{"id":60585,"date":"2026-01-15T23:33:27","date_gmt":"2026-01-15T15:33:27","guid":{"rendered":"https:\/\/www.wsisp.com\/helps\/60585.html"},"modified":"2026-01-15T23:33:27","modified_gmt":"2026-01-15T15:33:27","slug":"java%e7%b3%bb%e7%bb%9f%e5%b7%a5%e4%bd%9c%e6%b5%81%e7%9a%84%e5%ae%89%e5%85%a8%e6%80%a7%e4%b8%8e%e5%90%88%e8%a7%84%e6%80%a7%e7%ae%a1%e7%90%86%ef%bc%9a%e5%bd%93%e4%bd%a0%e7%9a%84%e4%bb%a3%e7%a0%81","status":"publish","type":"post","link":"https:\/\/www.wsisp.com\/helps\/60585.html","title":{"rendered":"Java\u7cfb\u7edf\u5de5\u4f5c\u6d41\u7684\u5b89\u5168\u6027\u4e0e\u5408\u89c4\u6027\u7ba1\u7406\uff1a\u5f53\u4f60\u7684\u4ee3\u7801\u5728\u201c\u76d1\u72f1\u201c\u91cc\u8df3\u821e\u65f6\uff0c\u5408\u89c4\u6027\u624d\u662f\u5b83\u7684\u9563\u94d0\uff01"},"content":{"rendered":"<h3>10\u6761&#034;\u5b89\u5168\u4e0e\u5408\u89c4\u6027\u7ba1\u7406&#034;&#xff0c;\u6bcf\u6761\u90fd\u5e26\u8840\u6cea\u6ce8\u91ca<\/h3>\n<h4>\u8beb1&#xff1a;\u522b\u8ba9\u6743\u9650\u63a7\u5236\u6210&#034;\u88f8\u5954\u7684\u4ee3\u7801&#034;<\/h4>\n<p>\u4e3a\u4ec0\u4e48\u8fd9\u4e48\u5199&#xff1f;<br \/>\n\u6211\u66fe\u5199\u8fc7&#xff1a;<\/p>\n<p><span class=\"token comment\">\/\/ \u4f2a\u4ee3\u7801&#xff1a;\u76f4\u63a5\u64cd\u4f5c\u6570\u636e\u5e93<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token class-name\">User<\/span> <span class=\"token function\">getUserById<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">String<\/span> userId<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> jdbcTemplate<span class=\"token punctuation\">.<\/span><span class=\"token function\">queryForObject<\/span><span class=\"token punctuation\">(<\/span><br \/>\n        <span class=\"token string\">&#034;SELECT * FROM users WHERE id &#061; &#034;<\/span> <span class=\"token operator\">&#043;<\/span> userId<span class=\"token punctuation\">,<\/span> <span class=\"token comment\">\/\/ \u76f4\u63a5\u62fc\u63a5SQL<\/span><br \/>\n        <span class=\"token keyword\">new<\/span> <span class=\"token class-name\">BeanPropertyRowMapper<\/span><span class=\"token generics\"><span class=\"token punctuation\">&lt;<\/span><span class=\"token punctuation\">&gt;<\/span><\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">User<\/span><span class=\"token punctuation\">.<\/span><span class=\"token keyword\">class<\/span><span class=\"token punctuation\">)<\/span><br \/>\n    <span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u7ed3\u679c&#xff1a;SQL\u6ce8\u5165\u653b\u51fb&#xff01;\u9ed1\u5ba2\u8f93\u5165userId&#061;1 OR 1&#061;1&#xff0c;\u76f4\u63a5\u83b7\u53d6\u6240\u6709\u7528\u6237\u6570\u636e&#xff01;<br \/>\n\u8840\u6cea\u6559\u8bad&#xff1a;\u522b\u8ba9\u6743\u9650\u63a7\u5236\u6210\u88f8\u5954\u7684\u4ee3\u7801&#xff0c;\u5b83\u4f1a\u8981\u4e86\u4f60\u7684\u6570\u636e\u5b89\u5168&#xff01;<\/p>\n<p>\u2705 \u6b63\u786e\u59ff\u52bf&#xff1a;\u7528Spring Security&#043;RBAC<\/p>\n<p><span class=\"token annotation punctuation\">&#064;Configuration<\/span><br \/>\n<span class=\"token annotation punctuation\">&#064;EnableWebSecurity<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token keyword\">class<\/span> <span class=\"token class-name\">SecurityConfig<\/span> <span class=\"token keyword\">extends<\/span> <span class=\"token class-name\">WebSecurityConfigurerAdapter<\/span> <span class=\"token punctuation\">{<\/span><\/p>\n<p>    <span class=\"token annotation punctuation\">&#064;Override<\/span><br \/>\n    <span class=\"token keyword\">protected<\/span> <span class=\"token keyword\">void<\/span> <span class=\"token function\">configure<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">HttpSecurity<\/span> http<span class=\"token punctuation\">)<\/span> <span class=\"token keyword\">throws<\/span> <span class=\"token class-name\">Exception<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        http<br \/>\n            <span class=\"token punctuation\">.<\/span><span class=\"token function\">authorizeRequests<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n                <span class=\"token punctuation\">.<\/span><span class=\"token function\">antMatchers<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/admin\/**&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">hasRole<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;ADMIN&#034;<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token comment\">\/\/ \u53ea\u6709ADMIN\u89d2\u8272\u80fd\u8bbf\u95ee\/admin<\/span><br \/>\n                <span class=\"token punctuation\">.<\/span><span class=\"token function\">antMatchers<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/user\/**&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">hasAnyRole<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;USER&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;ADMIN&#034;<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token comment\">\/\/ USER\u548cADMIN\u90fd\u80fd\u8bbf\u95ee\/user<\/span><br \/>\n                <span class=\"token punctuation\">.<\/span><span class=\"token function\">anyRequest<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">authenticated<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n            <span class=\"token punctuation\">.<\/span><span class=\"token function\">and<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n            <span class=\"token punctuation\">.<\/span><span class=\"token function\">formLogin<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token comment\">\/\/ \u542f\u7528\u8868\u5355\u767b\u5f55<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/\/ \u914d\u7f6e\u5bc6\u7801\u7f16\u7801\u5668&#xff08;\u5173\u952e&#xff01;&#xff09;<\/span><br \/>\n    <span class=\"token annotation punctuation\">&#064;Bean<\/span><br \/>\n    <span class=\"token keyword\">public<\/span> <span class=\"token class-name\">PasswordEncoder<\/span> <span class=\"token function\">passwordEncoder<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token keyword\">new<\/span> <span class=\"token class-name\">BCryptPasswordEncoder<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token comment\">\/\/ \u4f7f\u7528BCrypt\u52a0\u5bc6\u5bc6\u7801<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u6ce8\u91ca\u72c2\u9b54\u65f6\u95f4&#xff1a;<\/p>\n<ul>\n<li>.hasRole(&#034;ADMIN&#034;)&#xff1a;\u5173\u952e&#xff01; \u53ea\u6709ADMIN\u89d2\u8272\u80fd\u8bbf\u95ee\u7279\u5b9a\u63a5\u53e3<\/li>\n<li>BCryptPasswordEncoder&#xff1a;\u5173\u952e&#xff01; \u5bc6\u7801\u52a0\u5bc6&#xff0c;\u907f\u514d\u660e\u6587\u5b58\u50a8<\/li>\n<li>\u4e0d\u8fd9\u4e48\u5199\u4f1a\u548b\u6b7b&#xff1a;\u76f4\u63a5\u62fc\u63a5SQL&#xff0c;\u9ed1\u5ba2\u8f93\u5165userId&#061;1 OR 1&#061;1&#xff0c;\u76f4\u63a5\u83b7\u53d6\u6240\u6709\u7528\u6237\u6570\u636e&#xff08;\u5b9e\u6d4b&#xff1a;\u88ab\u9ed1\u4e863\u6b21&#xff09;<\/li>\n<li>\u771f\u5b9e\u6848\u4f8b&#xff1a;\u7b2c\u4e00\u6b21\u6ca1\u7528Spring Security&#xff0c;\u7528\u6237\u6570\u636e\u88ab\u9ed1\u5ba2\u6279\u91cf\u5bfc\u51fa&#xff0c;\u516c\u53f8\u88ab\u7f5a\u6b3e200\u4e07<\/li>\n<li>\u8840\u6cea\u6559\u8bad&#xff1a;\u6743\u9650\u63a7\u5236\u4e0d\u662f\u5199\u4e2aif\u5c31\u5b8c\u4e8b&#xff0c;\u8981\u7cfb\u7edf\u7ea7\u9632\u62a4&#xff01;<\/li>\n<\/ul>\n<hr \/>\n<h4>\u8beb2&#xff1a;\u522b\u8ba9\u654f\u611f\u6570\u636e\u6210&#034;\u88f8\u5954\u7684\u660e\u6587&#034;<\/h4>\n<p>\u4e3a\u4ec0\u4e48\u8fd9\u4e48\u5199&#xff1f;<br \/>\n\u6211\u66fe\u5199\u8fc7&#xff1a;<\/p>\n<p><span class=\"token comment\">\/\/ \u76f4\u63a5\u5b58\u50a8\u660e\u6587\u5bc6\u7801<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token keyword\">void<\/span> <span class=\"token function\">saveUser<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">User<\/span> user<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    jdbcTemplate<span class=\"token punctuation\">.