feat: Update Druid login endpoint to use session-based authentication and remove sensitive data exposure
This commit is contained in:
@@ -1,7 +1,5 @@
|
|||||||
package com.ruoyi.web.controller.monitor;
|
package com.ruoyi.web.controller.monitor;
|
||||||
|
|
||||||
import java.util.HashMap;
|
|
||||||
import java.util.Map;
|
|
||||||
import org.springframework.beans.factory.annotation.Autowired;
|
import org.springframework.beans.factory.annotation.Autowired;
|
||||||
import org.springframework.http.CacheControl;
|
import org.springframework.http.CacheControl;
|
||||||
import org.springframework.http.ResponseEntity;
|
import org.springframework.http.ResponseEntity;
|
||||||
@@ -10,9 +8,12 @@ import org.springframework.web.bind.annotation.GetMapping;
|
|||||||
import org.springframework.web.bind.annotation.RequestMapping;
|
import org.springframework.web.bind.annotation.RequestMapping;
|
||||||
import org.springframework.web.bind.annotation.RestController;
|
import org.springframework.web.bind.annotation.RestController;
|
||||||
import com.alibaba.druid.spring.boot.autoconfigure.properties.DruidStatProperties;
|
import com.alibaba.druid.spring.boot.autoconfigure.properties.DruidStatProperties;
|
||||||
|
import com.alibaba.druid.support.http.ResourceServlet;
|
||||||
import com.ruoyi.common.core.domain.AjaxResult;
|
import com.ruoyi.common.core.domain.AjaxResult;
|
||||||
import com.ruoyi.common.utils.StringUtils;
|
import com.ruoyi.common.utils.StringUtils;
|
||||||
|
|
||||||
|
import javax.servlet.http.HttpServletRequest;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Druid 数据监控接口。
|
* Druid 数据监控接口。
|
||||||
*
|
*
|
||||||
@@ -26,29 +27,28 @@ public class DruidController
|
|||||||
private DruidStatProperties druidStatProperties;
|
private DruidStatProperties druidStatProperties;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* 获取当前环境的 Druid 登录信息,供已授权的管理前端自动登录使用。
|
* 使用当前系统登录态建立 Druid 登录态。
|
||||||
*
|
*
|
||||||
* 注意:该接口返回敏感信息,只允许拥有数据监控权限的用户访问,并禁止缓存。
|
* 不向前端返回 Druid 账号密码,避免触发浏览器密码安全提示和暴露监控账号。
|
||||||
*/
|
*/
|
||||||
@PreAuthorize("@ss.hasPermi('monitor:druid:list')")
|
@PreAuthorize("@ss.hasPermi('monitor:druid:list')")
|
||||||
@GetMapping("/credentials")
|
@GetMapping("/sso")
|
||||||
public ResponseEntity<AjaxResult> getCredentials()
|
public ResponseEntity<AjaxResult> sso(HttpServletRequest request)
|
||||||
{
|
{
|
||||||
DruidStatProperties.StatViewServlet statViewServlet = druidStatProperties.getStatViewServlet();
|
DruidStatProperties.StatViewServlet statViewServlet = druidStatProperties.getStatViewServlet();
|
||||||
if (statViewServlet == null || !statViewServlet.isEnabled()
|
if (statViewServlet == null || !statViewServlet.isEnabled()
|
||||||
|| StringUtils.isEmpty(statViewServlet.getLoginUsername())
|
|| StringUtils.isEmpty(statViewServlet.getLoginUsername()))
|
||||||
|| StringUtils.isEmpty(statViewServlet.getLoginPassword()))
|
|
||||||
{
|
{
|
||||||
return ResponseEntity.ok()
|
return ResponseEntity.ok()
|
||||||
.cacheControl(CacheControl.noStore())
|
.cacheControl(CacheControl.noStore())
|
||||||
.body(AjaxResult.error("Druid 监控登录配置未启用"));
|
.body(AjaxResult.error("Druid 监控登录配置未启用"));
|
||||||
}
|
}
|
||||||
|
|
||||||
Map<String, String> credentials = new HashMap<>(2);
|
request.getSession(true).setAttribute(
|
||||||
credentials.put("username", statViewServlet.getLoginUsername());
|
ResourceServlet.SESSION_USER_KEY,
|
||||||
credentials.put("password", statViewServlet.getLoginPassword());
|
statViewServlet.getLoginUsername());
|
||||||
return ResponseEntity.ok()
|
return ResponseEntity.ok()
|
||||||
.cacheControl(CacheControl.noStore())
|
.cacheControl(CacheControl.noStore())
|
||||||
.body(AjaxResult.success(credentials));
|
.body(AjaxResult.success());
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user