diff --git a/cutejava-springboot3/cutejava-framework/src/main/java/cn/odboy/framework/context/BootApplication.java b/cutejava-springboot3/cutejava-framework/src/main/java/cn/odboy/framework/context/BootApplication.java index 8d75b9c3..c22c1e6e 100644 --- a/cutejava-springboot3/cutejava-framework/src/main/java/cn/odboy/framework/context/BootApplication.java +++ b/cutejava-springboot3/cutejava-framework/src/main/java/cn/odboy/framework/context/BootApplication.java @@ -47,8 +47,10 @@ public class BootApplication { env.getProperty("config.servlet.context-path"); log.info( "\n----------------------------------------------------------\n\t" + - "Application is running! Access URLs:\n\t" + "Local: \t\thttp://localhost:" + port + path + "/\n\t" + - "External: \thttp://" + ip + ":" + port + path + "/\n\t" + "Swagger文档: \thttp://" + ip + ":" + port + - path + "/doc.html\n" + "----------------------------------------------------------"); + "Application is running! Access URLs:\n\t" + + "Local: \t\thttp://localhost:" + port + path + "/\n\t" + + "External: \thttp://" + ip + ":" + port + path + "/\n\t" +// + "Swagger文档: \thttp://" + ip + ":" + port + path + "/doc.html\n" + + "----------------------------------------------------------"); } } \ No newline at end of file diff --git a/cutejava-springboot3/cutejava-framework/src/main/java/cn/odboy/framework/doc/SwaggerConfig.java b/cutejava-springboot3/cutejava-framework/src/main/java/cn/odboy/framework/doc/SwaggerConfig.java index 30e78ee0..1efee521 100644 --- a/cutejava-springboot3/cutejava-framework/src/main/java/cn/odboy/framework/doc/SwaggerConfig.java +++ b/cutejava-springboot3/cutejava-framework/src/main/java/cn/odboy/framework/doc/SwaggerConfig.java @@ -1,48 +1,48 @@ -/* - * Copyright 2021-2025 Odboy - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package cn.odboy.framework.doc; - -import cn.odboy.framework.properties.AppProperties; -import io.swagger.v3.oas.models.Components; -import io.swagger.v3.oas.models.OpenAPI; -import io.swagger.v3.oas.models.info.Info; -import io.swagger.v3.oas.models.security.SecurityRequirement; -import io.swagger.v3.oas.models.security.SecurityScheme; -import org.springframework.beans.factory.annotation.Autowired; -import org.springframework.context.annotation.Bean; -import org.springframework.context.annotation.Configuration; - -/** - * api页面 /doc.html - */ -@Configuration -public class SwaggerConfig { - @Autowired - private AppProperties properties; - - @Bean - public OpenAPI customOpenAPI() { - // 添加开关控制 - if (!properties.getSwagger().getEnabled()) { - return new OpenAPI(); - } - return new OpenAPI().components(new Components().addSecuritySchemes("Authorization", - new SecurityScheme().name("Authorization").type(SecurityScheme.Type.APIKEY).in(SecurityScheme.In.HEADER))) - .info(new Info().title("CuteJava 接口文档").version("1.4.1").description("一个简单且易上手的自动化运维平台")) - .addSecurityItem(new SecurityRequirement().addList("Authorization")); - } -} +///* +// * Copyright 2021-2025 Odboy +// * +// * Licensed under the Apache License, Version 2.0 (the "License"); +// * you may not use this file except in compliance with the License. +// * You may obtain a copy of the License at +// * +// * http://www.apache.org/licenses/LICENSE-2.0 +// * +// * Unless required by applicable law or agreed to in writing, software +// * distributed under the License is distributed on an "AS IS" BASIS, +// * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// * See