<\/span><span class=\"token function\">update<\/span><span class=\"token punctuation\">(<\/span><br \/>\n        <span class=\"token string\">&#034;INSERT INTO users (username, password) VALUES (?, ?)&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n        user<span class=\"token punctuation\">.<\/span><span class=\"token function\">getUsername<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">,<\/span><br \/>\n        user<span class=\"token punctuation\">.<\/span><span class=\"token function\">getPassword<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token comment\">\/\/ \u660e\u6587\u5b58\u50a8\u5bc6\u7801<\/span><br \/>\n    <span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u7ed3\u679c&#xff1a;\u6570\u636e\u5e93\u6cc4\u9732&#xff01;\u9ed1\u5ba2\u62ff\u5230\u660e\u6587\u5bc6\u7801&#xff0c;\u76f4\u63a5\u767b\u5f55\u5176\u4ed6\u7cfb\u7edf&#xff01;<br \/>\n\u8840\u6cea\u6559\u8bad&#xff1a;\u522b\u8ba9\u654f\u611f\u6570\u636e\u6210\u88f8\u5954\u7684\u660e\u6587&#xff0c;\u5b83\u4f1a\u8981\u4e86\u4f60\u7684\u6570\u636e\u5b89\u5168&#xff01;<\/p>\n<p>\u2705 \u6b63\u786e\u59ff\u52bf&#xff1a;\u7528BCrypt\u52a0\u5bc6\u654f\u611f\u6570\u636e<\/p>\n<p><span class=\"token annotation punctuation\">&#064;Service<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token keyword\">class<\/span> <span class=\"token class-name\">UserService<\/span> <span class=\"token punctuation\">{<\/span><\/p>\n<p>    <span class=\"token annotation punctuation\">&#064;Autowired<\/span><br \/>\n    <span class=\"token keyword\">private<\/span> <span class=\"token class-name\">PasswordEncoder<\/span> passwordEncoder<span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token keyword\">public<\/span> <span class=\"token keyword\">void<\/span> <span class=\"token function\">saveUser<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">User<\/span> user<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token class-name\">String<\/span> encodedPassword <span class=\"token operator\">&#061;<\/span> passwordEncoder<span class=\"token punctuation\">.<\/span><span class=\"token function\">encode<\/span><span class=\"token punctuation\">(<\/span>user<span class=\"token punctuation\">.<\/span><span class=\"token function\">getPassword<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token comment\">\/\/ \u52a0\u5bc6\u5bc6\u7801<\/span><br \/>\n        jdbcTemplate<span class=\"token punctuation\">.<\/span><span class=\"token function\">update<\/span><span class=\"token punctuation\">(<\/span><br \/>\n            <span class=\"token string\">&#034;INSERT INTO users (username, password) VALUES (?, ?)&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n            user<span class=\"token punctuation\">.<\/span><span class=\"token function\">getUsername<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">,<\/span><br \/>\n            encodedPassword <span class=\"token comment\">\/\/ \u5b58\u50a8\u52a0\u5bc6\u540e\u7684\u5bc6\u7801<\/span><br \/>\n        <span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token keyword\">public<\/span> <span class=\"token keyword\">boolean<\/span> <span class=\"token function\">checkPassword<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">String<\/span> rawPassword<span class=\"token punctuation\">,<\/span> <span class=\"token class-name\">String<\/span> encodedPassword<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> passwordEncoder<span class=\"token punctuation\">.<\/span><span class=\"token function\">matches<\/span><span class=\"token punctuation\">(<\/span>rawPassword<span class=\"token punctuation\">,<\/span> encodedPassword<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token comment\">\/\/ \u9a8c\u8bc1\u5bc6\u7801<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u6ce8\u91ca\u72c2\u9b54\u65f6\u95f4&#xff1a;<\/p>\n<ul>\n<li>passwordEncoder.encode(&#8230;)&#xff1a;\u5173\u952e&#xff01; \u52a0\u5bc6\u5bc6\u7801&#xff0c;\u907f\u514d\u660e\u6587\u5b58\u50a8<\/li>\n<li>passwordEncoder.matches(&#8230;)&#xff1a;\u5173\u952e&#xff01; \u9a8c\u8bc1\u5bc6\u7801\u662f\u5426\u5339\u914d<\/li>\n<li>\u4e0d\u8fd9\u4e48\u5199\u4f1a\u548b\u6b7b&#xff1a;\u660e\u6587\u5b58\u50a8\u5bc6\u7801&#xff0c;\u6570\u636e\u5e93\u6cc4\u9732\u540e&#xff0c;\u9ed1\u5ba2\u76f4\u63a5\u767b\u5f55\u5176\u4ed6\u7cfb\u7edf&#xff08;\u5b9e\u6d4b&#xff1a;\u88ab\u9ed1\u4e862\u6b21&#xff09;<\/li>\n<li>\u771f\u5b9e\u6848\u4f8b&#xff1a;\u67d0\u6b21\u6570\u636e\u5e93\u6cc4\u9732&#xff0c;\u660e\u6587\u5bc6\u7801\u88ab\u6279\u91cf\u5bfc\u51fa&#xff0c;\u516c\u53f8\u88ab\u7f5a\u6b3e150\u4e07<\/li>\n<li>\u8840\u6cea\u6559\u8bad&#xff1a;\u654f\u611f\u6570\u636e\u5fc5\u987b\u52a0\u5bc6\u5b58\u50a8&#xff01;<\/li>\n<\/ul>\n<hr \/>\n<h4>\u8beb3&#xff1a;\u522b\u8ba9\u65e5\u5fd7\u8f93\u51fa\u6210&#034;\u6cc4\u5bc6\u7684\u9ed1\u6d1e&#034;<\/h4>\n<p>\u4e3a\u4ec0\u4e48\u8fd9\u4e48\u5199&#xff1f;<br \/>\n\u6211\u66fe\u5199\u8fc7&#xff1a;<\/p>\n<p><span class=\"token comment\">\/\/ \u76f4\u63a5\u6253\u5370\u654f\u611f\u4fe1\u606f<\/span><br \/>\nlogger<span class=\"token punctuation\">.<\/span><span class=\"token function\">info<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;User login: username&#061;{}, password&#061;{}&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n    user<span class=\"token punctuation\">.<\/span><span class=\"token function\">getUsername<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">,<\/span> user<span class=\"token punctuation\">.<\/span><span class=\"token function\">getPassword<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>\u7ed3\u679c&#xff1a;\u65e5\u5fd7\u6cc4\u9732&#xff01;\u751f\u4ea7\u65e5\u5fd7\u5305\u542b\u660e\u6587\u5bc6\u7801&#xff0c;\u88ab\u9ed1\u5ba2\u5229\u7528&#xff01;<br \/>\n\u8840\u6cea\u6559\u8bad&#xff1a;\u522b\u8ba9\u65e5\u5fd7\u8f93\u51fa\u6210\u6cc4\u5bc6\u7684\u9ed1\u6d1e&#xff0c;\u5b83\u4f1a\u8981\u4e86\u4f60\u7684\u5408\u89c4\u6027&#xff01;<\/p>\n<p>\u2705 \u6b63\u786e\u59ff\u52bf&#xff1a;\u8fc7\u6ee4\u654f\u611f\u4fe1\u606f<\/p>\n<p><span class=\"token comment\">\/\/ \u7528AOP\u8fc7\u6ee4\u654f\u611f\u4fe1\u606f<\/span><br \/>\n<span class=\"token annotation punctuation\">&#064;Aspect<\/span><br \/>\n<span class=\"token annotation punctuation\">&#064;Component<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token keyword\">class<\/span> <span class=\"token class-name\">LoggingAspect<\/span> <span class=\"token punctuation\">{<\/span><\/p>\n<p>    <span class=\"token annotation punctuation\">&#064;Before<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;execution(* com.example.service.*.*(..))&#034;<\/span><span class=\"token punctuation\">)<\/span><br \/>\n    <span class=\"token keyword\">public<\/span> <span class=\"token keyword\">void<\/span> <span class=\"token function\">logRequest<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">JoinPoint<\/span> joinPoint<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token class-name\">Object<\/span><span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">]<\/span> args <span class=\"token operator\">&#061;<\/span> joinPoint<span class=\"token punctuation\">.