【底座】优化Oauth和Oidc认证源的获取accessToken和获取用户信息及三方登录回调接口的state校验

This commit is contained in:
xuyuxiang
2026-06-24 22:43:12 +08:00
parent 2800d056d5
commit 7937b43653
3 changed files with 69 additions and 38 deletions
@@ -17,6 +17,7 @@ import cn.dev33.satoken.oauth2.consts.SaOAuth2Consts;
import cn.hutool.core.util.ObjectUtil;
import cn.hutool.core.util.StrUtil;
import cn.hutool.http.HttpUtil;
import cn.hutool.json.JSONObject;
import cn.hutool.json.JSONUtil;
import com.xkcoding.http.config.HttpConfig;
import com.xkcoding.http.support.HttpHeader;
@@ -54,29 +55,33 @@ public class AuthOauthCommonRequest extends AuthDefaultRequest {
@Override
public AuthToken getAccessToken(AuthCallback authCallback) {
cn.hutool.json.JSONObject jsonObject = JSONUtil.createObj();
JSONObject jsonObject = JSONUtil.createObj();
jsonObject.set( SaOAuth2Consts.Param.client_id, this.config.getClientId());
jsonObject.set( SaOAuth2Consts.Param.client_secret, this.config.getClientSecret());
jsonObject.set( SaOAuth2Consts.Param.grant_type, GrantType.authorization_code);
jsonObject.set( SaOAuth2Consts.Param.redirect_uri, this.config.getRedirectUri());
jsonObject.set( SaOAuth2Consts.Param.code, authCallback.getCode());
String body = HttpUtil.post(this.source.accessToken(), jsonObject, 5000);
cn.hutool.json.JSONObject bodyJsonObject = JSONUtil.parseObj(body);
if(!bodyJsonObject.containsKey(SaOAuth2Consts.Param.access_token) &&
!bodyJsonObject.containsKey(StrUtil.toCamelCase(SaOAuth2Consts.Param.access_token))) {
JSONObject bodyJsonObject = JSONUtil.parseObj(body);
String accessTokenKey = SaOAuth2Consts.Param.access_token;
String accessTokenCamelKey = StrUtil.toCamelCase(accessTokenKey);
if(!bodyJsonObject.containsKey(accessTokenKey) &&
!bodyJsonObject.containsKey(accessTokenCamelKey) && bodyJsonObject.containsKey("data")) {
Object data = bodyJsonObject.get("data");
if(ObjectUtil.isEmpty(data)) {
throw new AuthException(AuthResponseStatus.FAILURE);
}
bodyJsonObject = JSONUtil.parseObj(data);
}
if(ObjectUtil.isAllEmpty(bodyJsonObject.getStr(SaOAuth2Consts.Param.access_token),
bodyJsonObject.getStr(StrUtil.toCamelCase(SaOAuth2Consts.Param.access_token)))) {
throw new AuthException(AuthResponseStatus.FAILURE);
}
String accessToken = bodyJsonObject.getStr(SaOAuth2Consts.Param.access_token);
String accessToken = bodyJsonObject.getStr(accessTokenKey);
if(ObjectUtil.isEmpty(accessToken)) {
accessToken = bodyJsonObject.getStr(StrUtil.toCamelCase(SaOAuth2Consts.Param.access_token));
accessToken = bodyJsonObject.getStr(accessTokenCamelKey);
}
if(ObjectUtil.isEmpty(accessToken)) {
throw new AuthException(AuthResponseStatus.FAILURE);
}
return AuthToken.builder()
.accessToken(accessToken)
@@ -96,13 +101,16 @@ public class AuthOauthCommonRequest extends AuthDefaultRequest {
HttpHeader header = (new HttpHeader()).add(SaOAuth2Consts.Param.Authorization,
SaOAuth2Consts.TokenType.Bearer + " " + authToken.getAccessToken());
userInfo = (new HttpUtils(httpConfig))
.post(this.source.userInfo(), null, header, false).getBody();
.get(this.source.userInfo(), null, header, false).getBody();
} else {
userInfo = (new HttpUtils(httpConfig)).get(this.userInfoUrl(authToken)).getBody();
}
cn.hutool.json.JSONObject bodyJsonObject = JSONUtil.parseObj(userInfo);
Object data = bodyJsonObject.get("data");
if(ObjectUtil.isNotEmpty(data)) {
JSONObject bodyJsonObject = JSONUtil.parseObj(userInfo);
if(!bodyJsonObject.containsKey(authOauthBaseJson.getSourceProperty()) && bodyJsonObject.containsKey("data")) {
Object data = bodyJsonObject.get("data");
if(ObjectUtil.isEmpty(data)) {
throw new AuthException(AuthResponseStatus.FAILURE);
}
bodyJsonObject = JSONUtil.parseObj(data);
}
return AuthUser.builder()
@@ -70,15 +70,28 @@ public class AuthOidcCommonRequest extends AuthDefaultRequest {
jsonObject.set( SaOAuth2Consts.Param.code, authCallback.getCode());
String body = HttpUtil.post(this.source.accessToken(), jsonObject, 5000);
JSONObject bodyJsonObject = JSONUtil.parseObj(body);
if(ObjectUtil.isAllEmpty(bodyJsonObject.getStr(SaOAuth2Consts.Param.access_token),
bodyJsonObject.getStr(StrUtil.toCamelCase(SaOAuth2Consts.Param.access_token)))) {
