JwtUtils.java 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141
  1. package com.genersoft.iot.vmp.conf.security;
  2. import com.genersoft.iot.vmp.conf.security.dto.JwtUser;
  3. import org.jose4j.json.JsonUtil;
  4. import org.jose4j.jwk.RsaJsonWebKey;
  5. import org.jose4j.jws.AlgorithmIdentifiers;
  6. import org.jose4j.jws.JsonWebSignature;
  7. import org.jose4j.jwt.JwtClaims;
  8. import org.jose4j.jwt.NumericDate;
  9. import org.jose4j.jwt.consumer.ErrorCodes;
  10. import org.jose4j.jwt.consumer.InvalidJwtException;
  11. import org.jose4j.jwt.consumer.JwtConsumer;
  12. import org.jose4j.jwt.consumer.JwtConsumerBuilder;
  13. import org.jose4j.lang.JoseException;
  14. import org.slf4j.Logger;
  15. import org.slf4j.LoggerFactory;
  16. import java.security.PrivateKey;
  17. import java.time.LocalDateTime;
  18. import java.time.ZoneOffset;
  19. public class JwtUtils {
  20. private static final Logger logger = LoggerFactory.getLogger(JwtUtils.class);
  21. private static final String HEADER = "access-token";
  22. private static final String AUDIENCE = "Audience";
  23. private static final long EXPIRED_THRESHOLD = 10 * 60;
  24. private static final String keyId = "3e79646c4dbc408383a9eed09f2b85ae";
  25. private static final String privateKeyStr = "{\"kty\":\"RSA\",\"kid\":\"3e79646c4dbc408383a9eed09f2b85ae\",\"alg\":\"RS256\",\"n\":\"gndmVdiOTSJ5et2HIeTM5f1m61x5ojLUi5HDfvr-jRrESQ5kbKuySGHVwR4QhwinpY1wQqBnwc80tx7cb_6SSqsTOoGln6T_l3k2Pb54ClVnGWiW_u1kmX78V2TZOsVmZmwtdZCMi-2zWIyAdIEXE-gncIehoAgEoq2VAhaCURbJWro_EwzzQwNmCTkDodLAx4npXRd_qSu0Ayp0txym9OFovBXBULRvk4DPiy3i_bPUmCDxzC46pTtFOe9p82uybTehZfULZtXXqRm85FL9n5zkrsTllPNAyEGhgb0RK9sE5nK1m_wNNysDyfLC4EFf1VXTrKm14XNVjc2vqLb7Mw\",\"e\":\"AQAB\",\"d\":\"ed7U_k3rJ4yTk70JtRSIfjKGiEb67BO1TabcymnljKO7RU8nage84zZYuSu_XpQsHk6P1f0Gzxkicghm_Er-FrfVn2pp70Xu52z3yRd6BJUgWLDFk97ngScIyw5OiULKU9SrZk2frDpftNCSUcIgb50F8m0QAnBa_CdPsQKbuuhLv8V8tBAV7F_lAwvSBgu56wRo3hPz5dWH8YeXM7XBfQ9viFMNEKd21sP_j5C7ueUnXT66nBxe3ZJEU3iuMYM6D6dB_KW2GfZC6WmTgvGhhxJD0h7aYmfjkD99MDleB7SkpbvoODOqiQ5Epb7Nyh6kv5u4KUv2CJYtATLZkUeMkQ\",\"p\":\"uBUjWPWtlGksmOqsqCNWksfqJvMcnP_8TDYN7e4-WnHL4N-9HjRuPDnp6kHvCIEi9SEfxm7gNxlRcWegvNQr3IZCz7TnCTexXc5NOklB9OavWFla6u-s3Thn6Tz45-EUjpJr0VJMxhO-KxGmuTwUXBBp4vN6K2qV6rQNFmgkWzk\",\"q\":\"tW_i7cCec56bHkhITL_79dXHz_PLC_f7xlynmlZJGU_d6mqOKmLBNBbTMLnYW8uAFiFzWxDeDHh1o5uF0mSQR-Z1Fg35OftnpbWpy0Cbc2la5WgXQjOwtG1eLYIY2BD3-wQ1VYDBCvowr4FDi-sngxwLqvwmrJ0xjhi99O-Gzcs\",\"dp\":\"q1d5jE85Hz_6M-eTh_lEluEf0NtPEc-vvhw-QO4V-cecNpbrCBdTWBmr4dE3NdpFeJc5ZVFEv-SACyei1MBEh0ItI_pFZi4BmMfy2ELh8ptaMMkTOESYyVy8U7veDq9RnBcr5i1Nqr0rsBkA77-9T6gzdvycBZdzLYAkAmwzEvk\",\"dq\":\"q29A2K08Crs-jmp2Bi8Q_8QzvIX6wSBbwZ4ir24AO-5_HNP56IrPS0yV2GCB0pqCOGb6_Hz_koDvhtuYoqdqvMVAtMoXR3YJBUaVXPt65p4RyNmFwIPe31zHs_BNUTsXVRMw4c16mci03-Af1sEm4HdLfxAp6sfM3xr5wcnhcek\",\"qi\":\"rHPgVTyHUHuYzcxfouyBfb1XAY8nshwn0ddo81o1BccD4Z7zo5It6SefDHjxCAbcmbiCcXBSooLcY-NF5FMv3fg19UE21VyLQltHcVjRRp2tRs4OHcM8yaXIU2x6N6Z6BP2tOksHb9MOBY1wAQzFOAKg_G4Sxev6-_6ud6RISuc\"}";
  26. private static final String publicKeyStr = "{\"kty\":\"RSA\",\"kid\":\"3e79646c4dbc408383a9eed09f2b85ae\",\"alg\":\"RS256\",\"n\":\"gndmVdiOTSJ5et2HIeTM5f1m61x5ojLUi5HDfvr-jRrESQ5kbKuySGHVwR4QhwinpY1wQqBnwc80tx7cb_6SSqsTOoGln6T_l3k2Pb54ClVnGWiW_u1kmX78V2TZOsVmZmwtdZCMi-2zWIyAdIEXE-gncIehoAgEoq2VAhaCURbJWro_EwzzQwNmCTkDodLAx4npXRd_qSu0Ayp0txym9OFovBXBULRvk4DPiy3i_bPUmCDxzC46pTtFOe9p82uybTehZfULZtXXqRm85FL9n5zkrsTllPNAyEGhgb0RK9sE5nK1m_wNNysDyfLC4EFf1VXTrKm14XNVjc2vqLb7Mw\",\"e\":\"AQAB\"}";