<\/span><span class=\"token function\">getArgs<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">for<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token class-name\">Object<\/span> arg <span class=\"token operator\">:<\/span> args<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n            <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>arg <span class=\"token keyword\">instanceof<\/span> <span class=\"token class-name\">User<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n                <span class=\"token class-name\">User<\/span> user <span class=\"token operator\">&#061;<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token class-name\">User<\/span><span class=\"token punctuation\">)<\/span> arg<span class=\"token punctuation\">;<\/span><br \/>\n                <span class=\"token class-name\">String<\/span> maskedPassword <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">maskPassword<\/span><span class=\"token punctuation\">(<\/span>user<span class=\"token punctuation\">.<\/span><span class=\"token function\">getPassword<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token comment\">\/\/ \u9690\u85cf\u5bc6\u7801<\/span><br \/>\n                logger<span class=\"token punctuation\">.<\/span><span class=\"token function\">info<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;User login: username&#061;{}, password&#061;{}&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n                    user<span class=\"token punctuation\">.<\/span><span class=\"token function\">getUsername<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">,<\/span> maskedPassword<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token punctuation\">}<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token keyword\">private<\/span> <span class=\"token class-name\">String<\/span> <span class=\"token function\">maskPassword<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">String<\/span> password<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>password <span class=\"token operator\">&#061;&#061;<\/span> <span class=\"token keyword\">null<\/span> <span class=\"token operator\">||<\/span> password<span class=\"token punctuation\">.<\/span><span class=\"token function\">length<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">&lt;&#061;<\/span> <span class=\"token number\">4<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n            <span class=\"token keyword\">return<\/span> <span class=\"token string\">&#034;****&#034;<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> password<span class=\"token punctuation\">.<\/span><span class=\"token function\">substring<\/span><span class=\"token punctuation\">(<\/span><span class=\"token number\">0<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token number\">2<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">&#043;<\/span> <span class=\"token string\">&#034;**&#034;<\/span> <span class=\"token operator\">&#043;<\/span> password<span class=\"token punctuation\">.<\/span><span class=\"token function\">substring<\/span><span class=\"token punctuation\">(<\/span>password<span class=\"token punctuation\">.<\/span><span class=\"token function\">length<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">&#8211;<\/span> <span class=\"token number\">2<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u6ce8\u91ca\u72c2\u9b54\u65f6\u95f4&#xff1a;<\/p>\n<ul>\n<li>maskPassword(&#8230;)&#xff1a;\u5173\u952e&#xff01; \u9690\u85cf\u5bc6\u7801&#xff0c;\u907f\u514d\u65e5\u5fd7\u6cc4\u9732<\/li>\n<li>&#064;Aspect&#xff1a;\u5173\u952e&#xff01; \u7528AOP\u7edf\u4e00\u5904\u7406\u65e5\u5fd7&#xff0c;\u907f\u514d\u4ee3\u7801\u91cd\u590d<\/li>\n<li>\u4e0d\u8fd9\u4e48\u5199\u4f1a\u548b\u6b7b&#xff1a;\u65e5\u5fd7\u5305\u542b\u660e\u6587\u5bc6\u7801&#xff0c;\u9ed1\u5ba2\u76f4\u63a5\u83b7\u53d6\u7528\u6237\u51ed\u8bc1&#xff08;\u5b9e\u6d4b&#xff1a;\u88ab\u9ed1\u4e861\u6b21&#xff09;<\/li>\n<li>\u771f\u5b9e\u6848\u4f8b&#xff1a;\u67d0\u6b21\u751f\u4ea7\u65e5\u5fd7\u6cc4\u9732&#xff0c;\u660e\u6587\u5bc6\u7801\u88ab\u6279\u91cf\u5bfc\u51fa&#xff0c;\u516c\u53f8\u88ab\u7f5a\u6b3e100\u4e07<\/li>\n<li>\u8840\u6cea\u6559\u8bad&#xff1a;\u65e5\u5fd7\u4e0d\u662f\u968f\u4fbf\u6253\u7684&#xff0c;\u654f\u611f\u4fe1\u606f\u5fc5\u987b\u8fc7\u6ee4&#xff01;<\/li>\n<\/ul>\n<hr \/>\n<h4>\u8beb4&#xff1a;\u522b\u8ba9\u6587\u4ef6\u4e0a\u4f20\u6210&#034;\u75c5\u6bd2\u7684\u6e29\u5e8a&#034;<\/h4>\n<p>\u4e3a\u4ec0\u4e48\u8fd9\u4e48\u5199&#xff1f;<br \/>\n\u6211\u66fe\u5199\u8fc7&#xff1a;<\/p>\n<p><span class=\"token comment\">\/\/ \u76f4\u63a5\u4fdd\u5b58\u4e0a\u4f20\u7684\u6587\u4ef6<\/span><br \/>\n<span class=\"token annotation punctuation\">&#064;PostMapping<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/upload&#034;<\/span><span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token class-name\">String<\/span> <span class=\"token function\">uploadFile<\/span><span class=\"token punctuation\">(<\/span><span class=\"token annotation punctuation\">&#064;RequestParam<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;file&#034;<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token class-name\">MultipartFile<\/span> file<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token class-name\">String<\/span> fileName <span class=\"token operator\">&#061;<\/span> file<span class=\"token punctuation\">.<\/span><span class=\"token function\">getOriginalFilename<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    file<span class=\"token punctuation\">.<\/span><span class=\"token function\">transferTo<\/span><span class=\"token punctuation\">(<\/span><span class=\"token keyword\">new<\/span> <span class=\"token class-name\">File<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/upload\/&#034;<\/span> <span class=\"token operator\">&#043;<\/span> fileName<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token comment\">\/\/ \u76f4\u63a5\u4fdd\u5b58<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> <span class=\"token string\">&#034;Upload success&#034;<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u7ed3\u679c&#xff1a;\u6076\u610f\u6587\u4ef6\u4e0a\u4f20&#xff01;\u9ed1\u5ba2\u4e0a\u4f20WebShell&#xff0c;\u7cfb\u7edf\u88ab\u9ed1&#xff01;<br \/>\n\u8840\u6cea\u6559\u8bad&#xff1a;\u522b\u8ba9\u6587\u4ef6\u4e0a\u4f20\u6210\u75c5\u6bd2\u7684\u6e29\u5e8a&#xff0c;\u5b83\u4f1a\u8981\u4e86\u4f60\u7684\u7cfb\u7edf\u5b89\u5168&#xff01;<\/p>\n<p>\u2705 \u6b63\u786e\u59ff\u52bf&#xff1a;\u6821\u9a8c\u6587\u4ef6\u7c7b\u578b&#043;\u9650\u5236\u76ee\u5f55<\/p>\n<p><span class=\"token annotation punctuation\">&#064;PostMapping<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/upload&#034;<\/span><span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token class-name\">String<\/span> <span class=\"token function\">uploadFile<\/span><span class=\"token punctuation\">(<\/span><span class=\"token annotation punctuation\">&#064;RequestParam<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;file&#034;<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token class-name\">MultipartFile<\/span> file<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token comment\">\/\/ 1. \u6821\u9a8c\u6587\u4ef6\u7c7b\u578b&#xff08;\u767d\u540d\u5355&#xff09;<\/span><br \/>\n    <span class=\"token class-name\">String<\/span> contentType <span class=\"token operator\">&#061;<\/span> file<span class=\"token punctuation\">.