From 6e9bb2b31aa3212c0daabef54a3a355f99b038fc Mon Sep 17 00:00:00 2001 From: click33 <2393584716@qq.com> Date: Sat, 3 May 2025 12:04:14 +0800 Subject: [PATCH] =?UTF-8?q?feat(sso):=20=E6=96=B0=E5=A2=9E=20SSO=20Strateg?= =?UTF-8?q?y=20=E7=AD=96=E7=95=A5=E7=B1=BB?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../java/com/pj/sso/SsoServerController.java | 10 +-- .../java/com/pj/sso/SsoClientController.java | 4 +- .../java/com/pj/sso/SsoClientController.java | 4 +- .../satoken/sso/config/SaSsoClientConfig.java | 11 ---- .../satoken/sso/config/SaSsoServerConfig.java | 30 --------- .../server/SaSsoMessageCheckTicketHandle.java | 2 +- .../sso/processor/SaSsoClientProcessor.java | 4 +- .../sso/processor/SaSsoServerProcessor.java | 4 +- .../sso/strategy/SaSsoClientStrategy.java | 44 +++++++++++++ .../sso/strategy/SaSsoServerStrategy.java | 61 +++++++++++++++++++ .../sso/template/SaSsoClientTemplate.java | 24 ++++++-- .../sso/template/SaSsoServerTemplate.java | 22 ++++++- .../satoken/sso/template/SaSsoTemplate.java | 30 +++------ .../satoken/solon/sso/SaSsoBeanRegister.java | 25 ++++++++ .../satoken/spring/sso/SaSsoBeanRegister.java | 24 ++++++++ 15 files changed, 217 insertions(+), 82 deletions(-) create mode 100644 sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/strategy/SaSsoClientStrategy.java create mode 100644 sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/strategy/SaSsoServerStrategy.java diff --git a/sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-server/src/main/java/com/pj/sso/SsoServerController.java b/sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-server/src/main/java/com/pj/sso/SsoServerController.java index 47897c8c..ff222752 100644 --- a/sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-server/src/main/java/com/pj/sso/SsoServerController.java +++ b/sa-token-demo/sa-token-demo-sso/sa-token-demo-sso-server/src/main/java/com/pj/sso/SsoServerController.java @@ -2,8 +2,8 @@ package com.pj.sso; import cn.dev33.satoken.context.SaHolder; import cn.dev33.satoken.sign.SaSignUtil; -import cn.dev33.satoken.sso.config.SaSsoServerConfig; import cn.dev33.satoken.sso.processor.SaSsoServerProcessor; +import cn.dev33.satoken.sso.template.SaSsoServerTemplate; import cn.dev33.satoken.stp.StpUtil; import cn.dev33.satoken.stp.parameter.SaLoginParameter; import cn.dev33.satoken.util.SaFoxUtil; @@ -35,15 +35,15 @@ public class SsoServerController { // 配置SSO相关参数 @Autowired - private void configSso(SaSsoServerConfig ssoServer) { - + private void configSso(SaSsoServerTemplate ssoServerTemplate) { + // 配置:未登录时返回的View - ssoServer.notLoginView = () -> { + ssoServerTemplate.strategy.notLoginView = () -> { return new ModelAndView("sa-login.html"); }; // 配置:登录处理函数 - ssoServer.doLoginHandle = (name, pwd) -> { + ssoServerTemplate.strategy.doLoginHandle = (name, pwd) -> { // 此处仅做模拟登录,真实环境应该查询数据进行登录 if("sa".equals(name) && "123456".equals(pwd)) { String deviceId = SaHolder.getRequest().getParam("deviceId", SaFoxUtil.getRandomString(32)); diff --git a/sa-token-demo/sa-token-demo-sso/sa-token-demo-sso2-client/src/main/java/com/pj/sso/SsoClientController.java b/sa-token-demo/sa-token-demo-sso/sa-token-demo-sso2-client/src/main/java/com/pj/sso/SsoClientController.java index 56eda97d..2fc5ecbc 100644 --- a/sa-token-demo/sa-token-demo-sso/sa-token-demo-sso2-client/src/main/java/com/pj/sso/SsoClientController.java +++ b/sa-token-demo/sa-token-demo-sso/sa-token-demo-sso2-client/src/main/java/com/pj/sso/SsoClientController.java @@ -1,8 +1,8 @@ package com.pj.sso; import cn.dev33.satoken.sso.SaSsoManager; -import