Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 46 additions & 0 deletions continew-auth-refresh/pom.xml
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<parent>
<groupId>top.continew.admin</groupId>
<artifactId>continew-admin</artifactId>
<version>${revision}</version>
</parent>

<artifactId>continew-auth-refresh</artifactId>
<packaging>jar</packaging>

<name>${project.artifactId}</name>
<description>认证会话模块(Refresh Token、会话轮换和 Access Token 绑定)</description>

<dependencies>
<dependency>
<groupId>${project.groupId}</groupId>
<artifactId>continew-common</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-aop</artifactId>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-test</artifactId>
<scope>test</scope>
</dependency>
</dependencies>

<build>
<plugins>
<!-- 本模块为轮换/重放等核心认证逻辑提供纯单元测试(无外部依赖),需在 CI 中实际运行 -->
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-surefire-plugin</artifactId>
<configuration>
<skip>false</skip>
</configuration>
</plugin>
</plugins>
</build>
</project>
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
/*
* Copyright (c) 2022-present Charles7c Authors. All Rights Reserved.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package top.continew.admin.auth.api;

/** 校验 Access Token 是否仍绑定有效认证会话。 */
public interface AccessSessionValidator {

/**
* 会话失效原因提示。
*
* @param accessToken Access Token
* @return 失效提示;null 表示会话仍然有效
*/
String getInvalidReason(String accessToken);

/**
* 判断 Access Token 绑定的认证会话是否已经失效。
*
* @param accessToken Access Token
* @return 已失效返回 true
*/
default boolean isInvalid(String accessToken) {
return this.getInvalidReason(accessToken) != null;
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
/*
* Copyright (c) 2022-present Charles7c Authors. All Rights Reserved.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package top.continew.admin.auth.api;

/**
* 认证会话安全策略锁的目标。
*
* @author luoqiz
*/
public record AuthPolicyLockTarget(Type type, String key) {

public static AuthPolicyLockTarget client(String clientId) {
return new AuthPolicyLockTarget(Type.CLIENT, clientId);
}

public static AuthPolicyLockTarget tenant(Long tenantId) {
return new AuthPolicyLockTarget(Type.TENANT, String.valueOf(tenantId));
}

public static AuthPolicyLockTarget user(Long userId) {
return new AuthPolicyLockTarget(Type.USER, String.valueOf(userId));
}

public enum Type {
USER,
TENANT,
CLIENT
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
/*
* Copyright (c) 2022-present Charles7c Authors. All Rights Reserved.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package top.continew.admin.auth.api;

import java.util.Collection;

/**
* 将业务方法参数解析为认证会话策略锁目标。
*
* <p>实现由 system 或 tenant 插件提供,认证会话模块不引用任何业务 Mapper。</p>
*
* @author luoqiz
*/
public interface AuthPolicyLockTargetResolver {

Collection<AuthPolicyLockTarget> resolve(Object[] args);
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
/*
* Copyright (c) 2022-present Charles7c Authors. All Rights Reserved.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package top.continew.admin.auth.api;

import java.lang.annotation.ElementType;
import java.lang.annotation.Retention;
import java.lang.annotation.RetentionPolicy;
import java.lang.annotation.Target;

/**
* 在数据库事务开始前获取认证策略写锁。
*
* <p>标记会改变登录资格或会话策略的项目业务方法,统一约束分布式锁与数据库事务的
* 顺序,避免登录/刷新路径的“Redis 锁→数据库”与管理路径的“数据库→Redis 锁”互锁。</p>
*
* @author luoqiz
*/
@Target(ElementType.METHOD)
@Retention(RetentionPolicy.RUNTIME)
public @interface AuthPolicyWriteLocked {

/** 由业务模块实现的锁目标解析器。 */
Class<? extends AuthPolicyLockTargetResolver> value();
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
/*
* Copyright (c) 2022-present Charles7c Authors. All Rights Reserved.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package top.continew.admin.auth.api;

/**
* 认证会话常量。
*
* @author luoqiz
*/
public final class AuthSessionConstants {

/** Access Token 中绑定 Refresh Session ID 的声明名称。 */
public static final String SESSION_ID_CLAIM = "sid";

/** 会话失效广播 Topic 前缀,完整 Topic 默认追加应用名:{prefix}:{spring.application.name} */
public static final String ACCESS_SESSION_INVALID_TOPIC_PREFIX = "auth:access-session-invalid";

private AuthSessionConstants() {
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
/*
* Copyright (c) 2022-present Charles7c Authors. All Rights Reserved.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package top.continew.admin.auth.api;

/**
* 认证会话撤销通知器。
*
* @author luoqiz
*/
public interface AuthSessionRevocationNotifier {

/**
* 通知所有实时连接撤销指定登录会话。
*
* @param sessionId Refresh Session ID
*/
void notifyRevoked(String sessionId);
}
Loading
Loading