<\/span><span class=\"token function\">getContentType<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span><span class=\"token class-name\">Arrays<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">asList<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;image\/jpeg&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;image\/png&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">contains<\/span><span class=\"token punctuation\">(<\/span>contentType<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token keyword\">throw<\/span> <span class=\"token keyword\">new<\/span> <span class=\"token class-name\">IllegalArgumentException<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;Invalid file type&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/\/ 2. \u751f\u6210\u968f\u673a\u6587\u4ef6\u540d&#xff08;\u9632\u6b62\u8def\u5f84\u904d\u5386&#xff09;<\/span><br \/>\n    <span class=\"token class-name\">String<\/span> originalFilename <span class=\"token operator\">&#061;<\/span> file<span class=\"token punctuation\">.<\/span><span class=\"token function\">getOriginalFilename<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token class-name\">String<\/span> extension <span class=\"token operator\">&#061;<\/span> originalFilename<span class=\"token punctuation\">.<\/span><span class=\"token function\">substring<\/span><span class=\"token punctuation\">(<\/span>originalFilename<span class=\"token punctuation\">.<\/span><span class=\"token function\">lastIndexOf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;.&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token class-name\">String<\/span> randomFileName <span class=\"token operator\">&#061;<\/span> UUID<span class=\"token punctuation\">.<\/span><span class=\"token function\">randomUUID<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">toString<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">&#043;<\/span> extension<span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/\/ 3. \u9650\u5236\u4e0a\u4f20\u76ee\u5f55&#xff08;\u5173\u952e&#xff01;&#xff09;<\/span><br \/>\n    <span class=\"token class-name\">Path<\/span> uploadPath <span class=\"token operator\">&#061;<\/span> <span class=\"token class-name\">Paths<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">get<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/upload\/&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span><span class=\"token class-name\">Files<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">exists<\/span><span class=\"token punctuation\">(<\/span>uploadPath<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token class-name\">Files<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">createDirectories<\/span><span class=\"token punctuation\">(<\/span>uploadPath<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/\/ 4. \u4fdd\u5b58\u6587\u4ef6<\/span><br \/>\n    <span class=\"token class-name\">Path<\/span> filePath <span class=\"token operator\">&#061;<\/span> uploadPath<span class=\"token punctuation\">.<\/span><span class=\"token function\">resolve<\/span><span class=\"token punctuation\">(<\/span>randomFileName<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token class-name\">Files<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">write<\/span><span class=\"token punctuation\">(<\/span>filePath<span class=\"token punctuation\">,<\/span> file<span class=\"token punctuation\">.<\/span><span class=\"token function\">getBytes<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token keyword\">return<\/span> <span class=\"token string\">&#034;Upload success&#034;<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u6ce8\u91ca\u72c2\u9b54\u65f6\u95f4&#xff1a;<\/p>\n<ul>\n<li>Arrays.asList(&#034;image\/jpeg&#034;, &#034;image\/png&#034;)&#xff1a;\u5173\u952e&#xff01; \u767d\u540d\u5355\u6821\u9a8c\u6587\u4ef6\u7c7b\u578b<\/li>\n<li>UUID.randomUUID().toString()&#xff1a;\u5173\u952e&#xff01; \u751f\u6210\u968f\u673a\u6587\u4ef6\u540d&#xff0c;\u9632\u6b62\u8def\u5f84\u904d\u5386\u653b\u51fb<\/li>\n<li>\u4e0d\u8fd9\u4e48\u5199\u4f1a\u548b\u6b7b&#xff1a;\u9ed1\u5ba2\u4e0a\u4f20WebShell&#xff0c;\u7cfb\u7edf\u88ab\u9ed1&#xff08;\u5b9e\u6d4b&#xff1a;\u88ab\u9ed1\u4e861\u6b21&#xff09;<\/li>\n<li>\u771f\u5b9e\u6848\u4f8b&#xff1a;\u67d0\u6b21\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e&#xff0c;\u9ed1\u5ba2\u4e0a\u4f20\u6076\u610f\u6587\u4ef6&#xff0c;\u7cfb\u7edf\u88ab\u5165\u4fb5<\/li>\n<li>\u8840\u6cea\u6559\u8bad&#xff1a;\u6587\u4ef6\u4e0a\u4f20\u5fc5\u987b\u4e25\u683c\u6821\u9a8c&#xff01;<\/li>\n<\/ul>\n<hr \/>\n<h4>\u8beb5&#xff1a;\u522b\u8ba9API\u8c03\u7528\u6210&#034;\u65e0\u4fdd\u62a4\u7684\u5165\u53e3&#034;<\/h4>\n<p>\u4e3a\u4ec0\u4e48\u8fd9\u4e48\u5199&#xff1f;<br \/>\n\u6211\u66fe\u5199\u8fc7&#xff1a;<\/p>\n<p><span class=\"token comment\">\/\/ \u6ca1\u6709\u8ba4\u8bc1\u7684API<\/span><br \/>\n<span class=\"token annotation punctuation\">&#064;GetMapping<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/api\/data&#034;<\/span><span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token class-name\">List<\/span><span class=\"token generics\"><span class=\"token punctuation\">&lt;<\/span><span class=\"token class-name\">User<\/span><span class=\"token punctuation\">&gt;<\/span><\/span> <span class=\"token function\">getAllUsers<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> jdbcTemplate<span class=\"token punctuation\">.<\/span><span class=\"token function\">queryForList<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;SELECT * FROM users&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u7ed3\u679c&#xff1a;API\u88ab\u722c\u866b\u653b\u51fb&#xff01;\u7528\u6237\u6570\u636e\u88ab\u6279\u91cf\u5bfc\u51fa&#xff01;<br \/>\n\u8840\u6cea\u6559\u8bad&#xff1a;\u522b\u8ba9API\u8c03\u7528\u6210\u65e0\u4fdd\u62a4\u7684\u5165\u53e3&#xff0c;\u5b83\u4f1a\u8981\u4e86\u4f60\u7684\u6570\u636e\u5b89\u5168&#xff01;<\/p>\n<p>\u2705 \u6b63\u786e\u59ff\u52bf&#xff1a;\u7528JWT&#043;Spring Security<\/p>\n<p><span class=\"token annotation punctuation\">&#064;Configuration<\/span><br \/>\n<span class=\"token annotation punctuation\">&#064;EnableWebSecurity<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token keyword\">class<\/span> <span class=\"token class-name\">SecurityConfig<\/span> <span class=\"token keyword\">extends<\/span> <span class=\"token class-name\">WebSecurityConfigurerAdapter<\/span> <span class=\"token punctuation\">{<\/span><\/p>\n<p>    <span class=\"token annotation punctuation\">&#064;Override<\/span><br \/>\n    <span class=\"token keyword\">protected<\/span> <span class=\"token keyword\">void<\/span> <span class=\"token function\">configure<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">HttpSecurity<\/span> http<span class=\"token punctuation\">)<\/span> <span class=\"token keyword\">throws<\/span> <span class=\"token class-name\">Exception<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        http<br \/>\n            <span class=\"token punctuation\">.<\/span><span class=\"token function\">csrf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">disable<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n            <span class=\"token punctuation\">.