shiro introduction and use

Keywords: Programming Shiro Spring Session Ehcache

1, shiro internal structure

1. Components contained in shiro

shiro mainly includes Authenticator, authorizer, session manager, encryption, remember me and cache manager

2. Introduction to components of shiro

Subject: the subject, which can be understood as the user interacting with the application, contains all the information of the user, such as user information, user role, user authority, whether to log in, etc;
Security Manager: Security Manager shiro manages all modules of shiro through security manager.
Authenticator: authenticator, which is responsible for authenticating whether the user is a legal user. The specific authentication process of authenticator is to process whether the user is a legal user through realm;
Authorizer: authorizer, which is responsible for authorizing users. The specific authorization of authorizer is to obtain the permissions of users through realm;
Realm: you can have one or more realms, or you can customize the realm. In the shiro framework, the realm is very important to handle the user's authentication information and authorization information;
Session manager: responsible for session management;
SessionDAO: curd operation on session;
CacheManager: can cache user permission information to provide performance;
Cryptography: cryptographic module, which encrypts and saltes the password;

shiro manages the authenticator, authorizer, session manager, cache, sessionDao, realm through the securityManager authentication manager. The application side (app) interacts with the securityManager authentication manager through the subject. The authentication manager is responsible for proxy to the authenticator or authorizer. The authenticator authorizer finally obtains the user's authentication information or authorization information through the realm

2, pom files on which shiro depends


3, Using shiro as ini file

1. User authentication Demo

The content of shiro1.ini file is as follows

#Users impersonate real users
# Format user name = password
    public void testAuthenticate(){
        //1. Load ini file create IniSecurityManagerFactory from ini file
        IniSecurityManagerFactory managerFactory = new IniSecurityManagerFactory("classpath:shiro1.ini");
        //2. Get security manager
        SecurityManager instance = managerFactory.getInstance();
        //3. Bind the current SecurityManager to the current environment
        //4. Get subject subject object
        Subject subject = SecurityUtils.getSubject();
        //5. Set user name and password
        UsernamePasswordToken token = new UsernamePasswordToken("xiaoming","123");
        //6. Log in
        //7. Check whether the user logs in successfully true success false failure

2. User authorization Demo

The content of shiro2.ini file is as follows

#Users impersonate real users
# Format user name = password. For example, if the password of xiaoming is 123 and the role of admin corresponds to the role of user:save,user:delete,user:update,user:find
#roles simulation role information
#Format role name = the corresponding permissions of the role, such as admin role with user:save,user:delete,user:update,user:find permission manager role with user:find permission
    public void testAuthrizer(){
        //1. Load ini file create IniSecurityManagerFactory from ini file
        IniSecurityManagerFactory managerFactory = new IniSecurityManagerFactory("classpath:shiro2.ini");
        //2. Get security manager
        SecurityManager instance = managerFactory.getInstance();
        //3. Bind the current SecurityManager to the current environment
        //4. Get subject subject object
        Subject subject = SecurityUtils.getSubject();
        //5. Set user name and password
        UsernamePasswordToken token = new UsernamePasswordToken("xiaohong","123456");
        //6. Log in
        //7. View roles and permissions owned by users

3. Custom realm Demo

The content of shiro3.ini file is as follows

#Declare custom realm name = custom realm class fully qualified name
#Register realm to Security Manager