cn.dev33.satoken.sso.config.SaSsoClientConfig; import cn.dev33.satoken.sso.processor.SaSsoClientProcessor; +import cn.dev33.satoken.sso.template.SaSsoClientTemplate; import cn.dev33.satoken.stp.StpUtil; import cn.dev33.satoken.util.SaResult; import org.springframework.beans.factory.annotation.Autowired; @@ -41,7 +41,7 @@ public class SsoClientController { // 配置SSO相关参数 @Autowired - private void configSso(SaSsoClientConfig ssoClient) { + private void configSso(SaSsoClientTemplate ssoClientTemplate) { } diff --git a/sa-token-demo/sa-token-demo-sso/sa-token-demo-sso3-client/src/main/java/com/pj/sso/SsoClientController.java b/sa-token-demo/sa-token-demo-sso/sa-token-demo-sso3-client/src/main/java/com/pj/sso/SsoClientController.java index 37578649..436ea459 100644 --- a/sa-token-demo/sa-token-demo-sso/sa-token-demo-sso3-client/src/main/java/com/pj/sso/SsoClientController.java +++ b/sa-token-demo/sa-token-demo-sso/sa-token-demo-sso3-client/src/main/java/com/pj/sso/SsoClientController.java @@ -1,7 +1,7 @@ package com.pj.sso; -import cn.dev33.satoken.sso.config.SaSsoClientConfig; import cn.dev33.satoken.sso.processor.SaSsoClientProcessor; +import cn.dev33.satoken.sso.template.SaSsoClientTemplate; import cn.dev33.satoken.sso.template.SaSsoUtil; import cn.dev33.satoken.stp.StpUtil; import cn.dev33.satoken.util.SaResult; @@ -43,7 +43,7 @@ public class SsoClientController { // 配置SSO相关参数 @Autowired - private void configSso(SaSsoClientConfig ssoClient) { + private void configSso(SaSsoClientTemplate ssoClientTemplate) { } diff --git a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/config/SaSsoClientConfig.java b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/config/SaSsoClientConfig.java index 3d4537c7..6f5d08ed 100644 --- a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/config/SaSsoClientConfig.java +++ b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/config/SaSsoClientConfig.java @@ -16,7 +16,6 @@ package cn.dev33.satoken.sso.config; -import cn.dev33.satoken.sso.function.TicketResultHandleFunction; import cn.dev33.satoken.util.SaFoxUtil; import java.io.Serializable; @@ -133,16 +132,6 @@ public class SaSsoClientConfig implements Serializable { } - // -------------------- 所有回调函数 -------------------- - - /** - * SSO-Client端:自定义校验 ticket 返回值的处理逻辑 (每次从认证中心获取校验 ticket 的结果后调用) - *
参数:loginId, back - *
返回值:返回给前端的值 - */ - public TicketResultHandleFunction ticketResultHandle = null; - - // get set /** diff --git a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/config/SaSsoServerConfig.java b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/config/SaSsoServerConfig.java index df59d9ce..a84793fb 100644 --- a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/config/SaSsoServerConfig.java +++ b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/config/SaSsoServerConfig.java @@ -16,12 +16,8 @@ package cn.dev33.satoken.sso.config; -import cn.dev33.satoken.sso.function.CheckTicketAppendDataFunction; -import cn.dev33.satoken.sso.function.DoLoginHandleFunction; -import cn.dev33.satoken.sso.function.NotLoginViewFunction; import cn.dev33.satoken.sso.template.SaSsoServerTemplate; import cn.dev33.satoken.util.SaFoxUtil; -import cn.dev33.satoken.util.SaResult; import java.io.Serializable; import java.util.LinkedHashMap; @@ -122,31 +118,6 @@ public class SaSsoServerConfig implements Serializable { } - // -------------------- 所有回调函数 -------------------- - - - /** - * SSO-Server端:未登录时返回的View - */ - public NotLoginViewFunction notLoginView = () -> { - return "当前会话在SSO-Server认证中心尚未登录(当前未配置登录视图)"; - }; - - /** - * SSO-Server端:登录函数 - */ - public