前言
眾所周知在spring boot內,設置session過期時間只需在application.properties
內添加server.session.timeout
配置即可。在整合shiro時發現,server.session.timeout
設置為7200,但未到2小時就需要重新登錄,后來發現是shiro的session已經過期了,shiro的session過期時間并不和server.session.timeout
一致,目前是采用filter的方式來進行設置。
ShiroSessionFilter
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
|
/** * 通過攔截器設置shiroSession過期時間 * @author yangwk */ public class ShiroSessionFilter implements Filter { private static Logger logger = LoggerFactory.getLogger(ShiroSessionFilter. class ); public List<String> excludes = new ArrayList<String>(); private long serverSessionTimeout = 180000L; //ms public void doFilter(ServletRequest request, ServletResponse response, FilterChain filterChain) throws IOException,ServletException { if (logger.isDebugEnabled()){ logger.debug( "shiro session filter is open" ); } HttpServletRequest req = (HttpServletRequest) request; HttpServletResponse resp = (HttpServletResponse) response; if (handleExcludeURL(req, resp)){ filterChain.doFilter(request, response); return ; } Subject currentUser = SecurityUtils.getSubject(); if (currentUser.isAuthenticated()){ currentUser.getSession().setTimeout(serverSessionTimeout); } filterChain.doFilter(request, response); } private boolean handleExcludeURL(HttpServletRequest request, HttpServletResponse response) { if (excludes == null || excludes.isEmpty()) { return false ; } String url = request.getServletPath(); for (String pattern : excludes) { Pattern p = Pattern.compile( "^" + pattern); Matcher m = p.matcher(url); if (m.find()) { return true ; } } return false ; } @Override public void init(FilterConfig filterConfig) throws ServletException { if (logger.isDebugEnabled()){ logger.debug( "shiro session filter init~~~~~~~~~~~~" ); } String temp = filterConfig.getInitParameter( "excludes" ); if (temp != null ) { String[] url = temp.split( "," ); for ( int i = 0 ; url != null && i < url.length; i++) { excludes.add(url[i]); } } String timeout = filterConfig.getInitParameter( "serverSessionTimeout" ); if (StringUtils.isNotBlank(timeout)){ this .serverSessionTimeout = NumberUtils.toLong(timeout,1800L)*1000L; } } @Override public void destroy() {} } |
注冊filter
在被@Configuration注解標注的類內注冊ShiroSessionFilter。
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
|
@Value ( "${server.session.timeout}" ) private String serverSessionTimeout; @Bean public FilterRegistrationBean shiroSessionFilterRegistrationBean() { FilterRegistrationBean filterRegistrationBean = new FilterRegistrationBean(); filterRegistrationBean.setFilter( new ShiroSessionFilter()); filterRegistrationBean.setOrder(FilterRegistrationBean.LOWEST_PRECEDENCE); filterRegistrationBean.setEnabled( true ); filterRegistrationBean.addUrlPatterns( "/*" ); Map<String, String> initParameters = Maps.newHashMap(); initParameters.put( "serverSessionTimeout" , serverSessionTimeout); initParameters.put( "excludes" , "/favicon.ico,/img/*,/js/*,/css/*" ); filterRegistrationBean.setInitParameters(initParameters); return filterRegistrationBean; } |
這樣當每次請求時,如果用戶已登錄,就重新設置shiro session有效期,從而和server session保持了一致。
總結
以上就是這篇文章的全部內容,希望本文的內容對大家的學習或者工作具有一定的參考學習價值,如果有疑問大家可以留言交流,謝謝大家對服務器之家的支持。
原文鏈接:http://www.jianshu.com/p/21d800215c17