Custom realm

public class CustomerRealm extends AuthorizingRealm {
    //Customize the name of the realm because there may be more than one realm in the shiro framework. According to the name of the realm, decide which realm to use for processing
    public void setName(String name) {
    //Authorization when the subject calls to get the user role, the method doGetAuthorizationInfo will be called
    protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principalCollection) {
        System.out.println("Authorization start");
        //User information can be obtained from principalCollection
        String primaryPrincipal = (String) principalCollection.getPrimaryPrincipal();
        SimpleAuthorizationInfo info = new SimpleAuthorizationInfo();
        return info;
    //Authentication the method doGetAuthenticationInfo is called when the subject calls the user to log in
    protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken authenticationToken) throws AuthenticationException {
        System.out.println("Start of certification");
        //When the user logs in, subject.login(token); the token type passed in is UsernamePasswordToken
        //So you can force the authenticationToken to UsernamePasswordToken
        UsernamePasswordToken token = (UsernamePasswordToken) authenticationToken;
        String username = token.getUsername();
        String pwd = new String (token.getPassword());
        //The user name and password found from the database are xiaoming 123
        if ("xiaoming".equals(username) && "123".equals(pwd)) {
            //Authentication is achieved by storing the user information in the AuthenticationInfo object
            //The three parameters of SimpleAuthenticationInfo are as follows
            //1. Object principal user information can be any type of object
            //2. Object credentials password
            //3. String realmName the name of the current realm
            AuthenticationInfo authenticationInfo = new SimpleAuthenticationInfo(username,pwd,getName());
            return authenticationInfo;
        //Exception thrown if authentication fails
        throw new RuntimeException("Login failed");
    public void testCustomerRealm(){
        //1. Load ini file create IniSecurityManagerFactory from ini file
        IniSecurityManagerFactory managerFactory = new IniSecurityManagerFactory("classpath:shiro3.ini");
        //2. Get security manager
        SecurityManager instance = managerFactory.getInstance();
        //3. Bind the current SecurityManager to the current environment
        //4. Get subject subject object
        Subject subject = SecurityUtils.getSubject();
        //5. Set user name and password
        UsernamePasswordToken token = new UsernamePasswordToken("xiaoming","123");
        //6. When logging in the subject, the doGetAuthenticationInfo method in the realm will be called
        //7. View the roles and permissions owned by the user. When the subject obtains the roles or permissions, it will call the doGetAuthorizationInfo method in the realm

4. Use cache to save user role information and permission information Demo

Use ehcache as cache

shiro-ehcache.xml configuration information

<ehcache xmlns:xsi=""
    public void testCacheManager(){
        //1. Load ini file create IniSecurityManagerFactory from ini file
        IniSecurityManagerFactory managerFactory = new IniSecurityManagerFactory("classpath:shiro3.ini");
        //2. Get security manager if CacheManager is enabled, cachesecuritymanager object is required
        CachingSecurityManager instance = (CachingSecurityManager) managerFactory.getInstance();
        //3. Create cache management objects (ehcache is used for cache, so EhCacheManager is used) other cache objects can be used
        EhCacheManager ehCacheManager = new EhCacheManager();
        //4. Read ehcache configuration file
        //5. Set the EhCacheManager object to the cacheingsecuritymanager Security Manager
        //6. Bind the current SecurityManager to the current environment
        //7. Get subject subject object
        Subject subject = SecurityUtils.getSubject();
        //8. Set user name and password
        UsernamePasswordToken token = new UsernamePasswordToken("xiaoming","123");
        //9. Log in
        //10. When viewing the roles and permissions owned by users, the first time they get permission information, they will call the doGetAuthorizationInfo method in the realm, and the second time they directly get from the cache, they will not walk away from the realm

5. Clear cached user information

    public void testCacheManager(){
        //1. Load ini file create IniSecurityManagerFactory from ini file
        IniSecurityManagerFactory managerFactory = new IniSecurityManagerFactory("classpath:shiro3.ini");
        //2. Get security manager if CacheManager is enabled, cachesecuritymanager object is required
        CachingSecurityManager instance = (CachingSecurityManager) managerFactory.getInstance();
        //3. Create cache management objects (ehcache is used for cache, so EhCacheManager is used) other cache objects can be used
        EhCacheManager ehCacheManager = new EhCacheManager();
        //4. Read ehcache configuration file
        //5. Set the EhCacheManager object to the cacheingsecuritymanager Security Manager
        //6. Bind the current SecurityManager to the current environment
        //7. Get subject subject object
        Subject subject = SecurityUtils.getSubject();
        //8. Set user name and password
        UsernamePasswordToken token = new UsernamePasswordToken("xiaoming","123");
        //9. Log in
        //10. When viewing the roles and permissions owned by users, the first time they get permission information, they will call the doGetAuthorizationInfo method in the realm, and the second time they directly get from the cache, they will not walk away from the realm
        //Get ehcache user cache information
        Cache<Object, Object> cache = ehCacheManager.getCache("CustomerRealm.authorizationCache");
        //Clear the corresponding cache information of xiaoming user
        cache.remove(new SimplePrincipalCollection("xiaoming", "CustomerRealm"));
        //Get user role and permission information from the realm after clearing the cache

3, Integrating shiro with springboot

<?xml version="1.0" encoding="UTF-8"?>
<project xmlns=""

        <!--shiro core-->
        <!-- ehcache -->
        <!--spring and shiro integration -->
        <!--shiro And redis integration-->
        <!--thymeleaf -->


