MaxKeyMgtConfig.java 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186
  1. /*
  2. * Copyright [2020] [MaxKey of copyright http://www.maxkey.top]
  3. *
  4. * Licensed under the Apache License, Version 2.0 (the "License");
  5. * you may not use this file except in compliance with the License.
  6. * You may obtain a copy of the License at
  7. *
  8. * http://www.apache.org/licenses/LICENSE-2.0
  9. *
  10. * Unless required by applicable law or agreed to in writing, software
  11. * distributed under the License is distributed on an "AS IS" BASIS,
  12. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13. * See the License for the specific language governing permissions and
  14. * limitations under the License.
  15. */
  16. package org.maxkey;
  17. import javax.sql.DataSource;
  18. import org.maxkey.authz.oauth2.provider.client.JdbcClientDetailsService;
  19. import org.maxkey.authz.oauth2.provider.token.DefaultTokenServices;
  20. import org.maxkey.authz.oauth2.provider.token.TokenStore;
  21. import org.maxkey.authz.oauth2.provider.token.store.InMemoryTokenStore;
  22. import org.maxkey.authz.oauth2.provider.token.store.JdbcTokenStore;
  23. import org.maxkey.authz.oauth2.provider.token.store.RedisTokenStore;
  24. import org.maxkey.constants.ConstantsProperties;
  25. import org.maxkey.jobs.DynamicGroupsJob;
  26. import org.maxkey.password.onetimepwd.AbstractOtpAuthn;
  27. import org.maxkey.password.onetimepwd.impl.TimeBasedOtpAuthn;
  28. import org.maxkey.persistence.db.LoginHistoryService;
  29. import org.maxkey.persistence.db.LoginService;
  30. import org.maxkey.persistence.db.PasswordPolicyValidator;
  31. import org.maxkey.persistence.redis.RedisConnectionFactory;
  32. import org.maxkey.persistence.service.GroupsService;
  33. import org.opensaml.xml.ConfigurationException;
  34. import org.quartz.CronScheduleBuilder;
  35. import org.quartz.CronTrigger;
  36. import org.quartz.JobBuilder;
  37. import org.quartz.JobDataMap;
  38. import org.quartz.JobDetail;
  39. import org.quartz.Scheduler;
  40. import org.quartz.SchedulerException;
  41. import org.quartz.TriggerBuilder;
  42. import org.maxkey.authn.realm.jdbc.JdbcAuthenticationRealm;
  43. import org.maxkey.authn.support.rememberme.AbstractRemeberMeService;
  44. import org.slf4j.Logger;
  45. import org.slf4j.LoggerFactory;
  46. import org.springframework.beans.factory.InitializingBean;
  47. import org.springframework.beans.factory.annotation.Value;
  48. import org.springframework.context.annotation.Bean;
  49. import org.springframework.context.annotation.Configuration;
  50. import org.springframework.context.annotation.PropertySource;
  51. import org.springframework.jdbc.core.JdbcTemplate;
  52. import org.springframework.scheduling.quartz.SchedulerFactoryBean;
  53. import org.springframework.security.crypto.password.PasswordEncoder;
  54. @Configuration
  55. @PropertySource(ConstantsProperties.applicationPropertySource)
  56. public class MaxKeyMgtConfig implements InitializingBean {
  57. private static final Logger _logger = LoggerFactory.getLogger(MaxKeyMgtConfig.class);
  58. @Bean(name = "oauth20JdbcClientDetailsService")
  59. public JdbcClientDetailsService JdbcClientDetailsService(
  60. DataSource dataSource,PasswordEncoder passwordReciprocal) {
  61. JdbcClientDetailsService clientDetailsService = new JdbcClientDetailsService(dataSource);
  62. clientDetailsService.setPasswordEncoder(passwordReciprocal);
  63. _logger.debug("JdbcClientDetailsService inited.");
  64. return clientDetailsService;
  65. }
  66. /**
  67. * TokenStore.
