设为首页 收藏本站
查看: 626|回复: 0

[经验分享] Apache CXF实战之六 创建安全的Web Service

[复制链接]

尚未签到

发表于 2017-1-8 12:48:37 | 显示全部楼层 |阅读模式
  本文链接:http://blog.csdn.net/kongxx/article/details/7534035
  Apache CXF实战之一 Hello World Web Service
  Apache CXF实战之二 集成Sping与Web容器
  Apache CXF实战之三 传输Java对象
  Apache CXF实战之四 构建RESTful Web Service
  Apache CXF实战之五 压缩Web Service数据
  我们在使用Web Service的过程中,很多情况是需要对web service请求做认证的,对于运行在web容器里的应用程序来说,可能会比较简单一些,通常可以通过filter来做一些处理,但是其实CXF本身也提供了对web service认证的方式。下面来看一下如何实现
  1. 首先是一个简单pojo

package com.googlecode.garbagecan.cxfstudy.security;public class User {private String id;private String name;private String password;public String getId() {return id;}public void setId(String id) {this.id = id;}public String getName() {return name;}public void setName(String name) {this.name = name;}public String getPassword() {return password;}public void setPassword(String password) {this.password = password;}}2. Web Service接口package com.googlecode.garbagecan.cxfstudy.security;import java.util.List;import javax.jws.WebMethod;import javax.jws.WebResult;import javax.jws.WebService;@WebServicepublic interface UserService {@WebMethod@WebResult List<User> list();}3. Web Service实现类package com.googlecode.garbagecan.cxfstudy.security;import java.util.ArrayList;import java.util.List;public class UserServiceImpl implements UserService {public List<User> list() {List<User> users = new ArrayList<User>();for (int i = 0; i < 10; i++) {User user = new User();user.setId("" + i);user.setName("user_" + i);user.setPassword("password_" + i);users.add(user);}return users;}}4. Server端Handler,其中使用了一个Map来存放用户信息,真是应用中可以使用数据库或者其它方式获取用户和密码package com.googlecode.garbagecan.cxfstudy.security;import java.io.IOException;import java.util.HashMap;import java.util.Map;import javax.security.auth.callback.Callback;import javax.security.auth.callback.CallbackHandler;import javax.security.auth.callback.UnsupportedCallbackException;import org.apache.ws.security.WSPasswordCallback;public class ServerUsernamePasswordHandler implements CallbackHandler {// key is username, value is passwordprivate Map<String, String> users;public ServerUsernamePasswordHandler() {users = new HashMap<String, String>();users.put("admin", "admin");}public void handle(Callback[] callbacks) throws IOException, UnsupportedCallbackException {WSPasswordCallback callback = (WSPasswordCallback) callbacks[0];String id = callback.getIdentifier();if (users.containsKey(id)) {if (!callback.getPassword().equals(users.get(id))) {throw new SecurityException("Incorrect password.");}} else {throw new SecurityException("Invalid user.");}}}5. Client端Handler,用来设置用户密码,在真实应用中可以根据此类和下面的测试类来修改逻辑设置用户名和密码。package com.googlecode.garbagecan.cxfstudy.security;import java.io.IOException;import javax.security.auth.callback.Callback;import javax.security.auth.callback.CallbackHandler;import javax.security.auth.callback.UnsupportedCallbackException;import org.apache.ws.security.WSPasswordCallback;public class ClientUsernamePasswordHandler implements CallbackHandler {public void handle(Callback[] callbacks) throws IOException, UnsupportedCallbackException {WSPasswordCallback callback = (WSPasswordCallback) callbacks[0];int usage = callback.getUsage();System.out.println("identifier: " + callback.getIdentifier());System.out.println("usage: " + callback.getUsage());if (usage == WSPasswordCallback.USERNAME_TOKEN) {callback.setPassword("admin");}}}6. 单元测试类,注意在Server端添加了WSS4JInInterceptor到Interceptor列表中,在Client添加了WSS4JOutInterceptor到Interceptor列表中。package com.googlecode.garbagecan.cxfstudy.security;import java.net.SocketTimeoutException;import java.util.HashMap;import java.util.List;import java.util.Map;import javax.xml.ws.WebServiceException;import junit.framework.Assert;import org.apache.cxf.endpoint.Client;import org.apache.cxf.endpoint.Endpoint;import org.apache.cxf.frontend.ClientProxy;import org.apache.cxf.interceptor.LoggingInInterceptor;import org.apache.cxf.interceptor.LoggingOutInterceptor;import org.apache.cxf.jaxws.JaxWsProxyFactoryBean;import org.apache.cxf.jaxws.JaxWsServerFactoryBean;import org.apache.cxf.transport.http.HTTPConduit;import org.apache.cxf.transports.http.configuration.HTTPClientPolicy;import org.apache.cxf.ws.security.wss4j.WSS4JInInterceptor;import org.apache.cxf.ws.security.wss4j.WSS4JOutInterceptor;import org.apache.ws.security.WSConstants;import org.apache.ws.security.handler.WSHandlerConstants;import org.junit.BeforeClass;import org.junit.Test;public class UserServiceTest {private static final String address = "http://localhost:9000/ws/security/userService";@BeforeClasspublic static void setUpBeforeClass() throws Exception {JaxWsServerFactoryBean factoryBean = new JaxWsServerFactoryBean();factoryBean.getInInterceptors().add(new LoggingInInterceptor());factoryBean.getOutInterceptors().add(new LoggingOutInterceptor());Map<String, Object> props = new HashMap<String, Object>();props.put("action", "UsernameToken");props.put("passwordType", "PasswordText");props.put("passwordCallbackClass", ServerUsernamePasswordHandler.class.getName());WSS4JInInterceptor wss4JInInterceptor = new WSS4JInInterceptor(props);factoryBean.getInInterceptors().add(wss4JInInterceptor);factoryBean.setServiceClass(UserServiceImpl.class);factoryBean.setAddress(address);factoryBean.create();}@Testpublic void testList() {JaxWsProxyFactoryBean factoryBean = new JaxWsProxyFactoryBean();factoryBean.setAddress(address);factoryBean.setServiceClass(UserService.class);Object obj = factoryBean.create();Client client = ClientProxy.getClient(obj);Endpoint endpoint = client.getEndpoint();Map<String,Object> props = new HashMap<String,Object>();props.put(WSHandlerConstants.ACTION, WSHandlerConstants.USERNAME_TOKEN);props.put(WSHandlerConstants.USER, "admin");props.put(WSHandlerConstants.PASSWORD_TYPE, WSConstants.PW_TEXT);props.put(WSHandlerConstants.PW_CALLBACK_CLASS, ClientUsernamePasswordHandler.class.getName());WSS4JOutInterceptor wss4JOutInterceptor = new WSS4JOutInterceptor(props);endpoint.getOutInterceptors().add(wss4JOutInterceptor);HTTPConduit conduit = (HTTPConduit) client.getConduit();HTTPClientPolicy policy = new HTTPClientPolicy();policy.setConnectionTimeout(5 * 1000);policy.setReceiveTimeout(5 * 1000);conduit.setClient(policy);UserService service = (UserService) obj;try {List<User> users = service.list();Assert.assertNotNull(users);Assert.assertEquals(10, users.size());} catch(Exception e) {if (e instanceof WebServiceException && e.getCause() instanceof SocketTimeoutException) {System.err.println("This is timeout exception.");} else {e.printStackTrace();}}}}最后运行上面的测试类来测试结果,也可以修改测试方法中的密码,看看错误结果,这里就不在写错误密码的测试用例了,因为我是一懒人。  

