package com.oying.modules.security.security;
|
|
import com.fasterxml.jackson.databind.ObjectMapper;
|
import lombok.extern.slf4j.Slf4j;
|
import com.oying.exception.handler.ApiError;
|
import org.springframework.http.HttpStatus;
|
import org.springframework.security.core.AuthenticationException;
|
import org.springframework.security.web.AuthenticationEntryPoint;
|
import org.springframework.stereotype.Component;
|
import javax.servlet.http.HttpServletRequest;
|
import javax.servlet.http.HttpServletResponse;
|
import java.io.IOException;
|
|
/**
|
* @author Z
|
*/
|
@Slf4j
|
@Component
|
public class JwtAuthenticationEntryPoint implements AuthenticationEntryPoint {
|
|
@Override
|
public void commence(HttpServletRequest request, HttpServletResponse response, AuthenticationException authException) throws IOException {
|
// 当用户尝试访问安全的REST资源而不提供任何凭据时,将调用此方法发送401 响应
|
int code = HttpStatus.UNAUTHORIZED.value();
|
response.setStatus(code);
|
response.setContentType("application/json;charset=UTF-8");
|
ObjectMapper objectMapper = new ObjectMapper();
|
String jsonResponse = objectMapper.writeValueAsString(ApiError.error(HttpStatus.UNAUTHORIZED.value(), "登录状态已过期,请重新登录"));
|
response.getWriter().write(jsonResponse);
|
}
|
}
|