the License for the specific language governing permissions and +// * limitations under the License. +// */ +// +//package cn.odboy.framework.doc; +// +//import cn.odboy.framework.properties.AppProperties; +//import io.swagger.v3.oas.models.Components; +//import io.swagger.v3.oas.models.OpenAPI; +//import io.swagger.v3.oas.models.info.Info; +//import io.swagger.v3.oas.models.security.SecurityRequirement; +//import io.swagger.v3.oas.models.security.SecurityScheme; +//import org.springframework.beans.factory.annotation.Autowired; +//import org.springframework.context.annotation.Bean; +//import org.springframework.context.annotation.Configuration; +// +///** +// * api页面 /doc.html +// */ +//@Configuration +//public class SwaggerConfig { +// @Autowired +// private AppProperties properties; +// +// @Bean +// public OpenAPI customOpenAPI() { +// // 添加开关控制 +// if (!properties.getSwagger().getEnabled()) { +// return new OpenAPI(); +// } +// return new OpenAPI().components(new Components().addSecuritySchemes("Authorization", +// new SecurityScheme().name("Authorization").type(SecurityScheme.Type.APIKEY).in(SecurityScheme.In.HEADER))) +// .info(new Info().title("CuteJava 接口文档").version("1.4.1").description("一个简单且易上手的自动化运维平台")) +// .addSecurityItem(new SecurityRequirement().addList("Authorization")); +// } +//} diff --git a/cutejava-springboot3/cutejava-module-system/src/main/java/cn/odboy/system/framework/permission/config/SpringSecurityConfig.java b/cutejava-springboot3/cutejava-module-system/src/main/java/cn/odboy/system/framework/permission/config/SpringSecurityConfig.java index 46b09c13..6a340a85 100644 --- a/cutejava-springboot3/cutejava-module-system/src/main/java/cn/odboy/system/framework/permission/config/SpringSecurityConfig.java +++ b/cutejava-springboot3/cutejava-module-system/src/main/java/cn/odboy/system/framework/permission/config/SpringSecurityConfig.java @@ -75,71 +75,46 @@ public class SpringSecurityConfig { protected SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception { // 获取匿名标记 Map> anonymousUrls = CsAnonTagUtil.getAnonymousUrl(applicationContext); - + // 创建TokenFilter实例 TokenFilter customFilter = new TokenFilter(tokenProvider, systemUserOnlineInfoDAO); - + return httpSecurity - // 禁用 CSRF - .csrf(AbstractHttpConfigurer::disable) - .addFilter(corsFilter) - .addFilterBefore(customFilter, UsernamePasswordAuthenticationFilter.class) - // 授权异常 - .exceptionHandling(exceptionHandling -> exceptionHandling - .authenticationEntryPoint(authenticationErrorHandler) - .accessDeniedHandler(jwtAccessDeniedHandler)) - // 防止iframe 造成跨域 - .headers(headers -> headers - .frameOptions(HeadersConfigurer.FrameOptionsConfig::disable)) - // 不创建会话 - .sessionManagement(sessionManagement -> sessionManagement - .sessionCreationPolicy(SessionCreationPolicy.STATELESS)) - .authorizeHttpRequests(authorizeRequests -> authorizeRequests - // 静态资源等等 - .requestMatchers(HttpMethod.GET, "/*.html", "/**/*.html", "/**/*.css", "/**/*.js", "/websocket/**") - .permitAll() - // swagger 文档 - .requestMatchers("/swagger-ui.html") - .permitAll() - .requestMatchers("/swagger-resources/**") - .permitAll() - .requestMatchers("/webjars/**") - .permitAll() - .requestMatchers("/*/api-docs") - .permitAll() - // 文件 - .requestMatchers("/avatar/**") - .permitAll() - .requestMatchers("/file/**") - .permitAll() - // 阿里巴巴 druid - .requestMatchers("/druid/**") - .permitAll() - // 放行OPTIONS请求 - .requestMatchers(HttpMethod.OPTIONS, "/**") - .permitAll() - // 自定义匿名访问所有url放行:允许匿名和带Token访问,细腻化到每个 Request 类型 - // GET - .requestMatchers(HttpMethod.GET, anonymousUrls.get(RequestMethodEnum.GET.getType()).toArray(new String[0])) - .permitAll() - // POST - .requestMatchers(HttpMethod.POST, anonymousUrls.get(RequestMethodEnum.POST.getType()).toArray(new String[0])) - .permitAll() - // PUT - .requestMatchers(HttpMethod.PUT, anonymousUrls.get(RequestMethodEnum.PUT.getType()).toArray(new String[0])) - .permitAll() - // PATCH - .requestMatchers(HttpMethod.PATCH, anonymousUrls.get(RequestMethodEnum.PATCH.getType()).toArray(new String[0])) - .permitAll() - // DELETE - .requestMatchers(HttpMethod.DELETE, anonymousUrls.get(RequestMethodEnum.DELETE.getType()).toArray(new String[0])) - .permitAll() - // 所有类型的接口都放行 - .requestMatchers(anonymousUrls.get(RequestMethodEnum.ALL.getType()).toArray(new String[0])) - .permitAll() - // 所有请求都需要认证 - .anyRequest() - .authenticated()) - .build(); + // 禁用 CSRF + .csrf(AbstractHttpConfigurer::disable).addFilter(corsFilter).addFilterBefore(customFilter, UsernamePasswordAuthenticationFilter.class) + // 授权异常 + .exceptionHandling( + exceptionHandling -> exceptionHandling.authenticationEntryPoint(authenticationErrorHandler).accessDeniedHandler(jwtAccessDeniedHandler)) + // 防止iframe 造成跨域 + .headers(headers -> headers.frameOptions(HeadersConfigurer.FrameOptionsConfig::disable)) + // 不创建会话 + .sessionManagement(sessionManagement -> sessionManagement.sessionCreationPolicy(SessionCreationPolicy.STATELESS)) + .authorizeHttpRequests(authorizeRequests -> authorizeRequests + // 静态资源等等 + .requestMatchers(HttpMethod.GET, "*.html", "*.css", "*.js", "/websocket/**").permitAll() +// // Knife4j 和 OpenAPI 相关路径 +// .requestMatchers("/doc.html", "/webjars/**", "/v3/api-docs", "/v3/api-docs/**", "/swagger-resources", "/swagger-resources/**", +// "/configuration/ui", "/configuration/security").permitAll() + // 文件 + .requestMatchers("/avatar/**").permitAll().requestMatchers("/file/**").permitAll() + // 阿里巴巴 druid + .requestMatchers("/druid/**").permitAll() + // 放行OPTIONS请求 + .requestMatchers(HttpMethod.OPTIONS, "/**").permitAll() + // 自定义匿名访问所有url放行:允许匿名和带Token访问,细腻化到每个 Request 类型 + // GET + .requestMatchers(HttpMethod.GET, anonymousUrls.get(RequestMethodEnum.GET.getType()).toArray(new String[0])).permitAll() + // POST + .requestMatchers(HttpMethod.POST, anonymousUrls.get(RequestMethodEnum.POST.getType()).toArray(new String[0])).permitAll() + // PUT + .requestMatchers(HttpMethod.PUT, anonymousUrls.get(RequestMethodEnum.PUT.getType()).toArray(new String[0])).permitAll() + // PATCH + .requestMatchers(HttpMethod.PATCH, anonymousUrls.get(RequestMethodEnum.PATCH.getType()).toArray(new String[0])).permitAll() + // DELETE + .requestMatchers(HttpMethod.DELETE, anonymousUrls.get(RequestMethodEnum.DELETE.getType()).toArray(new String[0])).permitAll() + // 所有类型的接口都放行 + .requestMatchers(anonymousUrls.get(RequestMethodEnum.ALL.getType()).toArray(new String[0])).permitAll() + // 所有请求都需要认证 + .anyRequest().authenticated()).build(); } } \ No newline at end of file diff --git a/cutejava-springboot3/pom.xml b/cutejava-springboot3/pom.xml index 45562dcb..f02c9687 100644 --- a/cutejava-springboot3/pom.xml +++ b/cutejava-springboot3/pom.xml @@ -154,19 +154,19 @@ commons-lang3 - + p6spy p6spy 3.9.1 - - - com.github.xiaoymin - knife4j-openapi3-jakarta-spring-boot-starter - 4.5.0 - + + + + + + io.swagger swagger-annotations