admin
2020-12-31 74196bcc835d9b76cdd1bc3d85b0dfbe0191fc00
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
package com.ks.daylucky.aspect;
 
import org.aspectj.lang.ProceedingJoinPoint;
import org.aspectj.lang.annotation.Around;
import org.aspectj.lang.annotation.Aspect;
import org.springframework.core.annotation.Order;
import org.springframework.stereotype.Component;
import org.springframework.web.context.request.RequestContextHolder;
import org.springframework.web.context.request.ServletRequestAttributes;
import org.yeshi.utils.JsonUtil;
import org.yeshi.utils.StringUtil;
 
import javax.servlet.http.HttpServletRequest;
import javax.validation.Validator;
import java.io.PrintWriter;
import java.util.*;
 
/**
 * 参数检查AOP
 */
@Aspect
@Order(1)
@Component
public class ApiClientSignAspect {
 
    public static final String EDP = "execution(* com.ks.daylucky.controller.api.client.**.*(..))";
    private final static String SECRET = "123123123";
 
    @Around(EDP)
    public Object validSign(ProceedingJoinPoint joinPoint) throws Throwable {
        ServletRequestAttributes servletContainer = (ServletRequestAttributes) RequestContextHolder
                .getRequestAttributes();
 
        HttpServletRequest request = servletContainer.getRequest();
        Map<String, String[]> pm = request.getParameterMap();
        Map<String, String> paramsMap = new HashMap<>();
        for (Iterator<String> its = pm.keySet().iterator(); its.hasNext(); ) {
            String key = its.next();
            paramsMap.put(key, pm.get(key)[0]);
        }
 
 
        List<String> dataSource = new ArrayList<>();
        for (Iterator<String> its = paramsMap.keySet().iterator(); its.hasNext(); ) {
            String key = its.next();
            if (!key.equalsIgnoreCase("sign")) {
                dataSource.add(key + "=" + paramsMap.get(key));
            }
        }
        Collections.sort(dataSource);
        String src = StringUtil.concat(dataSource, "&") + SECRET;
        String sign = StringUtil.Md5(src);
 
        if (!sign.equalsIgnoreCase(paramsMap.get("sign"))) {
            PrintWriter out = servletContainer.getResponse().getWriter();
            //签名出错
            out.print(JsonUtil.loadFalseResult(-1, "签名出错"));
            out.close();
        }
        return joinPoint.proceed(joinPoint.getArgs());
    }
 
 
}