2. Custom realm

public class CustomerRealm extends AuthorizingRealm {
    private UserInfoService userInfoService;
    //Customize the name of the realm because there may be more than one realm in the shiro framework. According to the name of the realm, decide which realm to use for processing
    public void setName(String name) {
    //Authorization when the subject calls to get the user role, the method doGetAuthorizationInfo will be called
    protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principalCollection) {
        System.out.println("Authorization start");
        //User information can be obtained from principalCollection
        UserInfo userInfo = (UserInfo) principalCollection.getPrimaryPrincipal();
        SimpleAuthorizationInfo info = new SimpleAuthorizationInfo();
        UserDto userExtInfo = userInfoService.findUserExtInfo(userInfo.getId());
        return info;
    //Authentication the method doGetAuthenticationInfo is called when the subject calls the user to log in
    protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken authenticationToken) throws AuthenticationException {
        System.out.println("Start of certification");
        //When the user logs in, subject.login(token); the token type passed in is UsernamePasswordToken
        //So you can force the authenticationToken to UsernamePasswordToken
        UsernamePasswordToken token = (UsernamePasswordToken) authenticationToken;
        String username = token.getUsername();
        String pwd = new String (token.getPassword());
        UserInfo user = userInfoService.findUserByUserNameAndPwd(username, pwd);
        //The user name and password found from the database are xiaoming 123
        if (user != null) {
            //Authentication is achieved by storing the user information in the AuthenticationInfo object
            //The three parameters of SimpleAuthenticationInfo are as follows
            //1. Object principal user information can be any type of object
            //2. Object credentials password
            //3. String realmName the name of the current realm
            AuthenticationInfo authenticationInfo = new SimpleAuthenticationInfo(user, pwd, getName());
            return authenticationInfo;
        //Exception thrown if authentication fails
        throw new RuntimeException("Login failed");

3. shiro configuration class

public class ShiroConfig {
    //Give the custom realm to the spring container for management
    public CustomerRealm getCustomerRealm(){
        return new CustomerRealm();

    public SecurityManager getSecurityManager(CustomerRealm realm){
        //Create a security manager and give the realm to the manager for management
        DefaultWebSecurityManager securityManager = new DefaultWebSecurityManager(realm);
        return securityManager;

    //Configure shiro filter conditions and jump page
    public ShiroFilterFactoryBean shiroFilterFactoryBean(SecurityManager securityManager){
        ShiroFilterFactoryBean bean = new ShiroFilterFactoryBean();
        //Set up security manager
        //Login page
        //Authorization failure jump page
        //LinkedHashMap must be used to ensure the order of filtering
        Map<String, String> map = new LinkedHashMap<>();
        //anon anonymous access means access without login and authorization
        //authc requires authentication login to access
        //Logout logout logout logout to jump to the page set by bean.setLoginUrl() method
        //perms[xx] has xx permission to access
        //roles[xx] can only be accessed by roles of xx
        map.put("/user/index", "anon");
        //Indicates that you have select user permission to access
        map.put("/user/select", "perms[select-user]");
        //Represents the role of system administrator to access
        map.put("/user/delete", "roles[system administrator]");
        //Only authentication login can access
        map.put("/user/**", "authc");
        //Set the filter chain of the request. The filter chain needs to be authenticated in order. It is usually placed after anonymous access
        return bean;

4. Test controller

public class TestController {
    public String login(UserInfo userInfo) {
        try {
            UsernamePasswordToken upt = new UsernamePasswordToken(userInfo.getUsername(), userInfo.getPassword());
            return "Login successful";
        } catch (Exception e) {
            return "Login failed";

    public String index(){
        return "visit index success";

    public String select(){
        return "visit select success";

    public String delete(){
        return "visit delete success";

    public String login(){
        return "visit login success";
    //Skip landing page
    public String tologin(){
        return "login";
    //Skip unauthorized page
    public String toUnauthorized(){
        return "unauthorized";

5. Permission control by shiro annotation

(1) . add a dependency to the pom file by referring to the above dependency

(2) The shiro configuration class adds the configuration of the two objects DefaultAdvisorAutoProxyCreator and AuthorizationAttributeSourceAdvisor

public class ShiroConfig {
    //To enable shiro annotation, you need to configure two objects: DefaultAdvisorAutoProxyCreator and AuthorizationAttributeSourceAdvisor
    public DefaultAdvisorAutoProxyCreator getDefaultAdvisorAutoProxyCreator() {
        DefaultAdvisorAutoProxyCreator autoProxyCreator = new DefaultAdvisorAutoProxyCreator();
        //Turn on proxy for spring AOP
        return autoProxyCreator;

    public CustomerRealm getCustomerRealm(){
        return new CustomerRealm();

    public SecurityManager getSecurityManager(CustomerRealm realm){
        //Create a security manager and give the realm to the manager for management
        DefaultWebSecurityManager securityManager = new DefaultWebSecurityManager(realm);
        return securityManager;

