2016-07-05 120 views
1

我试图执行本教程https://spring.io/guides/tutorials/spring-boot-oauth2/#_social_login_logout 这是我的应用程序配置(春季启动)如何将Facebook认证的用户存储在数据库中?

@Configuration 
@ComponentScan(basePackages = {"org.fiodorov.controller","org.fiodorov.service", "org.fiodorov.config"}) 
@EntityScan(basePackages = "org.fiodorov.model") 
@EnableJpaRepositories(basePackages = "org.fiodorov.repository") 
@EnableOAuth2Client 
@EnableAutoConfiguration 
public class Application extends WebSecurityConfigurerAdapter{ 

    @Autowired 
    OAuth2ClientContext oauth2ClientContext; 

    @Override 
    protected void configure(HttpSecurity http) throws Exception { 
     http.antMatcher("/**") 
     .addFilterBefore(ssoFilter(), BasicAuthenticationFilter.class); 
    } 


    public static void main(String[] args) { 
     SpringApplication.run(
       Application.class, args); 
    } 

    private Filter ssoFilter() { 
     OAuth2ClientAuthenticationProcessingFilter facebookFilter = new OAuth2ClientAuthenticationProcessingFilter("/login/facebook"); 
     OAuth2RestTemplate facebookTemplate = new OAuth2RestTemplate(facebook(), oauth2ClientContext); 
     facebookFilter.setRestTemplate(facebookTemplate); 
     facebookFilter.setTokenServices(new UserInfoTokenServices(facebookResource().getUserInfoUri(), facebook().getClientId())); 
     return facebookFilter; 
    } 

    @Bean 
    @ConfigurationProperties("facebook.client") 
    OAuth2ProtectedResourceDetails facebook() { 
     return new AuthorizationCodeResourceDetails(); 
    } 

    @Bean 
    @ConfigurationProperties("facebook.resource") 
    ResourceServerProperties facebookResource() { 
     return new ResourceServerProperties(); 
    } 

    @Bean 
    public FilterRegistrationBean oauth2ClientFilterRegistration(
      OAuth2ClientContextFilter filter) { 
     FilterRegistrationBean registration = new FilterRegistrationBean(); 
     registration.setFilter(filter); 
     registration.setOrder(-100); 
     return registration; 
    } 

} 

和它的作品。我可以登录并获取用户信息,如教程中所述。但我不知道如何才能在登录之后以及在重定向到主页面之前找到那一刻,以便在用户不存在的情况下将用户详细信息存储在数据库中,并在存在的情况下验证其角色。

我该怎么做?

回答

2

呦可以使这个类在登录后在数据库中存储用户的详细信息。 成功登录后执行认证

class OAuth2ClientAuthenticationProcessingAndSavingFilter extends OAuth2ClientAuthenticationProcessingFilter { 

    public OAuth2ClientAuthenticationProcessingAndSavingFilter(String defaultFilterProcessesUrl) { 
     super(defaultFilterProcessesUrl); 
    } 

    @Override 
    protected void successfulAuthentication(HttpServletRequest request, HttpServletResponse response, 
      FilterChain chain, Authentication authResult) throws IOException, ServletException { 
     super.successfulAuthentication(request, response, chain, authResult); 

     SecurityContext context = SecurityContextHolder.getContext(); 
    } 
} 

后,必须通过OAuth2ClientAuthenticationProcessingAndSavingFilter

private Filter ssoFilter() { 
     OAuth2ClientAuthenticationProcessingAndSavingFilter facebookFilter = new OAuth2ClientAuthenticationProcessingAndSavingFilter("/login/facebook"); 
     OAuth2RestTemplate facebookTemplate = new OAuth2RestTemplate(facebook(), oauth2ClientContext); 
     facebookFilter.setRestTemplate(facebookTemplate); 
     facebookFilter.setTokenServices(new UserInfoTokenServices(facebookResource().getUserInfoUri(), facebook().getClientId())); 
     return facebookFilter; 
    } 
修饰OAuth2ClientAuthenticationProcessingFilter
相关问题