  

运维网声明 1、欢迎大家加入本站运维交流群:群②:261659950 群⑤:202807635 群⑦870801961 群⑧679858003
2、本站所有主题由该帖子作者发表,该帖子作者与运维网享有帖子相关版权
3、所有作品的著作权均归原作者享有,请您和我们一样尊重他人的著作权等合法权益。如果您对作品感到满意,请购买正版
4、禁止制作、复制、发布和传播具有反动、淫秽、色情、暴力、凶杀等内容的信息,一经发现立即删除。若您因此触犯法律,一切后果自负,我们对此不承担任何责任
5、所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其内容的准确性、可靠性、正当性、安全性、合法性等负责,亦不承担任何法律责任
6、所有作品仅供您个人学习、研究或欣赏,不得用于商业或者其他用途,否则,一切后果均由您自己承担,我们对此不承担任何法律责任
7、如涉及侵犯版权等问题,请您及时通知我们,我们将立即采取措施予以解决
8、联系人Email:admin@iyunv.com 网址:www.yunweiku.com

所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其承担任何法律责任,如涉及侵犯版权等问题,请您及时通知我们,我们将立即处理,联系人Email:kefu@iyunv.com,QQ:1061981298 本贴地址:https://www.yunweiku.com/thread-325573-1-1.html 上篇帖子: apache-2.0.52自动启动的问题 下篇帖子: apache http server tomcat jk 配置,实现url rewrite功能
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

扫码加入运维网微信交流群X

扫码加入运维网微信交流群

扫描二维码加入运维网微信交流群,最新一手资源尽在官方微信交流群!快快加入我们吧...

扫描微信二维码查看详情

客服E-mail:kefu@iyunv.com 客服QQ:1061981298


QQ群⑦:运维网交流群⑦ QQ群⑧:运维网交流群⑧ k8s群:运维网kubernetes交流群


提醒:禁止发布任何违反国家法律、法规的言论与图片等内容;本站内容均来自个人观点与网络等信息,非本站认同之观点.


本站大部分资源是网友从网上搜集分享而来,其版权均归原作者及其网站所有,我们尊重他人的合法权益,如有内容侵犯您的合法权益,请及时与我们联系进行核实删除!



合作伙伴: 青云cloud

快速回复 返回顶部 返回列表