    //Configure launch shiro annotation
    public AuthorizationAttributeSourceAdvisor  getAuthorizationAttributeSourceAdvisor(SecurityManager securityManager) {
        AuthorizationAttributeSourceAdvisor advisor = new AuthorizationAttributeSourceAdvisor();
        return advisor;
    //Configure shiro filter conditions and jump page
    public ShiroFilterFactoryBean shiroFilterFactoryBean(SecurityManager securityManager){
        ShiroFilterFactoryBean bean = new ShiroFilterFactoryBean();
        //Set up security manager
        //Login page
        //Authorization failure jump page
        //LinkedHashMap must be used to ensure the order of filtering
        Map<String, String> map = new LinkedHashMap<>();
        //anon anonymous access means access without login and authorization
        //authc requires authentication login to access
        //Logout logout logout logout to jump to the page set by bean.setLoginUrl() method
        //perms[xx] has xx permission to access
        //roles[xx] can only be accessed by roles of xx
        map.put("/user/index", "anon");
        map.put("/login", "anon");
        //Indicates that you have select user permission to access
        map.put("/user/select", "perms[select-user]");
        //Represents the role of system administrator to access
        map.put("/user/delete", "roles[system administrator]");
        //Only authentication login can access
        map.put("/**", "authc");
        //Set the filter chain of the request. The filter chain needs to be authenticated in order. It is usually placed after anonymous access
        return bean;

(3) , test controller

public class TestController {
    //Skip landing page
    public String tologin(){
        return "login";
    //Skip unauthorized page
    public String toUnauthorized(){
        return "unauthorized";

    //User add and user delete permission are available to access
    @RequiresPermissions(value = {"user-add","user-delete"})
    public String testPermission(){
        return "test  Permission success";

    //Only administrator role can access
    @RequiresRoles(value = "administrators")
    public String tesRoles(){
        return "test  role success";

shiro's method based on filter chain (such as map.put("/**", "authc")) is different from that based on annotation (such as @ RequiresRoles) when they no longer have access

If you do not have permission, you will jump to the address set by setunauthorized URL ("/ tounauthorized")

If you do not have permission to annotate, you will throw an AuthorizationException exception. You can customize a global exception to handle annotation. The code is as follows

public class CustomerExceptionHandler {
    //Catch an exception of type AuthorizationException
    @ExceptionHandler(value = AuthorizationException.class)
    public String error(HttpServletRequest request, HttpServletResponse response,AuthorizationException e) {
		return "Unauthorized";

4, shiro password encryption

 public static void main(String[] args) {
        //The three parameters are as follows
        //1. Object source original password
        //2. Object salt value
        //3. int hashIterations salt several times
        Md5Hash pwd = new Md5Hash("12345", "salt", 2);

5, Spring boot integrates session management of shiro to store sessions in redis

shiro provides three default implementations of session manager by default

(1) . DefaultSessionManager: for Java se environment
(2) . ServletContainerSessionManager: used in the web environment. By default, the web environment uses this implementation class session information in the httpSession
(3) . DefaultWebSessionManager: used in the web environment. The session information can be stored in the specified place, such as mysql and redis

1. Introducing Shiro redis dependency


2. Introduce redis configuration into application.yml

		port: 6379

3. Customize shiro session manager

public class CustomerSessionManager extends DefaultWebSessionManager {
     * sessionid in header information
     *      Request header: Authorization: sessionid
     * Specify how to get sessionId
    protected Serializable getSessionId(ServletRequest request, ServletResponse response) {
        //Get data in request header Authorization
        String id = WebUtils.toHttp(request).getHeader("Authorization");
        if(StringUtils.isEmpty(id)) {
            //If it is not carried, a new sessionId will be generated
            return super.getSessionId(request,response);
            //Specify the source of sessionId specify to get sessionId from the request header do not specify to get sessionId from the cookie by default
            request.setAttribute(ShiroHttpServletRequest.REFERENCED_SESSION_ID_SOURCE, "header");
            request.setAttribute(ShiroHttpServletRequest.REFERENCED_SESSION_ID, id);
            request.setAttribute(ShiroHttpServletRequest.REFERENCED_SESSION_ID_IS_VALID, Boolean.TRUE);
            return id;