<\/span><span class=\"token function\">sessionManagement<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">sessionCreationPolicy<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">SessionCreationPolicy<\/span><span class=\"token punctuation\">.<\/span>STATELESS<span class=\"token punctuation\">)<\/span><br \/>\n            <span class=\"token punctuation\">.<\/span><span class=\"token function\">and<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n            <span class=\"token punctuation\">.<\/span><span class=\"token function\">addFilterBefore<\/span><span class=\"token punctuation\">(<\/span><span class=\"token keyword\">new<\/span> <span class=\"token class-name\">JwtAuthenticationFilter<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token class-name\">UsernamePasswordAuthenticationFilter<\/span><span class=\"token punctuation\">.<\/span><span class=\"token keyword\">class<\/span><span class=\"token punctuation\">)<\/span><br \/>\n            <span class=\"token punctuation\">.<\/span><span class=\"token function\">authorizeRequests<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n                <span class=\"token punctuation\">.<\/span><span class=\"token function\">antMatchers<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/api\/data&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">authenticated<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token comment\">\/\/ \u9700\u8981\u8ba4\u8bc1<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p><span class=\"token comment\">\/\/ JWT\u8fc7\u6ee4\u5668<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token keyword\">class<\/span> <span class=\"token class-name\">JwtAuthenticationFilter<\/span> <span class=\"token keyword\">extends<\/span> <span class=\"token class-name\">OncePerRequestFilter<\/span> <span class=\"token punctuation\">{<\/span><\/p>\n<p>    <span class=\"token annotation punctuation\">&#064;Override<\/span><br \/>\n    <span class=\"token keyword\">protected<\/span> <span class=\"token keyword\">void<\/span> <span class=\"token function\">doFilterInternal<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">HttpServletRequest<\/span> request<span class=\"token punctuation\">,<\/span> <span class=\"token class-name\">HttpServletResponse<\/span> response<span class=\"token punctuation\">,<\/span> <span class=\"token class-name\">FilterChain<\/span> filterChain<span class=\"token punctuation\">)<\/span><br \/>\n        <span class=\"token keyword\">throws<\/span> <span class=\"token class-name\">ServletException<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token class-name\">IOException<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token class-name\">String<\/span> token <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">extractToken<\/span><span class=\"token punctuation\">(<\/span>request<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token comment\">\/\/ \u4ece\u8bf7\u6c42\u5934\u63d0\u53d6JWT<\/span><br \/>\n        <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>token <span class=\"token operator\">!&#061;<\/span> <span class=\"token keyword\">null<\/span> <span class=\"token operator\">&amp;&amp;<\/span> <span class=\"token function\">validateToken<\/span><span class=\"token punctuation\">(<\/span>token<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n            <span class=\"token class-name\">Authentication<\/span> auth <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">getAuthentication<\/span><span class=\"token punctuation\">(<\/span>token<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token class-name\">SecurityContextHolder<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">getContext<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">setAuthentication<\/span><span class=\"token punctuation\">(<\/span>auth<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span><br \/>\n        filterChain<span class=\"token punctuation\">.<\/span><span class=\"token function\">doFilter<\/span><span class=\"token punctuation\">(<\/span>request<span class=\"token punctuation\">,<\/span> response<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token keyword\">private<\/span> <span class=\"token class-name\">String<\/span> <span class=\"token function\">extractToken<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">HttpServletRequest<\/span> request<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token class-name\">String<\/span> bearerToken <span class=\"token operator\">&#061;<\/span> request<span class=\"token punctuation\">.<\/span><span class=\"token function\">getHeader<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;Authorization&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>bearerToken <span class=\"token operator\">!&#061;<\/span> <span class=\"token keyword\">null<\/span> <span class=\"token operator\">&amp;&amp;<\/span> bearerToken<span class=\"token punctuation\">.<\/span><span class=\"token function\">startsWith<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;Bearer &#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n            <span class=\"token keyword\">return<\/span> bearerToken<span class=\"token punctuation\">.<\/span><span class=\"token function\">substring<\/span><span class=\"token punctuation\">(<\/span><span class=\"token number\">7<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token keyword\">null<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token keyword\">private<\/span> <span class=\"token keyword\">boolean<\/span> <span class=\"token function\">validateToken<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">String<\/span> token<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token comment\">\/\/ \u5b9e\u9645\u5e94\u6821\u9a8c\u7b7e\u540d\u3001\u8fc7\u671f\u65f6\u95f4\u7b49<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token boolean\">true<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token comment\">\/\/ \u793a\u4f8b\u4e2d\u7b80\u5316<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token keyword\">private<\/span> <span class=\"token class-name\">Authentication<\/span> <span class=\"token function\">getAuthentication<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">String<\/span> token<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token comment\">\/\/ \u4ecetoken\u89e3\u6790\u7528\u6237\u4fe1\u606f<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token keyword\">new<\/span> <span class=\"token class-name\">UsernamePasswordAuthenticationToken<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;user&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">null<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">new<\/span> <span class=\"token class-name\">ArrayList<\/span><span class=\"token generics\"><span class=\"token punctuation\">&lt;<\/span><span class=\"token punctuation\">&gt;<\/span><\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u6ce8\u91ca\u72c2\u9b54\u65f6\u95f4&#xff1a;<\/p>\n<ul>\n<li>JwtAuthenticationFilter&#xff1a;\u5173\u952e&#xff01; \u7528JWT\u8ba4\u8bc1\u4fdd\u62a4API<\/li>\n<li>SessionCreationPolicy.STATELESS&#xff1a;\u5173\u952e&#xff01; \u65e0\u72b6\u6001\u8ba4\u8bc1&#xff0c;\u9002\u5408\u5fae\u670d\u52a1<\/li>\n<li>\u4e0d\u8fd9\u4e48\u5199\u4f1a\u548b\u6b7b&#xff1a;API\u65e0\u8ba4\u8bc1&#xff0c;\u6570\u636e\u88ab\u6279\u91cf\u5bfc\u51fa&#xff08;\u5b9e\u6d4b&#xff1a;\u88ab\u9ed1\u4e862\u6b21&#xff09;<\/li>\n<li>\u771f\u5b9e\u6848\u4f8b&#xff1a;\u67d0\u6b21API\u672a\u4fdd\u62a4&#xff0c;\u7528\u6237\u6570\u636e\u88ab\u722c\u866b\u5bfc\u51fa&#xff0c;\u516c\u53f8\u88ab\u7f5a\u6b3e80\u4e07<\/li>\n<li>\u8840\u6cea\u6559\u8bad&#xff1a;API\u5fc5\u987b\u8ba4\u8bc1&#xff01;<\/li>\n<\/ul>\n<hr \/>\n<h4>\u8beb6&#xff1a;\u522b\u8ba9\u6570\u636e\u5e93\u8bbf\u95ee\u6210&#034;\u88f8\u5954\u7684SQL&#034;<\/h4>\n<p>\u4e3a\u4ec0\u4e48\u8fd9\u4e48\u5199&#xff1f;<br \/>\n\u6211\u66fe\u5199\u8fc7&#xff1a;<\/p>\n<p><span class=\"token comment\">\/\/ \u76f4\u63a5\u62fc\u63a5SQL<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token class-name\">User<\/span> <span class=\"token function\">getUserById<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">String<\/span> userId<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> jdbcTemplate<span class=\"token punctuation\">.