JwtAuthenticationProvider.java 1.91 KB
Newer Older
eddie.woo's avatar
eddie.woo committed
1 2
package pwc.taxtech.atms.security;

eddie.woo's avatar
eddie.woo committed
3
import io.jsonwebtoken.ExpiredJwtException;
eddie.woo's avatar
eddie.woo committed
4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.security.authentication.BadCredentialsException;
import org.springframework.security.authentication.UsernamePasswordAuthenticationToken;
import org.springframework.security.authentication.dao.AbstractUserDetailsAuthenticationProvider;
import org.springframework.security.core.AuthenticationException;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.stereotype.Component;

@Component
public class JwtAuthenticationProvider extends AbstractUserDetailsAuthenticationProvider {

    @Autowired
    private JwtUtil jwtUtil;

    @Override
    public boolean supports(Class<?> authentication) {
        return (JwtAuthenticationToken.class.isAssignableFrom(authentication));
    }

    @Override
    protected void additionalAuthenticationChecks(UserDetails userDetails,
            UsernamePasswordAuthenticationToken authentication) throws AuthenticationException {
        // 如果需要连接数据库查询User状态,可以增强该方法
    }

    @Override
    protected UserDetails retrieveUser(String username, UsernamePasswordAuthenticationToken authentication)
            throws AuthenticationException {
        JwtAuthenticationToken jwtAuthenticationToken = (JwtAuthenticationToken) authentication;
        String token = jwtAuthenticationToken.getToken();

eddie.woo's avatar
eddie.woo committed
35 36 37 38 39 40 41 42
        JwtUser parsedUser;
        try {
            parsedUser = jwtUtil.parseToken(token);
        } catch (ExpiredJwtException e) {
            throw new BadCredentialsException("Expired jwt token");
        } catch (Exception e) {
            throw new BadCredentialsException("Bad jwt token", e);
        }
eddie.woo's avatar
eddie.woo committed
43 44 45 46 47 48 49 50 51

        if (parsedUser == null) {
            throw new BadCredentialsException("JWT token is not valid");
        }

        return parsedUser;
    }

}