  68. * @param persistence int
  69. * @return oauth20TokenStore
  70. */
  71. @Bean(name = "oauth20TokenStore")
  72. public TokenStore oauth20TokenStore(
  73. @Value("${config.server.persistence}") int persistence,
  74. JdbcTemplate jdbcTemplate,
  75. RedisConnectionFactory jedisConnectionFactory) {
  76. TokenStore tokenStore = null;
  77. if (persistence == 0) {
  78. tokenStore = new InMemoryTokenStore();
  79. _logger.debug("InMemoryTokenStore");
  80. } else if (persistence == 1) {
  81. tokenStore = new JdbcTokenStore(jdbcTemplate);
  82. _logger.debug("JdbcTokenStore");
  83. } else if (persistence == 2) {
  84. tokenStore = new RedisTokenStore(jedisConnectionFactory);
  85. _logger.debug("RedisTokenStore");
  86. }
  87. return tokenStore;
  88. }
  89. /**
  90. * clientDetailsUserDetailsService.
  91. * @return oauth20TokenServices
  92. */
  93. @Bean(name = "oauth20TokenServices")
  94. public DefaultTokenServices DefaultTokenServices(
  95. JdbcClientDetailsService oauth20JdbcClientDetailsService,
  96. TokenStore oauth20TokenStore) {
  97. DefaultTokenServices tokenServices = new DefaultTokenServices();
  98. tokenServices.setClientDetailsService(oauth20JdbcClientDetailsService);
  99. tokenServices.setTokenStore(oauth20TokenStore);
  100. tokenServices.setSupportRefreshToken(true);
  101. return tokenServices;
  102. }
  103. //浠ヤ笅鍐呭鍙互娉ㄩ噴鎺夊悗鍐峹ml涓厤缃�,xml寮曞叆鍦∕axKeyMgtApplication涓�
  104. @Bean(name = "authenticationRealm")
  105. public JdbcAuthenticationRealm authenticationRealm(
  106. PasswordEncoder passwordEncoder,
  107. PasswordPolicyValidator passwordPolicyValidator,
  108. LoginService loginService,
  109. LoginHistoryService loginHistoryService,
  110. AbstractRemeberMeService remeberMeService,
  111. JdbcTemplate jdbcTemplate) {
  112. JdbcAuthenticationRealm authenticationRealm = new JdbcAuthenticationRealm(
  113. passwordEncoder,
  114. passwordPolicyValidator,
  115. loginService,
  116. loginHistoryService,
  117. remeberMeService,
  118. jdbcTemplate);
  119. _logger.debug("JdbcAuthenticationRealm inited.");
  120. return authenticationRealm;
  121. }
  122. @Bean(name = "timeBasedOtpAuthn")
  123. public AbstractOtpAuthn timeBasedOtpAuthn() {
  124. AbstractOtpAuthn tfaOtpAuthn = new TimeBasedOtpAuthn();
  125. _logger.debug("TimeBasedOtpAuthn inited.");
  126. return tfaOtpAuthn;
  127. }
  128. /**
  129. * schedulerJobsInit.
  130. * @return schedulerJobsInit
  131. * @throws ConfigurationException
  132. * @throws SchedulerException
  133. */
  134. @Bean(name = "schedulerJobs")
  135. public Scheduler schedulerJobs(
  136. SchedulerFactoryBean schedulerFactoryBean,
  137. GroupsService groupsService,
  138. @Value("${config.job.cron.dynamicgroups}") String cronScheduleDynamicGroups
  139. ) throws SchedulerException {
  140. Scheduler scheduler = schedulerFactoryBean.getScheduler();
  141. dynamicGroupsJob(scheduler,cronScheduleDynamicGroups,groupsService);
  142. return scheduler;
  143. }
  144. private void dynamicGroupsJob(Scheduler scheduler ,
  145. String cronSchedule,
  146. GroupsService groupsService) throws SchedulerException {
  147. JobDetail jobDetail =
  148. JobBuilder.newJob(DynamicGroupsJob.class)
  149. .withIdentity("DynamicGroupsJob", "DynamicGroups")
  150. .build();
  151. JobDataMap jobDataMap = new JobDataMap();
  152. jobDataMap.put("groupsService", groupsService);
  153. CronScheduleBuilder scheduleBuilder = CronScheduleBuilder.cronSchedule(cronSchedule);
  154. CronTrigger cronTrigger =
  155. TriggerBuilder.newTrigger()
  156. .withIdentity("triggerDynamicGroups", "DynamicGroups")
  157. .usingJobData(jobDataMap)
  158. .withSchedule(scheduleBuilder)
  159. .build();
  160. scheduler.scheduleJob(jobDetail,cronTrigger);
  161. }
  162. @Override
  163. public void afterPropertiesSet() throws Exception {
  164. }
  165. }