annotation.web.configurers.AuthorizationServerSecurityConfigurer; +import org.springframework.security.oauth2.provider.ClientDetailsService; +import org.springframework.security.oauth2.provider.client.JdbcClientDetailsService; +import org.springframework.security.oauth2.provider.token.TokenStore; +import org.springframework.security.oauth2.provider.token.store.JdbcTokenStore; + +import javax.sql.DataSource; + +/** + * 授权服务器配置 + */ +@Configuration +@EnableAuthorizationServer +public class OAuth2AuthorizationServerConfig extends AuthorizationServerConfigurerAdapter { + + /** + * 用户认证 Manager + */ + @Autowired + private AuthenticationManager authenticationManager; + + /** + * 数据源 DataSource + */ + @Autowired + private DataSource dataSource; + + @Bean + public TokenStore jdbcTokenStore() { + return new JdbcTokenStore(dataSource); + } + + @Override + public void configure(AuthorizationServerEndpointsConfigurer endpoints) throws Exception { + endpoints.authenticationManager(authenticationManager) + .tokenStore(jdbcTokenStore()); + } + + @Override + public void configure(AuthorizationServerSecurityConfigurer oauthServer) throws Exception { + oauthServer.checkTokenAccess("isAuthenticated()"); +// oauthServer.tokenKeyAccess("isAuthenticated()") +// .checkTokenAccess("isAuthenticated()"); +// oauthServer.tokenKeyAccess("permitAll()") +// .checkTokenAccess("permitAll()"); + } + + @Bean + public ClientDetailsService jdbcClientDetailsService() { + return new JdbcClientDetailsService(dataSource); + } + + @Override + public void configure(ClientDetailsServiceConfigurer clients) throws Exception { + clients.withClientDetails(jdbcClientDetailsService()); + } + +} diff --git a/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/java/cn/iocoder/springboot/lab68/authorizationserverdemo/config/SecurityConfig.java b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/java/cn/iocoder/springboot/lab68/authorizationserverdemo/config/SecurityConfig.java new file mode 100644 index 00000000..9da10ba5 --- /dev/null +++ b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/java/cn/iocoder/springboot/lab68/authorizationserverdemo/config/SecurityConfig.java @@ -0,0 +1,38 @@ +package cn.iocoder.springboot.lab68.authorizationserverdemo.config; + +import org.springframework.context.annotation.Bean; +import org.springframework.context.annotation.Configuration; +import org.springframework.security.authentication.AuthenticationManager; +import org.springframework.security.config.BeanIds; +import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; +import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; +import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; +import org.springframework.security.crypto.password.NoOpPasswordEncoder; + +@Configuration +@EnableWebSecurity +public class SecurityConfig extends WebSecurityConfigurerAdapter { + + @Override + @Bean(name = BeanIds.AUTHENTICATION_MANAGER) + public AuthenticationManager authenticationManagerBean() throws Exception { + return super.authenticationManagerBean(); + } + + @Bean + public static NoOpPasswordEncoder passwordEncoder() { + return (NoOpPasswordEncoder) NoOpPasswordEncoder.getInstance(); + } + + @Override + protected void configure(AuthenticationManagerBuilder auth) throws Exception { + auth. + // 使用内存中的 InMemoryUserDetailsManager + inMemoryAuthentication() + // 不使用 PasswordEncoder 密码编码器 + .passwordEncoder(passwordEncoder()) + // 配置 yunai 用户 + .withUser("yunai").password("1024").roles("USER"); + } + +} diff --git a/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/resources/application.yaml b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/resources/application.yaml new file mode 100644 index 00000000..41f8439a --- /dev/null +++ b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/resources/application.yaml @@ -0,0 +1,7 @@ +spring: + # datasource 数据源配置内容,对应 DataSourceProperties 配置属性类 + datasource: + url: jdbc:mysql://127.0.0.1:43063/demo-68-authorization-server?useSSL=false&useUnicode=true&characterEncoding=UTF-8 + driver-class-name: com.mysql.jdbc.Driver + username: root # 数据库账号 + password: 123456 # 数据库密码 diff --git a/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/resources/db/data.sql b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/resources/db/data.sql new file mode 100644 index 00000000..8e61435e --- /dev/null +++ b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/resources/db/data.sql @@ -0,0 +1,7 @@ +INSERT INTO oauth_client_details + (client_id, client_secret, scope, authorized_grant_types, + web_server_redirect_uri, authorities, access_token_validity, + refresh_token_validity, additional_information, autoapprove) +VALUES + ('clientapp', '112233', 'read_userinfo,read_contacts', + 'password,refresh_token', null, null, 3600, 864000, null, true); diff --git a/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/resources/db/schema.sql b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/resources/db/schema.sql new file mode 100644 index 00000000..43d55efa --- /dev/null +++ b/lab-68/lab-68-demo11-authorization-server-by-jdbc-store/src/main/resources/db/schema.sql @@ -0,0 +1,52 @@ +--------------- MySQL --------------- +drop table if exists oauth_client_details; +create table oauth_client_details ( + client_id VARCHAR(255) PRIMARY KEY, + resource_ids VARCHAR(255), + client_secret VARCHAR(255), + scope VARCHAR(255), + authorized_grant_types VARCHAR(255), + web_server_redirect_uri VARCHAR(255), + authorities VARCHAR(255), + access_token_validity INTEGER, + refresh_token_validity INTEGER, + additional_information VARCHAR(4096), + autoapprove VARCHAR(255) +); + +create table if not exists oauth_client_token ( + token_id VARCHAR(255), + token LONG VARBINARY, + authentication_id VARCHAR(255) PRIMARY KEY, + user_name VARCHAR(255), + client_id VARCHAR(255) +); + +create table if not exists oauth_access_token ( + token_id VARCHAR(255), + token LONG VARBINARY, + authentication_id VARCHAR(255) PRIMARY KEY, + user_name VARCHAR(255), + client_id VARCHAR(255), + authentication LONG VARBINARY, + refresh_token VARCHAR(255) +); + +create table if not exists oauth_refresh_token ( + token_id VARCHAR(255), + token LONG VARBINARY, + authentication LONG VARBINARY +); + +create table if not exists oauth_code ( + code VARCHAR(255), authentication LONG VARBINARY +); + +create table if not exists oauth_approvals ( + userId VARCHAR(255), + clientId VARCHAR(255), + scope VARCHAR(255), + status VARCHAR(10), + expiresAt TIMESTAMP DEFAULT CURRENT_TIMESTAMP, + lastModifiedAt TIMESTAMP DEFAULT CURRENT_TIMESTAMP +); diff --git a/lab-68/pom.xml b/lab-68/pom.xml index 5faae9d3..65143891 100644 --- a/lab-68/pom.xml +++ b/lab-68/pom.xml @@ -24,6 +24,7 @@ lab-68-demo02-authorization-server-with-client-credentials lab-68-demo03-authorization-server-with-resource-owner-password-credentials + lab-68-demo11-authorization-server-by-jdbc-store