4. Configure shiro session management to store in redis

package com.xiao.shiro.config;

import com.xiao.shiro.realm.CustomerRealm;
import com.xiao.shiro.session.CustomerSessionManager;
import org.apache.shiro.mgt.SecurityManager;
import org.apache.shiro.spring.LifecycleBeanPostProcessor;
import org.apache.shiro.spring.web.ShiroFilterFactoryBean;
import org.apache.shiro.web.mgt.DefaultWebSecurityManager;
import org.apache.shiro.web.session.mgt.DefaultWebSessionManager;
import org.crazycake.shiro.RedisCacheManager;
import org.crazycake.shiro.RedisManager;
import org.crazycake.shiro.RedisSessionDAO;
import org.springframework.aop.framework.autoproxy.DefaultAdvisorAutoProxyCreator;
import org.springframework.beans.factory.annotation.Value;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;

import java.util.HashMap;
import java.util.LinkedHashMap;
import java.util.Map;

public class ShiroConfig {

    public CustomerRealm getCustomerRealm(){
        return new CustomerRealm();

    public SecurityManager getSecurityManager(CustomerRealm realm){
         //Create a security manager and give the realm to the manager for management
         DefaultWebSecurityManager securityManager = new DefaultWebSecurityManager(realm);
        //Register a custom session manager with the Security Manager
        //Register the customized redis cache manager to the Security Manager
        return securityManager;

    //Configure launch shiro annotation
    public AuthorizationAttributeSourceAdvisor  getAuthorizationAttributeSourceAdvisor(SecurityManager securityManager) {
        AuthorizationAttributeSourceAdvisor advisor = new AuthorizationAttributeSourceAdvisor();
        return advisor;
    //Configure shiro filter conditions and jump page
    public ShiroFilterFactoryBean shiroFilterFactoryBean(SecurityManager securityManager){
        ShiroFilterFactoryBean bean = new ShiroFilterFactoryBean();
        //Set up security manager
        //Login page
        //Authorization failure jump page
        //LinkedHashMap must be used to ensure the order of filtering
        Map<String, String> map = new LinkedHashMap<>();
        //anon anonymous access means access without login and authorization
        //authc requires authentication login to access
        //Logout logout logout logout to jump to the page set by bean.setLoginUrl() method
        //perms[xx] has xx permission to access
        //roles[xx] can only be accessed by roles of xx
        map.put("/user/index", "anon");
        map.put("/login", "anon");
        //Indicates that you have select user permission to access
        map.put("/user/select", "perms[select-user]");
        //Represents the role of system administrator to access
        map.put("/user/delete", "roles[system administrator]");
        //Only authentication login can access
        map.put("/**", "authc");
        //Set the filter chain of the request. The filter chain needs to be authenticated in order. It is usually placed after anonymous access
        return bean;

    //To enable shiro annotation, you need to configure two objects: DefaultAdvisorAutoProxyCreator and AuthorizationAttributeSourceAdvisor
    public DefaultAdvisorAutoProxyCreator getDefaultAdvisorAutoProxyCreator() {
        DefaultAdvisorAutoProxyCreator autoProxyCreator = new DefaultAdvisorAutoProxyCreator();
        //Turn on proxy for spring AOP
        return autoProxyCreator;

    private String host;
    private int port;

     * 1.redis Operating redis
    public RedisManager redisManager() {
        RedisManager redisManager = new RedisManager();
        return redisManager;

     * 2.sessionDao
    public RedisSessionDAO redisSessionDAO() {
        RedisSessionDAO sessionDAO = new RedisSessionDAO();
        return sessionDAO;

     * 3.Session manager
    public DefaultWebSessionManager sessionManager() {
        CustomerSessionManager sessionManager = new CustomerSessionManager();
        return sessionManager;

     * 4.Cache manager
    public RedisCacheManager cacheManager() {
        RedisCacheManager redisCacheManager = new RedisCacheManager();
        return redisCacheManager;

5,AuthenticationInfo authenticationInfo = new SimpleAuthenticationInfo(user, pwd, getName());

The user object here implements two interfaces: serializable and authcacheprincipal

public class UserInfo implements Serializable,AuthCachePrincipal {
    private Long id;
    private String username;
    private String password;

    public Long getId() {
        return id;

    public void setId(Long id) { = id;

    public String getUsername() {
        return username;

    public void setUsername(String username) {
        this.username = username;

    public String getPassword() {
        return password;

    public void setPassword(String password) {
        this.password = password;
    //Just write getAuthCacheKey method
    public String getAuthCacheKey() {
        return null;

Posted by MrSheen on Fri, 15 May 2020 01:50:42 -0700