  27. /**
  28. * token过期时间(分钟)
  29. */
  30. public static final long expirationTime = 30 * 24 * 60;
  31. public static String createToken(String username, String password, Integer roleId) {
  32. try {
  33. /**
  34. * “iss” (issuer) 发行人
  35. *
  36. * “sub” (subject) 主题
  37. *
  38. * “aud” (audience) 接收方 用户
  39. *
  40. * “exp” (expiration time) 到期时间
  41. *
  42. * “nbf” (not before) 在此之前不可用
  43. *
  44. * “iat” (issued at) jwt的签发时间
  45. */
  46. //Payload
  47. JwtClaims claims = new JwtClaims();
  48. claims.setGeneratedJwtId();
  49. claims.setIssuedAtToNow();
  50. // 令牌将过期的时间 分钟
  51. claims.setExpirationTimeMinutesInTheFuture(expirationTime);
  52. claims.setNotBeforeMinutesInThePast(0);
  53. claims.setSubject("login");
  54. claims.setAudience(AUDIENCE);
  55. //添加自定义参数,必须是字符串类型
  56. claims.setClaim("username", username);
  57. claims.setClaim("password", password);
  58. claims.setClaim("roleId", roleId);
  59. //jws
  60. JsonWebSignature jws = new JsonWebSignature();
  61. //签名算法RS256
  62. jws.setAlgorithmHeaderValue(AlgorithmIdentifiers.RSA_USING_SHA256);
  63. jws.setKeyIdHeaderValue(keyId);
  64. jws.setPayload(claims.toJson());
  65. PrivateKey privateKey = new RsaJsonWebKey(JsonUtil.parseJson(privateKeyStr)).getPrivateKey();
  66. jws.setKey(privateKey);
  67. //get token
  68. String idToken = jws.getCompactSerialization();
  69. return idToken;
  70. } catch (JoseException e) {
  71. logger.error("[Token生成失败]: {}", e.getMessage());
  72. }
  73. return null;
  74. }
  75. public static String getHeader() {
  76. return HEADER;
  77. }
  78. public static JwtUser verifyToken(String token) {
  79. JwtUser jwtUser = new JwtUser();
  80. try {
  81. JwtConsumer consumer = new JwtConsumerBuilder()
  82. .setRequireExpirationTime()
  83. .setMaxFutureValidityInMinutes(5256000)
  84. .setAllowedClockSkewInSeconds(30)
  85. .setRequireSubject()
  86. //.setExpectedIssuer("")
  87. .setExpectedAudience(AUDIENCE)
  88. .setVerificationKey(new RsaJsonWebKey(JsonUtil.parseJson(publicKeyStr)).getPublicKey())
  89. .build();
  90. JwtClaims claims = consumer.processToClaims(token);
  91. NumericDate expirationTime = claims.getExpirationTime();
  92. // 判断是否即将过期, 默认剩余时间小于5分钟未即将过期
  93. // 剩余时间 (秒)
  94. long timeRemaining = LocalDateTime.now().toEpochSecond(ZoneOffset.ofHours(8)) - expirationTime.getValue();
  95. if (timeRemaining < 5 * 60) {
  96. jwtUser.setStatus(JwtUser.TokenStatus.EXPIRING_SOON);
  97. }else {
  98. jwtUser.setStatus(JwtUser.TokenStatus.NORMAL);
  99. }
  100. String username = (String) claims.getClaimValue("username");
  101. String password = (String) claims.getClaimValue("password");
  102. Long roleId = (Long) claims.getClaimValue("roleId");
  103. jwtUser.setUserName(username);
  104. jwtUser.setPassword(password);
  105. jwtUser.setRoleId(roleId.intValue());
  106. return jwtUser;
  107. } catch (InvalidJwtException e) {
  108. if (e.hasErrorCode(ErrorCodes.EXPIRED)) {
  109. jwtUser.setStatus(JwtUser.TokenStatus.EXPIRED);
  110. }else {
  111. jwtUser.setStatus(JwtUser.TokenStatus.EXCEPTION);
  112. }
  113. return jwtUser;
  114. }catch (Exception e) {
  115. logger.error("[Token解析失败]: {}", e.getMessage());
  116. jwtUser.setStatus(JwtUser.TokenStatus.EXPIRED);
  117. return jwtUser;
  118. }
  119. }
  120. }