如何使用Spring Security从过滤器中更新标题参数



我正在开发带有弹簧安全性的过滤器, OncePerRequestFilter类,并且必须在其余服务中更新参数。标题由注释@RequestHeader输入。

我尝试使用以下类别从过滤器中更新参数:

public class HeaderMapRequestWrapper extends HttpServletRequestWrapper {
    /**
     * construct a wrapper for this request
     * 
     * @param request
     */
    public HeaderMapRequestWrapper(HttpServletRequest request) {
        super(request);
    }
    private Map<String, String> headerMap = new HashMap<String, String>();
    /**
     * add a header with given name and value
     * 
     * @param name
     * @param value
     */
    public void addHeader(String name, String value) {
        headerMap.put(name, value);
    }
    public void removeteHeader(String name){
        headerMap.remove(name); 
    }
    @Override
    public String getHeader(String name) {
        String headerValue = super.getHeader(name);
        if (headerMap.containsKey(name)) {
            headerValue = headerMap.get(name);
        }
        return headerValue;
    }
    /**
     * get the Header names
     */
    @Override
    public Enumeration<String> getHeaderNames() {
        List<String> names = Collections.list(super.getHeaderNames());
        for (String name : headerMap.keySet()) {
            names.add(name);
        }
        return Collections.enumeration(names);
    }
    @Override
    public Enumeration<String> getHeaders(String name) {
        List<String> values = Collections.list(super.getHeaders(name));
        if (headerMap.containsKey(name)) {
            values.add(headerMap.get(name));
        }
        return Collections.enumeration(values);
    }
}

和使用方法.addHeader("parameter", "New value"),但是当我在方法中读取参数时,它没有更改,但是如果从.getheader('parameter')方法从 httpservletrequest 类中读取,我已经在相同的方法类中不截至。更改已完成,但在方法参数中未显示。

该方法是:

@Autowired
HttpServletRequest a;

//Annotations @GetMapping......
public void method (@RequestHeader(value="Parameter") String parameter){
      System.out.print(parameter); //Parameter did not change
      system.out.print(a.getHeader("parameter"));    //Parameter changed.
}

有人知道如何从过滤器中更改操作参数吗?或其他方式....

我不确定您在做什么错,但是当我尝试使用设置时,它似乎有效。请查看以下代码。

/**
 * username: test, password: test
 * Added Header: param
 * REST URL: http://localhost:8080/hello
 */
package com.test;
import java.io.IOException;
import java.util.Collections;
import java.util.Enumeration;
import java.util.HashMap;
import java.util.List;
import java.util.Map;
import javax.servlet.FilterChain;
import javax.servlet.ServletException;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletRequestWrapper;
import javax.servlet.http.HttpServletResponse;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
import org.springframework.stereotype.Component;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RequestHeader;
import org.springframework.web.bind.annotation.RestController;
import org.springframework.web.filter.OncePerRequestFilter;
@SpringBootApplication
public class TestRequestWrapperApplication {
    public static void main(String[] args) {
        SpringApplication.run(TestRequestWrapperApplication.class, args);
    }
}
@Component
class RequestWrapperFilter extends OncePerRequestFilter {
    @Override
    protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain filterChain)
            throws ServletException, IOException {
        HeaderMapRequestWrapper wrappedRequest = new HeaderMapRequestWrapper((HttpServletRequest)request);
        wrappedRequest.addHeader("param", "Hello World!");
        filterChain.doFilter(wrappedRequest, response);
    }
}
@RestController
class TestRest {
    @GetMapping("hello")
    public String hello(@RequestHeader("param") String param) {
        return "param: " + param;
    }
}
@Configuration
class SecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        super.configure(http);
    }
    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        auth.inMemoryAuthentication().withUser("test").authorities("test").password("test");
    }
}
class HeaderMapRequestWrapper extends HttpServletRequestWrapper {
    public HeaderMapRequestWrapper(HttpServletRequest request) {
        super(request);
    }
    private Map<String, String> headerMap = new HashMap<String, String>();
    public void addHeader(String name, String value) {
        headerMap.put(name, value);
    }
    public void removeteHeader(String name) {
        headerMap.remove(name);
    }
    @Override
    public String getHeader(String name) {
        String headerValue = super.getHeader(name);
        if (headerMap.containsKey(name)) {
            headerValue = headerMap.get(name);
        }
        return headerValue;
    }
    @Override
    public Enumeration<String> getHeaderNames() {
        List<String> names = Collections.list(super.getHeaderNames());
        for (String name : headerMap.keySet()) {
            names.add(name);
        }
        return Collections.enumeration(names);
    }
    @Override
    public Enumeration<String> getHeaders(String name) {
        List<String> values = Collections.list(super.getHeaders(name));
        if (headerMap.containsKey(name)) {
            values.add(headerMap.get(name));
        }
        return Collections.enumeration(values);
    }
}

最新更新