RestTemplate 添加公共的请求头信息

发布时间:2024年01月15日

场景描述

项目中 有很多的RestTemplate 接口,去调用第三方系统,原来第三方系统没有开启权限认证,可以直接调用。现在第三方系统开启了权限认证,导致 这些 RestTemplate 接口调用的时候,无法获取数据。

思路

RestTemplate 在请求第三方接口之前,为他们增加公共的请求头信息。这样第三方系统在拦截到请求之后,可以通过请求头信息,来判断是否需要进行权限认证,如果是免权限认证的接口请求,那么直接放行。

改造代码

  • 改造RestTemplate 配置类,改造前:
package com.ruoyi.web.config;

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.http.client.ClientHttpRequestFactory;
import org.springframework.http.client.SimpleClientHttpRequestFactory;
import org.springframework.web.client.RestTemplate;

import java.util.Collections;

@Configuration
public class RestTemplateConfig{

	private int timeoutms = 5 * 60 *1000;

    @Bean
    public RestTemplate restTemplate(ClientHttpRequestFactory factory){
        return new RestTemplate(factory);    }

    @Bean
    public ClientHttpRequestFactory simpleClientHttpRequestFactory(){
        SimpleClientHttpRequestFactory factory = new SimpleClientHttpRequestFactory();
        factory.setReadTimeout(timeoutms);//ms
        factory.setConnectTimeout(timeoutms);//ms
        return factory;
    }
}

  • 改造后
package com.ruoyi.web.config;

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.http.client.ClientHttpRequestFactory;
import org.springframework.http.client.SimpleClientHttpRequestFactory;
import org.springframework.web.client.RestTemplate;

import java.util.Collections;

@Configuration
public class RestTemplateConfig{

	private int timeoutms = 5 * 60 *1000;

    @Autowired
    private  TokenClientHttpRequestInterceptor tokenClientHttpRequestInterceptor;

    @Bean
    public RestTemplate restTemplate(ClientHttpRequestFactory factory){
        RestTemplate restTemplate = new RestTemplate(factory);
        restTemplate.setInterceptors(Collections.singletonList(tokenClientHttpRequestInterceptor));
        return restTemplate;
    }

    @Bean
    public ClientHttpRequestFactory simpleClientHttpRequestFactory(){
        SimpleClientHttpRequestFactory factory = new SimpleClientHttpRequestFactory();
        factory.setReadTimeout(timeoutms);//ms
        factory.setConnectTimeout(timeoutms);//ms
        return factory;
    }
}

  • 增加 自定义的 RestTemplate 请求拦截器类 TokenClientHttpRequestInterceptor
package com.ruoyi.web.config;

import org.springframework.http.HttpHeaders;
import org.springframework.http.HttpRequest;
import org.springframework.http.client.ClientHttpRequestExecution;
import org.springframework.http.client.ClientHttpRequestInterceptor;
import org.springframework.http.client.ClientHttpResponse;
import org.springframework.stereotype.Component;

import java.io.IOException;

/**
 * @Description : 自定义 RestTemplate 请求拦截器
 * @Date: 2024-01-11 12:06
 */
@Component
public class TokenClientHttpRequestInterceptor implements ClientHttpRequestInterceptor {

    private static final String ADMIN_AUTHORIZATION = "admin_authorization";

    @Override
    public ClientHttpResponse intercept(HttpRequest request, byte[] body, ClientHttpRequestExecution execution) throws IOException {
        try {
            HttpHeaders headers = request.getHeaders();

            headers.add(ADMIN_AUTHORIZATION , ADMIN_AUTHORIZATION );
        } catch (Exception e) {
            e.printStackTrace();
        }
        return execution.execute(request,body);
    }
}

  • 第三方系统部分代码
/**
 * 权限拦截
 *
 * @author xuxueli 2015-12-12 18:09:04
 */
@Component
public class PermissionInterceptor extends HandlerInterceptorAdapter {

	@Resource
	private LoginService loginService;

	@Resource
    private XxlJobUserDao xxlJobUserDao;

	private static final String ADMIN_AUTHORIZATION = "admin_authorization";

	@Override
	public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception {

		if (!(handler instanceof HandlerMethod)) {
			return super.preHandle(request, response, handler);
		}

		// if need login
		boolean needLogin = true;
		boolean needAdminuser = false;
		HandlerMethod method = (HandlerMethod)handler;

		String header = request.getHeader(ADMIN_AUTHORIZATION );
		if (header != null && header.trim().length() > 0){
            XxlJobUser user = xxlJobUserDao.loadByUserName("admin");
            request.setAttribute(LoginService.LOGIN_IDENTITY_KEY, user);
			return super.preHandle(request, response, handler);
		}
....................................
文章来源:https://blog.csdn.net/weixin_43860634/article/details/135594283
本文来自互联网用户投稿,该文观点仅代表作者本人,不代表本站立场。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。