DoLoginHandleFunction doLoginHandle = (name, pwd) -> { - return SaResult.error(); - }; - - /** - * SSO-Server端:在校验 ticket 后,给 sso-client 端追加返回信息的函数 - */ - public CheckTicketAppendDataFunction checkTicketAppendData = (loginId, result) -> { - return result; - }; - - // get set /** @@ -363,5 +334,4 @@ public class SaSsoServerConfig implements Serializable { + "]"; } - } diff --git a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/message/handle/server/SaSsoMessageCheckTicketHandle.java b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/message/handle/server/SaSsoMessageCheckTicketHandle.java index 1a106263..cc523dcc 100644 --- a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/message/handle/server/SaSsoMessageCheckTicketHandle.java +++ b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/message/handle/server/SaSsoMessageCheckTicketHandle.java @@ -94,7 +94,7 @@ public class SaSsoMessageCheckTicketHandle implements SaSsoMessageHandle { result.set(paramName.remainTokenTimeout, stpLogic.getTokenTimeout(ticketModel.getTokenValue())); result.set(paramName.remainSessionTimeout, stpLogic.getSessionTimeoutByLoginId(loginId)); - result = ssoServerConfig.checkTicketAppendData.apply(loginId, result); + result = ssoServerTemplate.strategy.checkTicketAppendData.apply(loginId, result); return result; } diff --git a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/processor/SaSsoClientProcessor.java b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/processor/SaSsoClientProcessor.java index d84357a4..cc3a5403 100644 --- a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/processor/SaSsoClientProcessor.java +++ b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/processor/SaSsoClientProcessor.java @@ -138,8 +138,8 @@ public class SaSsoClientProcessor { SaCheckTicketResult ctr = checkTicket(ticket, apiName.ssoLogin); // 2、如果开发者自定义了ticket结果值处理函数,则使用自定义的函数 - if(cfg.ticketResultHandle != null) { - return cfg.ticketResultHandle.run(ctr, back); + if(ssoClientTemplate.strategy.ticketResultHandle != null) { + return ssoClientTemplate.strategy.ticketResultHandle.run(ctr, back); } // 3、登录并重定向至back地址 diff --git a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/processor/SaSsoServerProcessor.java b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/processor/SaSsoServerProcessor.java index 52d5a0cb..bf4092f4 100644 --- a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/processor/SaSsoServerProcessor.java +++ b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/processor/SaSsoServerProcessor.java @@ -107,7 +107,7 @@ public class SaSsoServerProcessor { // ---------- 此处有两种情况分开处理: // ---- 情况1:在SSO认证中心尚未登录,需要先去登录 if( ! stpLogic.isLogin()) { - return cfg.notLoginView.get(); + return ssoServerTemplate.strategy.notLoginView.get(); } // ---- 情况2:在SSO认证中心已经登录,需要重定向回 Client 端,而这又分为两种方式: String mode = req.getParam(paramName.mode, SaSsoConsts.MODE_TICKET); @@ -155,7 +155,7 @@ public class SaSsoServerProcessor { ParamName paramName = ssoServerTemplate.paramName; // 处理 - return cfg.doLoginHandle.apply(req.getParam(paramName.name), req.getParam(paramName.pwd)); + return ssoServerTemplate.strategy.doLoginHandle.apply(req.getParam(paramName.name), req.getParam(paramName.pwd)); } /** diff --git a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/strategy/SaSsoClientStrategy.java b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/strategy/SaSsoClientStrategy.java new file mode 100644 index 00000000..e3d096fa --- /dev/null +++ b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/strategy/SaSsoClientStrategy.java @@ -0,0 +1,44 @@ +/* + * Copyright 2020-2099 sa-token.cc + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package cn.dev33.satoken.sso.strategy; + +import cn.dev33.satoken.SaManager; +import cn.dev33.satoken.sso.function.SendHttpFunction; +import cn.dev33.satoken.sso.function.TicketResultHandleFunction; + +/** + * Sa-Token SSO Client 相关策略 + * + * @author click33 + * @since 1.43.0 + */ +public class SaSsoClientStrategy { + + /** + * 发送 Http 请求的处理函数 + */ + public SendHttpFunction sendHttp = url -> { + return SaManager.getSaHttpTemplate().get(url); + }; + + /** + * SSO-Client端:自定义校验 ticket 返回值的处理逻辑 (每次从认证中心获取校验 ticket 的结果后调用) + *
参数:loginId, back + *
返回值:返回给前端的值
+ */
+ public TicketResultHandleFunction ticketResultHandle = null;
+
+}
diff --git a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/strategy/SaSsoServerStrategy.java b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/strategy/SaSsoServerStrategy.java
new file mode 100644
index 00000000..d6982f8d
--- /dev/null
+++ b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/strategy/SaSsoServerStrategy.java
@@ -0,0 +1,61 @@
+/*
+ * Copyright 2020-2099 sa-token.cc
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package cn.dev33.satoken.sso.strategy;
+
+import cn.dev33.satoken.SaManager;
+import cn.dev33.satoken.sso.function.CheckTicketAppendDataFunction;
+import cn.dev33.satoken.sso.function.DoLoginHandleFunction;
+import cn.dev33.satoken.sso.function.NotLoginViewFunction;
+import cn.dev33.satoken.sso.function.SendHttpFunction;
+import cn.dev33.satoken.util.SaResult;
+
+/**
+ * Sa-Token SSO Server 相关策略
+ *
+ * @author click33
+ * @since 1.43.0
+ */
+public class SaSsoServerStrategy {
+
+ /**
+ * 发送 Http 请求的处理函数
+ */
+ public SendHttpFunction sendHttp = url -> {
+ return SaManager.getSaHttpTemplate().get(url);
+ };
+
+ /**
+ * 未登录时返回的 View
+ */
+ public NotLoginViewFunction notLoginView = () -> {
+ return "当前会话在 SSO-Server 认证中心尚未登录(当前未配置登录视图)";
+ };
+
+ /**
+ * SSO-Server端:登录函数
+ */
+ public DoLoginHandleFunction doLoginHandle = (name, pwd) -> {
+ return SaResult.error();
+ };
+
+ /**
+ * SSO-Server端:在校验 ticket 后,给 sso-client 端追加返回信息的函数
+ */
+ public CheckTicketAppendDataFunction checkTicketAppendData = (loginId, result) -> {
+ return result;
+ };
+
+}
diff --git a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/template/SaSsoClientTemplate.java b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/template/SaSsoClientTemplate.java
index b38acee7..d7e03dd1 100644
--- a/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/template/SaSsoClientTemplate.java
+++ b/sa-token-plugin/sa-token-sso/src/main/java/cn/dev33/satoken/sso/template/SaSsoClientTemplate.java
@@ -24,6 +24,7 @@ import cn.dev33.satoken.sso.error.SaSsoErrorCode;
import cn.dev33.satoken.sso.exception.SaSsoException;
import cn.dev33.satoken.sso.message.SaSsoMessage;
import cn.dev33.satoken.sso.message.handle.client.SaSsoMessageLogoutCallHandle;
+import cn.dev33.satoken.sso.strategy.SaSsoClientStrategy;
import cn.dev33.satoken.sso.util.SaSsoConsts;
import cn.dev33.satoken.stp.parameter.SaLogoutParameter;
import cn.dev33.satoken.util.SaFoxUtil;
@@ -39,12 +40,16 @@ import java.util.Map;
*/
public class SaSsoClientTemplate extends SaSsoTemplate {
+ /**
+ * Client 相关策略
+ */
+ public SaSsoClientStrategy strategy = new SaSsoClientStrategy();
+
public SaSsoClientTemplate() {
super.messageHolder.addHandle(new SaSsoMessageLogoutCallHandle());
}
-
// ------------------- SSO 模式三相关 -------------------
/**
@@ -65,7 +70,7 @@ public class SaSsoClientTemplate extends SaSsoTemplate {
*/
public Object getData(String path, Map