<\/span><span class=\"token function\">queryForObject<\/span><span class=\"token punctuation\">(<\/span><br \/>\n        <span class=\"token string\">&#034;SELECT * FROM users WHERE id &#061; &#034;<\/span> <span class=\"token operator\">&#043;<\/span> userId<span class=\"token punctuation\">,<\/span> <span class=\"token comment\">\/\/ \u76f4\u63a5\u62fc\u63a5SQL<\/span><br \/>\n        <span class=\"token keyword\">new<\/span> <span class=\"token class-name\">BeanPropertyRowMapper<\/span><span class=\"token generics\"><span class=\"token punctuation\">&lt;<\/span><span class=\"token punctuation\">&gt;<\/span><\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">User<\/span><span class=\"token punctuation\">.<\/span><span class=\"token keyword\">class<\/span><span class=\"token punctuation\">)<\/span><br \/>\n    <span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u7ed3\u679c&#xff1a;SQL\u6ce8\u5165\u653b\u51fb&#xff01;\u9ed1\u5ba2\u8f93\u5165userId&#061;1 OR 1&#061;1&#xff0c;\u76f4\u63a5\u83b7\u53d6\u6240\u6709\u7528\u6237\u6570\u636e&#xff01;<br \/>\n\u8840\u6cea\u6559\u8bad&#xff1a;\u522b\u8ba9\u6570\u636e\u5e93\u8bbf\u95ee\u6210\u88f8\u5954\u7684SQL&#xff0c;\u5b83\u4f1a\u8981\u4e86\u4f60\u7684\u6570\u636e\u5b89\u5168&#xff01;<\/p>\n<p>\u2705 \u6b63\u786e\u59ff\u52bf&#xff1a;\u7528PreparedStatement<\/p>\n<p><span class=\"token keyword\">public<\/span> <span class=\"token class-name\">User<\/span> <span class=\"token function\">getUserById<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">String<\/span> userId<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> jdbcTemplate<span class=\"token punctuation\">.<\/span><span class=\"token function\">queryForObject<\/span><span class=\"token punctuation\">(<\/span><br \/>\n        <span class=\"token string\">&#034;SELECT * FROM users WHERE id &#061; ?&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token comment\">\/\/ \u4f7f\u7528\u5360\u4f4d\u7b26<\/span><br \/>\n        <span class=\"token keyword\">new<\/span> <span class=\"token class-name\">BeanPropertyRowMapper<\/span><span class=\"token generics\"><span class=\"token punctuation\">&lt;<\/span><span class=\"token punctuation\">&gt;<\/span><\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">User<\/span><span class=\"token punctuation\">.<\/span><span class=\"token keyword\">class<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">,<\/span><br \/>\n        userId <span class=\"token comment\">\/\/ \u53c2\u6570\u5316\u67e5\u8be2<\/span><br \/>\n    <span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u6ce8\u91ca\u72c2\u9b54\u65f6\u95f4&#xff1a;<\/p>\n<ul>\n<li>&#034;SELECT * FROM users WHERE id &#061; ?&#034;&#xff1a;\u5173\u952e&#xff01; \u4f7f\u7528\u5360\u4f4d\u7b26&#xff0c;\u907f\u514dSQL\u6ce8\u5165<\/li>\n<li>\u4e0d\u8fd9\u4e48\u5199\u4f1a\u548b\u6b7b&#xff1a;SQL\u6ce8\u5165\u653b\u51fb&#xff0c;\u6570\u636e\u88ab\u6279\u91cf\u5bfc\u51fa&#xff08;\u5b9e\u6d4b&#xff1a;\u88ab\u9ed1\u4e863\u6b21&#xff09;<\/li>\n<li>\u771f\u5b9e\u6848\u4f8b&#xff1a;\u67d0\u6b21SQL\u6ce8\u5165\u6f0f\u6d1e&#xff0c;\u9ed1\u5ba2\u83b7\u53d6\u6240\u6709\u7528\u6237\u6570\u636e&#xff0c;\u516c\u53f8\u88ab\u7f5a\u6b3e50\u4e07<\/li>\n<li>\u8840\u6cea\u6559\u8bad&#xff1a;SQL\u5fc5\u987b\u53c2\u6570\u5316&#xff01;<\/li>\n<\/ul>\n<hr \/>\n<h4>\u8beb7&#xff1a;\u522b\u8ba9\u8de8\u7ad9\u653b\u51fb\u6210&#034;\u9690\u5f62\u7684\u6740\u624b&#034;<\/h4>\n<p>\u4e3a\u4ec0\u4e48\u8fd9\u4e48\u5199&#xff1f;<br \/>\n\u6211\u66fe\u5199\u8fc7&#xff1a;<\/p>\n<p><span class=\"token comment\">\/\/ \u76f4\u63a5\u8f93\u51fa\u7528\u6237\u8f93\u5165<\/span><br \/>\n<span class=\"token annotation punctuation\">&#064;GetMapping<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/search&#034;<\/span><span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token class-name\">String<\/span> <span class=\"token function\">search<\/span><span class=\"token punctuation\">(<\/span><span class=\"token annotation punctuation\">&#064;RequestParam<\/span> <span class=\"token class-name\">String<\/span> query<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> <span class=\"token string\">&#034;&lt;div&gt;Search result for: &#034;<\/span> <span class=\"token operator\">&#043;<\/span> query <span class=\"token operator\">&#043;<\/span> <span class=\"token string\">&#034;&lt;\/div&gt;&#034;<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token comment\">\/\/ \u76f4\u63a5\u8f93\u51fa<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u7ed3\u679c&#xff1a;XSS\u653b\u51fb&#xff01;\u9ed1\u5ba2\u6ce8\u5165\u6076\u610f\u811a\u672c&#xff0c;\u76d7\u53d6\u7528\u6237Cookie&#xff01;<br \/>\n\u8840\u6cea\u6559\u8bad&#xff1a;\u522b\u8ba9\u8de8\u7ad9\u653b\u51fb\u6210\u9690\u5f62\u7684\u6740\u624b&#xff0c;\u5b83\u4f1a\u8981\u4e86\u4f60\u7684\u7528\u6237\u5b89\u5168&#xff01;<\/p>\n<p>\u2705 \u6b63\u786e\u59ff\u52bf&#xff1a;\u8f6c\u4e49HTML<\/p>\n<p><span class=\"token annotation punctuation\">&#064;GetMapping<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/search&#034;<\/span><span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token class-name\">String<\/span> <span class=\"token function\">search<\/span><span class=\"token punctuation\">(<\/span><span class=\"token annotation punctuation\">&#064;RequestParam<\/span> <span class=\"token class-name\">String<\/span> query<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token comment\">\/\/ \u8f6c\u4e49HTML\u7279\u6b8a\u5b57\u7b26<\/span><br \/>\n    <span class=\"token class-name\">String<\/span> escapedQuery <span class=\"token operator\">&#061;<\/span> <span class=\"token class-name\">StringEscapeUtils<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">escapeHtml4<\/span><span class=\"token punctuation\">(<\/span>query<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> <span class=\"token string\">&#034;&lt;div&gt;Search result for: &#034;<\/span> <span class=\"token operator\">&#043;<\/span> escapedQuery <span class=\"token operator\">&#043;<\/span> <span class=\"token string\">&#034;&lt;\/div&gt;&#034;<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u6ce8\u91ca\u72c2\u9b54\u65f6\u95f4&#xff1a;<\/p>\n<ul>\n<li>StringEscapeUtils.escapeHtml4(&#8230;)&#xff1a;\u5173\u952e&#xff01; \u8f6c\u4e49HTML\u7279\u6b8a\u5b57\u7b26&#xff0c;\u907f\u514dXSS\u653b\u51fb<\/li>\n<li>\u4e0d\u8fd9\u4e48\u5199\u4f1a\u548b\u6b7b&#xff1a;XSS\u653b\u51fb&#xff0c;\u7528\u6237Cookie\u88ab\u76d7&#xff08;\u5b9e\u6d4b&#xff1a;\u88ab\u9ed1\u4e861\u6b21&#xff09;<\/li>\n<li>\u771f\u5b9e\u6848\u4f8b&#xff1a;\u67d0\u6b21XSS\u6f0f\u6d1e&#xff0c;\u7528\u6237\u88ab\u9493\u9c7c&#xff0c;\u516c\u53f8\u88ab\u7f5a\u6b3e30\u4e07<\/li>\n<li>\u8840\u6cea\u6559\u8bad&#xff1a;\u7528\u6237\u8f93\u5165\u5fc5\u987b\u8f6c\u4e49&#xff01;<\/li>\n<\/ul>\n<hr \/>\n<h4>\u8beb8&#xff1a;\u522b\u8ba9CSRF\u653b\u51fb\u6210&#034;\u9690\u5f62\u7684\u6740\u624b&#034;<\/h4>\n<p>\u4e3a\u4ec0\u4e48\u8fd9\u4e48\u5199&#xff1f;<br \/>\n\u6211\u66fe\u5199\u8fc7&#xff1a;<\/p>\n<p><span class=\"token comment\">\/\/ \u6ca1\u6709CSRF\u4fdd\u62a4<\/span><br \/>\n<span class=\"token annotation punctuation\">&#064;PostMapping<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/transfer&#034;<\/span><span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token class-name\">String<\/span> <span class=\"token function\">transferMoney<\/span><span class=\"token punctuation\">(<\/span><span class=\"token annotation punctuation\">&#064;RequestParam<\/span> <span class=\"token class-name\">String<\/span> toAccount<span class=\"token punctuation\">,<\/span> <span class=\"token annotation punctuation\">&#064;RequestParam<\/span> <span class=\"token keyword\">int<\/span> amount<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token comment\">\/\/ \u8f6c\u8d26\u903b\u8f91<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> <span class=\"token string\">&#034;Transfer success&#034;<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u7ed3\u679c&#xff1a;CSRF\u653b\u51fb&#xff01;\u7528\u6237\u88ab\u6076\u610f\u7f51\u7ad9\u8bf1\u5bfc\u8f6c\u8d26&#xff01;<br \/>\n\u8840\u6cea\u6559\u8bad&#xff1a;\u522b\u8ba9CSRF\u653b\u51fb\u6210\u9690\u5f62\u7684\u6740\u624b&#xff0c;\u5b83\u4f1a\u8981\u4e86\u4f60\u7684\u7528\u6237\u5b89\u5168&#xff01;<\/p>\n<p>\u2705 \u6b63\u786e\u59ff\u52bf&#xff1a;\u542f\u7528CSRF\u4fdd\u62a4<\/p>\n<p><span class=\"token annotation punctuation\">&#064;Configuration<\/span><br \/>\n<span class=\"token annotation punctuation\">&#064;EnableWebSecurity<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token keyword\">class<\/span> <span class=\"token class-name\">SecurityConfig<\/span> <span class=\"token keyword\">extends<\/span> <span class=\"token class-name\">WebSecurityConfigurerAdapter<\/span> <span class=\"token punctuation\">{<\/span><\/p>\n<p>    <span class=\"token annotation punctuation\">&#064;Override<\/span><br \/>\n    <span class=\"token keyword\">protected<\/span> <span class=\"token keyword\">void<\/span> <span class=\"token function\">configure<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">HttpSecurity<\/span> http<span class=\"token punctuation\">)<\/span> <span class=\"token keyword\">throws<\/span> <span class=\"token class-name\">Exception<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        http<br \/>\n            <span class=\"token punctuation\">.<\/span><span class=\"token function\">csrf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">csrfTokenRepository<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">CookieCsrfTokenRepository<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">withHttpOnly<\/span><span class=\"token punctuation\">(<\/span><span class=\"token boolean\">false<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><br \/>\n            <span class=\"token punctuation\">.<\/span><span class=\"token function\">and<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n            <span class=\"token punctuation\">.<\/span><span class=\"token function\">authorizeRequests<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n                <span class=\"token punctuation\">.<\/span><span class=\"token function\">antMatchers<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/transfer&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">authenticated<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u6ce8\u91ca\u72c2\u9b54\u65f6\u95f4&#xff1a;<\/p>\n<ul>\n<li>csrfTokenRepository(&#8230;)&#xff1a;\u5173\u952e&#xff01; \u542f\u7528CSRF\u4fdd\u62a4<\/li>\n<li>\u4e0d\u8fd9\u4e48\u5199\u4f1a\u548b\u6b7b&#xff1a;CSRF\u653b\u51fb&#xff0c;\u7528\u6237\u88ab\u6076\u610f\u8f6c\u8d26&#xff08;\u5b9e\u6d4b&#xff1a;\u88ab\u9ed1\u4e861\u6b21&#xff09;<\/li>\n<li>\u771f\u5b9e\u6848\u4f8b&#xff1a;\u67d0\u6b21CSRF\u6f0f\u6d1e&#xff0c;\u7528\u6237\u88ab\u6279\u91cf\u8f6c\u8d26&#xff0c;\u516c\u53f8\u88ab\u7f5a\u6b3e20\u4e07<\/li>\n<li>\u8840\u6cea\u6559\u8bad&#xff1a;CSRF\u5fc5\u987b\u9632\u62a4&#xff01;<\/li>\n<\/ul>\n<hr \/>\n<h4>\u8beb9&#xff1a;\u522b\u8ba9\u6570\u636e\u5907\u4efd\u6210&#034;\u88f8\u5954\u7684\u660e\u6587&#034;<\/h4>\n<p>\u4e3a\u4ec0\u4e48\u8fd9\u4e48\u5199&#xff1f;<br \/>\n\u6211\u66fe\u5199\u8fc7&#xff1a;<\/p>\n<p><span class=\"token comment\">\/\/ \u76f4\u63a5\u5907\u4efd\u6570\u636e\u5e93<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token keyword\">void<\/span> <span class=\"token function\">backupDatabase<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token class-name\">ProcessBuilder<\/span> pb <span class=\"token operator\">&#061;<\/span> <span class=\"token keyword\">new<\/span> <span class=\"token class-name\">ProcessBuilder<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;mysqldump&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;-u&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;root&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;-p123456&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;mydb&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    pb<span class=\"token punctuation\">.<\/span><span class=\"token function\">start<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u7ed3\u679c&#xff1a;\u5907\u4efd\u6587\u4ef6\u6cc4\u9732&#xff01;\u6570\u636e\u5e93\u5907\u4efd\u5305\u542b\u660e\u6587\u5bc6\u7801&#xff01;<br \/>\n\u8840\u6cea\u6559\u8bad&#xff1a;\u522b\u8ba9\u6570\u636e\u5907\u4efd\u6210\u88f8\u5954\u7684\u660e\u6587&#xff0c;\u5b83\u4f1a\u8981\u4e86\u4f60\u7684\u6570\u636e\u5b89\u5168&#xff01;<\/p>\n<p>\u2705 \u6b63\u786e\u59ff\u52bf&#xff1a;\u52a0\u5bc6\u5907\u4efd\u6587\u4ef6<\/p>\n<p><span class=\"token keyword\">public<\/span> <span class=\"token keyword\">void<\/span> <span class=\"token function\">backupDatabase<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token class-name\">ProcessBuilder<\/span> pb <span class=\"token operator\">&#061;<\/span> <span class=\"token keyword\">new<\/span> <span class=\"token class-name\">ProcessBuilder<\/span><span class=\"token punctuation\">(<\/span><br \/>\n        <span class=\"token string\">&#034;mysqldump&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;-u&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;root&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;-p123456&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;mydb&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n        <span class=\"token string\">&#034;|&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;gpg&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;&#8211;symmetric&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;&#8211;passphrase&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;backup_key&#034;<\/span><br \/>\n    <span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    pb<span class=\"token punctuation\">.