package com.ff.base.utils; import com.ff.base.constant.Constants; import com.ff.base.constant.HttpStatus; import com.ff.base.core.domain.model.LoginUser; import com.ff.base.exception.ServiceException; import com.ff.base.system.domain.SysRole; import com.ff.base.utils.bean.BeanUtils; import com.ff.base.utils.sign.Md5Utils; import com.ff.base.utils.spring.SpringUtils; import com.ff.base.web.service.TokenService; import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; import org.springframework.security.core.Authentication; import org.springframework.security.core.context.SecurityContextHolder; import org.springframework.util.PatternMatchUtils; import javax.management.relation.Role; import java.util.Collection; import java.util.List; import java.util.Set; import java.util.stream.Collectors; /** * 安全服务工具类 * * @author ff */ public class SecurityUtils { /** * 获取用户id或null * * @return {@link Long } */ public static Long getUserIdOrNull() { try { return getLoginUser().getUserId(); } catch (Exception e) { return null; } } /** * 用户ID **/ public static Long getUserId() { try { return getLoginUser().getUserId(); } catch (Exception e) { throw new ServiceException("获取用户ID异常", HttpStatus.UNAUTHORIZED); } } /** * 获取角色 * * @return {@link List }<{@link SysRole }> */ public static List getRoles() { try { return getLoginUser().getUser().getRoles(); } catch (Exception e) { throw new ServiceException("获取用户角色异常", HttpStatus.UNAUTHORIZED); } } /** * 获取部门ID **/ public static Long getDeptId() { try { return getLoginUser().getDeptId(); } catch (Exception e) { throw new ServiceException("获取部门ID异常", HttpStatus.UNAUTHORIZED); } } /** * 获取用户账户 **/ public static String getUsername() { try { return getLoginUser().getUsername(); } catch (Exception e) { throw new ServiceException("获取用户账户异常", HttpStatus.UNAUTHORIZED); } } /** * 获取用户账户 **/ public static String getUsernameOrNull() { try { return getLoginUser().getUsername(); } catch (Exception e) { return null; } } /** * 获取用户 **/ public static LoginUser getLoginUser() { try { return (LoginUser) getAuthentication().getPrincipal(); } catch (Exception e) { throw new ServiceException("获取用户信息异常", HttpStatus.UNAUTHORIZED); } } public static void setLoginUser(LoginUser loginUser) { try { LoginUser principal = (LoginUser) getAuthentication().getPrincipal(); BeanUtils.copyProperties(loginUser,principal); UsernamePasswordAuthenticationToken authentication = (UsernamePasswordAuthenticationToken) SecurityContextHolder.getContext().getAuthentication(); UsernamePasswordAuthenticationToken copy = new UsernamePasswordAuthenticationToken(principal,null); // 修改原对象为空的字段不修改 BeanUtils.nullAwareCopyProperties(copy,authentication); SecurityContextHolder.getContext().setAuthentication(authentication); SpringUtils.getBean(TokenService.class).setLoginUser(loginUser); } catch (Exception e) { throw new ServiceException("获取用户信息异常", HttpStatus.UNAUTHORIZED); } } /** * 获取Authentication */ public static Authentication getAuthentication() { return SecurityContextHolder.getContext().getAuthentication(); } /** * 生成BCryptPasswordEncoder密码 * * @param password 密码 * @return 加密字符串 */ public static String encryptPassword(String password) { return Md5Utils.hash(password); } /** * 判断密码是否相同 * * @param rawPassword 真实密码 * @param encodedPassword 加密后字符 * @return 结果 */ public static boolean matchesPassword(String rawPassword, String encodedPassword) { return StringUtils.equals(Md5Utils.hash(rawPassword), encodedPassword); } /** * 是否为管理员 * * @param userId 用户ID * @return 结果 */ public static boolean isAdmin(Long userId) { return userId != null && 1L == userId; } /** * 验证用户是否具备某权限 * * @param permission 权限字符串 * @return 用户是否具备某权限 */ public static boolean hasPermi(String permission) { return hasPermi(getLoginUser().getPermissions(), permission); } /** * 判断是否包含权限 * * @param authorities 权限列表 * @param permission 权限字符串 * @return 用户是否具备某权限 */ public static boolean hasPermi(Collection authorities, String permission) { return authorities.stream().filter(StringUtils::hasText) .anyMatch(x -> Constants.ALL_PERMISSION.equals(x) || PatternMatchUtils.simpleMatch(x, permission)); } /** * 验证用户是否拥有某个角色 * * @param role 角色标识 * @return 用户是否具备某角色 */ public static boolean hasRole(String role) { List roleList = getLoginUser().getUser().getRoles(); Collection roles = roleList.stream().map(SysRole::getRoleKey).collect(Collectors.toSet()); return hasRole(roles, role); } /** * 判断是否包含角色 * * @param roles 角色列表 * @param role 角色 * @return 用户是否具备某角色权限 */ public static boolean hasRole(Collection roles, String role) { return roles.stream().filter(StringUtils::hasText) .anyMatch(x -> Constants.SUPER_ADMIN.equals(x) || PatternMatchUtils.simpleMatch(x, role)); } }