String accessTokenKey = SaOAuth2Consts.Param.access_token;
String accessTokenCamelKey = StrUtil.toCamelCase(accessTokenKey);
if(!bodyJsonObject.containsKey(accessTokenKey) &&
!bodyJsonObject.containsKey(accessTokenCamelKey) && bodyJsonObject.containsKey("data")) {
Object data = bodyJsonObject.get("data");
if(ObjectUtil.isEmpty(data)) {
throw new AuthException(AuthResponseStatus.FAILURE);
}
bodyJsonObject = JSONUtil.parseObj(data);
}
String accessToken = bodyJsonObject.getStr(accessTokenKey);
if(ObjectUtil.isEmpty(accessToken)) {
accessToken = bodyJsonObject.getStr(accessTokenCamelKey);
}
if(ObjectUtil.isEmpty(accessToken)) {
throw new AuthException(AuthResponseStatus.FAILURE);
}
this.checkResponse(bodyJsonObject);
String accessToken = bodyJsonObject.getStr(SaOAuth2Consts.Param.access_token);
if(ObjectUtil.isEmpty(accessToken)) {
accessToken = bodyJsonObject.getStr(StrUtil.toCamelCase(SaOAuth2Consts.Param.access_token));
}
return AuthToken.builder()
.accessToken(accessToken)
.refreshToken(bodyJsonObject.getStr(SaOAuth2Consts.Param.refresh_token))
@@ -97,11 +110,18 @@ public class AuthOidcCommonRequest extends AuthDefaultRequest {
HttpHeader header = (new HttpHeader()).add(SaOAuth2Consts.Param.Authorization,
SaOAuth2Consts.TokenType.Bearer + " " + authToken.getAccessToken());
userInfo = (new HttpUtils(httpConfig))
.post(this.source.userInfo(), null, header, false).getBody();
.get(this.source.userInfo(), null, header, false).getBody();
} else {
userInfo = (new HttpUtils(httpConfig)).get(this.userInfoUrl(authToken)).getBody();
}
JSONObject bodyJsonObject = JSONUtil.parseObj(userInfo);
if(!bodyJsonObject.containsKey(authOidcBaseJson.getSourceProperty()) && bodyJsonObject.containsKey("data")) {
Object data = bodyJsonObject.get("data");
if(ObjectUtil.isEmpty(data)) {
throw new AuthException(AuthResponseStatus.FAILURE);
}
bodyJsonObject = JSONUtil.parseObj(data);
}
return AuthUser.builder()
.rawUserInfo(com.alibaba.fastjson.JSONObject.parseObject(bodyJsonObject.toString()))
.uuid(bodyJsonObject.getStr(authOidcBaseJson.getSourceProperty()))
@@ -247,24 +247,27 @@ public class AuthThirdServiceImpl extends ServiceImpl<AuthThirdMapper, AuthThird
// 校验state
if(ObjectUtil.isEmpty(state)) {
state = SaHolder.getRequest().getParam("RelayState");
if(ObjectUtil.isEmpty(state)) {
throw new CommonException("state不能为空");
}
// 定义登录端类型
String clientType = SaClientTypeEnum.B.getValue();
if(ObjectUtil.isNotEmpty(state)) {
// 获取缓存操作类
CommonCacheOperator commonCacheOperator = SpringUtil.getBean(CommonCacheOperator.class);
// 获取缓存值
Object stateCacheValueObj = commonCacheOperator.get(CONFIG_CACHE_KEY + state);
// 判断是否为空
if(ObjectUtil.isNotEmpty(stateCacheValueObj)){
// 转换为json对象
JSONObject stateCacheValueJsonObject = JSONUtil.parseObj(stateCacheValueObj);
// 判断是否包含缓存值
if(stateCacheValueJsonObject.containsKey("clientType")) {
// 获取登录端类型
clientType = stateCacheValueJsonObject.getStr("clientType");
}
// 移除缓存
commonCacheOperator.remove(CONFIG_CACHE_KEY + state);
}
}
// 获取缓存操作类
CommonCacheOperator commonCacheOperator = SpringUtil.getBean(CommonCacheOperator.class);
// 获取缓存值
Object stateCacheValueObj = commonCacheOperator.get(CONFIG_CACHE_KEY + state);
// 判断是否为空
if(ObjectUtil.isEmpty(stateCacheValueObj)){
throw new CommonException("state已失效");
}
// 转换为json对象
JSONObject stateCacheValueJsonObject = JSONUtil.parseObj(stateCacheValueObj);
// 获取登录端类型
String clientType = stateCacheValueJsonObject.getStr("clientType");
// 移除缓存
commonCacheOperator.remove(CONFIG_CACHE_KEY + state);
// 执行请求
AuthResponse<AuthUser> authResponse = authSourceBaseClient.doLogin();
if (authResponse.ok()) {
@@ -359,7 +362,7 @@ public class AuthThirdServiceImpl extends ServiceImpl<AuthThirdMapper, AuthThird
authThirdUser.setAvatar(authUser.getAvatar());
authThirdUser.setName(authUser.getUsername());
authThirdUser.setNickname(authUser.getNickname());
authThirdUser.setGender(authUser.getGender().getDesc());
authThirdUser.setGender(ObjectUtil.isNotEmpty(authUser.getGender())?authUser.getGender().getDesc():"");
authThirdUser.setCategory(authUser.getSource());
authThirdUser.setExtJson(JSONUtil.toJsonStr(authUser.getRawUserInfo()));
this.save(authThirdUser);