【update】采用RSA加密的模式进行处理登录

This commit is contained in:
mzc5649
2021-04-16 13:17:23 +08:00
parent 74d0594771
commit a5148905c4
@@ -1,7 +1,7 @@
package com.jero.modules.system.controller; package com.jero.modules.system.controller;
import cn.hutool.core.util.RandomUtil; import cn.hutool.core.util.RandomUtil;
import cn.hutool.crypto.SecureUtil; import cn.hutool.crypto.asymmetric.RSA;
import com.alibaba.fastjson.JSONObject; import com.alibaba.fastjson.JSONObject;
import com.aliyuncs.exceptions.ClientException; import com.aliyuncs.exceptions.ClientException;
import com.baomidou.mybatisplus.core.conditions.query.LambdaQueryWrapper; import com.baomidou.mybatisplus.core.conditions.query.LambdaQueryWrapper;
@@ -33,7 +33,9 @@ import org.springframework.web.bind.annotation.*;
import javax.annotation.Resource; import javax.annotation.Resource;
import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse; import javax.servlet.http.HttpServletResponse;
import java.security.*; import java.security.KeyPair;
import java.security.PrivateKey;
import java.security.PublicKey;
import java.util.*; import java.util.*;
/** /**
@@ -71,11 +73,12 @@ public class LoginController {
Result<JSONObject> result = new Result<JSONObject>(); Result<JSONObject> result = new Result<JSONObject>();
String username = sysLoginModel.getUsername(); String username = sysLoginModel.getUsername();
String password = sysLoginModel.getPassword(); String password = sysLoginModel.getPassword();
String rsaPublicKey = sysLoginModel.getRsaPublicKey();
String rsaPrivateKey = String.valueOf(redisUtil.get(rsaPublicKey));
//update-begin--Author:scott Date:20190805 for:暂时注释掉密码加密逻辑,有点问题 //update-begin--Author:scott Date:20190805 for:暂时注释掉密码加密逻辑,有点问题
//前端密码加密,后端进行密码解密 //前端密码加密,后端进行密码解密
//password = AesEncryptUtil.desEncrypt(sysLoginModel.getPassword().replaceAll("%2B", "\\+")).trim();//密码解密 //password = AesEncryptUtil.desEncrypt(sysLoginModel.getPassword().replaceAll("%2B", "\\+")).trim();//密码解密
//update-begin--Author:scott Date:20190805 for:暂时注释掉密码加密逻辑,有点问题 //update-begin--Author:scott Date:20190805 for:暂时注释掉密码加密逻辑,有点问题
//update-begin-author:taoyan date:20190828 for:校验验证码 //update-begin-author:taoyan date:20190828 for:校验验证码
String captcha = sysLoginModel.getCaptcha(); String captcha = sysLoginModel.getCaptcha();
if(captcha==null){ if(captcha==null){
@@ -90,8 +93,13 @@ public class LoginController {
result.error500("验证码错误"); result.error500("验证码错误");
return result; return result;
} }
//update-end-author:taoyan date:20190828 for:校验验证码 try {
//解密获取密码和用户名
password = CommonUtils.decryptBtRsaPriKey(password, rsaPrivateKey);
username = CommonUtils.decryptBtRsaPriKey(username, rsaPrivateKey);
} catch (Exception e) {
e.printStackTrace();
}
//1. 校验用户是否有效 //1. 校验用户是否有效
//update-begin-author:wangshuai date:20200601 for: 登录代码验证用户是否注销bug,if条件永远为false //update-begin-author:wangshuai date:20200601 for: 登录代码验证用户是否注销bug,if条件永远为false
LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>(); LambdaQueryWrapper<SysUser> queryWrapper = new LambdaQueryWrapper<>();
@@ -119,7 +127,7 @@ public class LoginController {
// 重试登录次数加一 // 重试登录次数加一
retryCount++; retryCount++;
if( retryCount == 1){ if( retryCount == 1){
redisUtil.set(RETRY_LOGIN_PREFIX + username,retryCount, 60 * 30); redisUtil.set(RETRY_LOGIN_PREFIX + username,retryCount,60 * 30);
}else { }else {
redisUtil.set(RETRY_LOGIN_PREFIX + username,retryCount,redisUtil.getExpire(RETRY_LOGIN_PREFIX + username)); redisUtil.set(RETRY_LOGIN_PREFIX + username,retryCount,redisUtil.getExpire(RETRY_LOGIN_PREFIX + username));
} }
@@ -534,24 +542,14 @@ public class LoginController {
* @param * @param
* @return com.jero.common.api.vo.Result<java.lang.String> * @return com.jero.common.api.vo.Result<java.lang.String>
*/ */
@ApiOperation("获取RSA公钥")
@GetMapping("/getRSAPublicKey")
public Result<String> getRSAPublicKey(){ public Result<String> getRSAPublicKey(){
KeyPairGenerator keyPairGenerator = null; RSA rsa = new RSA();
try { String privateKeyBase64 = rsa.getPrivateKeyBase64();
keyPairGenerator = KeyPairGenerator.getInstance("RSA"); String publicKeyBase64 = rsa.getPublicKeyBase64();
} catch (NoSuchAlgorithmException e) {
e.printStackTrace();
}
assert keyPairGenerator != null;
KeyPair keyPair = keyPairGenerator.generateKeyPair();
// 得到私钥
PrivateKey privateKey = keyPair.getPrivate();
// 得到公钥
PublicKey publicKey = keyPair.getPublic();
//base64编码
String privateKeyBase64 = Base64.getEncoder().encodeToString(privateKey.getEncoded());
String publicKeyBase64 = Base64.getEncoder().encodeToString(publicKey.getEncoded());
//存到redis key为公钥 value为私钥 //存到redis key为公钥 value为私钥
redisUtil.set(publicKeyBase64, privateKeyBase64, 60 * 60L); redisUtil.set(publicKeyBase64, privateKeyBase64, 60L);
Result<String> result = new Result<>(); Result<String> result = new Result<>();
result.setResult(publicKeyBase64); result.setResult(publicKeyBase64);
return result; return result;