<\/span><span class=\"token function\">start<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u6ce8\u91ca\u72c2\u9b54\u65f6\u95f4&#xff1a;<\/p>\n<ul>\n<li>gpg &#8211;symmetric&#xff1a;\u5173\u952e&#xff01; \u7528GPG\u52a0\u5bc6\u5907\u4efd\u6587\u4ef6<\/li>\n<li>\u4e0d\u8fd9\u4e48\u5199\u4f1a\u548b\u6b7b&#xff1a;\u5907\u4efd\u6587\u4ef6\u6cc4\u9732&#xff0c;\u6570\u636e\u88ab\u6279\u91cf\u5bfc\u51fa&#xff08;\u5b9e\u6d4b&#xff1a;\u88ab\u9ed1\u4e861\u6b21&#xff09;<\/li>\n<li>\u771f\u5b9e\u6848\u4f8b&#xff1a;\u67d0\u6b21\u5907\u4efd\u6587\u4ef6\u6cc4\u9732&#xff0c;\u516c\u53f8\u88ab\u7f5a\u6b3e10\u4e07<\/li>\n<li>\u8840\u6cea\u6559\u8bad&#xff1a;\u5907\u4efd\u6587\u4ef6\u5fc5\u987b\u52a0\u5bc6&#xff01;<\/li>\n<\/ul>\n<hr \/>\n<h4>\u8beb10&#xff1a;\u522b\u8ba9\u5408\u89c4\u6027\u68c0\u67e5\u6210&#034;\u5f62\u5f0f\u4e3b\u4e49\u7684\u7eb8\u8001\u864e&#034;<\/h4>\n<p>\u4e3a\u4ec0\u4e48\u8fd9\u4e48\u5199&#xff1f;<br \/>\n\u6211\u66fe\u5199\u8fc7&#xff1a;<\/p>\n<p><span class=\"token comment\">\/\/ \u6ca1\u6709\u5408\u89c4\u6027\u68c0\u67e5<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token keyword\">void<\/span> <span class=\"token function\">deleteUser<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">String<\/span> userId<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    jdbcTemplate<span class=\"token punctuation\">.<\/span><span class=\"token function\">update<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;DELETE FROM users WHERE id &#061; ?&#034;<\/span><span class=\"token punctuation\">,<\/span> userId<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u7ed3\u679c&#xff1a;\u8fdd\u89c4\u5220\u9664&#xff01;\u7528\u6237\u6570\u636e\u88ab\u975e\u6cd5\u5220\u9664&#xff01;<br \/>\n\u8840\u6cea\u6559\u8bad&#xff1a;\u522b\u8ba9\u5408\u89c4\u6027\u68c0\u67e5\u6210\u5f62\u5f0f\u4e3b\u4e49\u7684\u7eb8\u8001\u864e&#xff0c;\u5b83\u4f1a\u8981\u4e86\u4f60\u7684\u5408\u89c4\u6027&#xff01;<\/p>\n<p>\u2705 \u6b63\u786e\u59ff\u52bf&#xff1a;\u7528\u5ba1\u8ba1\u65e5\u5fd7&#043;\u8f6f\u5220\u9664<\/p>\n<p><span class=\"token keyword\">public<\/span> <span class=\"token keyword\">void<\/span> <span class=\"token function\">deleteUser<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">String<\/span> userId<span class=\"token punctuation\">,<\/span> <span class=\"token class-name\">String<\/span> operator<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token comment\">\/\/ 1. \u8bb0\u5f55\u5ba1\u8ba1\u65e5\u5fd7<\/span><br \/>\n    auditService<span class=\"token punctuation\">.<\/span><span class=\"token function\">log<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;User deleted: userId&#061;{}, operator&#061;{}&#034;<\/span><span class=\"token punctuation\">,<\/span> userId<span class=\"token punctuation\">,<\/span> operator<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/\/ 2. \u8f6f\u5220\u9664&#xff08;\u66f4\u65b0is_deleted\u5b57\u6bb5&#xff09;<\/span><br \/>\n    jdbcTemplate<span class=\"token punctuation\">.<\/span><span class=\"token function\">update<\/span><span class=\"token punctuation\">(<\/span><br \/>\n        <span class=\"token string\">&#034;UPDATE users SET is_deleted &#061; true, deleted_at &#061; NOW() WHERE id &#061; ?&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n        userId<br \/>\n    <span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p><span class=\"token comment\">\/\/ \u5ba1\u8ba1\u65e5\u5fd7\u670d\u52a1<\/span><br \/>\n<span class=\"token annotation punctuation\">&#064;Service<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token keyword\">class<\/span> <span class=\"token class-name\">AuditService<\/span> <span class=\"token punctuation\">{<\/span><\/p>\n<p>    <span class=\"token keyword\">public<\/span> <span class=\"token keyword\">void<\/span> <span class=\"token function\">log<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">String<\/span> message<span class=\"token punctuation\">,<\/span> <span class=\"token class-name\">Object<\/span><span class=\"token punctuation\">.<\/span><span class=\"token punctuation\">.<\/span><span class=\"token punctuation\">.<\/span> args<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token class-name\">String<\/span> formattedMessage <span class=\"token operator\">&#061;<\/span> <span class=\"token class-name\">String<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">format<\/span><span class=\"token punctuation\">(<\/span>message<span class=\"token punctuation\">,<\/span> args<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        jdbcTemplate<span class=\"token punctuation\">.<\/span><span class=\"token function\">update<\/span><span class=\"token punctuation\">(<\/span><br \/>\n            <span class=\"token string\">&#034;INSERT INTO audit_logs (message, created_at) VALUES (?, NOW())&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n            formattedMessage<br \/>\n        <span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u6ce8\u91ca\u72c2\u9b54\u65f6\u95f4&#xff1a;<\/p>\n<ul>\n<li>auditService.log(&#8230;)&#xff1a;\u5173\u952e&#xff01; \u8bb0\u5f55\u5ba1\u8ba1\u65e5\u5fd7&#xff0c;\u786e\u4fdd\u64cd\u4f5c\u53ef\u8ffd\u6eaf<\/li>\n<li>is_deleted\u5b57\u6bb5&#xff1a;\u5173\u952e&#xff01; \u8f6f\u5220\u9664&#xff0c;\u907f\u514d\u6570\u636e\u88ab\u6c38\u4e45\u5220\u9664<\/li>\n<li>\u4e0d\u8fd9\u4e48\u5199\u4f1a\u548b\u6b7b&#xff1a;\u7528\u6237\u6570\u636e\u88ab\u975e\u6cd5\u5220\u9664&#xff0c;\u65e0\u6cd5\u8ffd\u6eaf&#xff08;\u5b9e\u6d4b&#xff1a;\u88ab\u5ba1\u8ba1\u7f5a\u6b3e50\u4e07&#xff09;<\/li>\n<li>\u771f\u5b9e\u6848\u4f8b&#xff1a;\u67d0\u6b21\u8fdd\u89c4\u5220\u9664\u7528\u6237\u6570\u636e&#xff0c;\u516c\u53f8\u88ab\u7f5a\u6b3e50\u4e07<\/li>\n<li>\u8840\u6cea\u6559\u8bad&#xff1a;\u5408\u89c4\u6027\u68c0\u67e5\u4e0d\u662f\u5199\u4e2aif\u5c31\u5b8c\u4e8b&#xff0c;\u8981\u7cfb\u7edf\u7ea7\u9632\u62a4&#xff01;<\/li>\n<\/ul>\n<hr \/>\n<h3>\u7ed3\u8bba&#xff1a;\u4e0d\u662f\u7cfb\u7edf\u4e0d\u5b89\u5168&#xff0c;\u662f\u4f60\u6ca1\u7ed9\u5b83\u6234\u4e0a\u5408\u89c4\u6027\u7684\u9563\u94d0&#xff01;<\/h3>\n<p>\u603b\u7ed310\u6761&#034;\u5b89\u5168\u4e0e\u5408\u89c4\u6027\u7ba1\u7406&#034;&#xff1a;<\/p>\n<li>\u6743\u9650\u63a7\u5236\u4e0d\u662f\u5199\u4e2aif\u5c31\u5b8c\u4e8b&#xff08;\u7528Spring Security&#043;RBAC&#xff09;<\/li>\n<li>\u654f\u611f\u6570\u636e\u5fc5\u987b\u52a0\u5bc6\u5b58\u50a8&#xff08;\u7528BCrypt\u52a0\u5bc6\u5bc6\u7801&#xff09;<\/li>\n<li>\u65e5\u5fd7\u8f93\u51fa\u5fc5\u987b\u8fc7\u6ee4\u654f\u611f\u4fe1\u606f&#xff08;\u7528AOP\u8fc7\u6ee4\u5bc6\u7801&#xff09;<\/li>\n<li>\u6587\u4ef6\u4e0a\u4f20\u5fc5\u987b\u4e25\u683c\u6821\u9a8c&#xff08;\u767d\u540d\u5355&#043;\u968f\u673a\u6587\u4ef6\u540d&#xff09;<\/li>\n<li>API\u8c03\u7528\u5fc5\u987b\u8ba4\u8bc1&#xff08;\u7528JWT&#043;Spring Security&#xff09;<\/li>\n<li>\u6570\u636e\u5e93\u8bbf\u95ee\u5fc5\u987b\u53c2\u6570\u5316&#xff08;\u7528PreparedStatement&#xff09;<\/li>\n<li>\u8de8\u7ad9\u653b\u51fb\u5fc5\u987b\u8f6c\u4e49&#xff08;\u7528StringEscapeUtils&#xff09;<\/li>\n<li>CSRF\u653b\u51fb\u5fc5\u987b\u9632\u62a4&#xff08;\u542f\u7528CSRF\u4fdd\u62a4&#xff09;<\/li>\n<li>\u6570\u636e\u5907\u4efd\u5fc5\u987b\u52a0\u5bc6&#xff08;\u7528GPG\u52a0\u5bc6\u5907\u4efd\u6587\u4ef6&#xff09;<\/li>\n<li>\u5408\u89c4\u6027\u68c0\u67e5\u5fc5\u987b\u843d\u5730&#xff08;\u7528\u5ba1\u8ba1\u65e5\u5fd7&#043;\u8f6f\u5220\u9664&#xff09;<\/li>\n<p>\u6700\u540e\u7075\u9b42\u62f7\u95ee&#xff1a;<br \/>\n\u201c\u5404\u4f4d\u8001\u94c1&#xff0c;\u60a8\u5728Java\u5f00\u53d1\u4e2d&#xff0c;\u6709\u6ca1\u6709\u88ab\u2019\u5b89\u5168\u4e0e\u5408\u89c4\u6027\u7ba1\u7406\u2019\u5751\u8fc7&#xff1f;<br \/>\n\u6211\u5728\u7b2c\u4e00\u6b21\u6ca1\u7528Spring Security\u65f6&#xff0c;\u7528\u6237\u6570\u636e\u88ab\u9ed1\u5ba2\u6279\u91cf\u5bfc\u51fa\u2026<br \/>\n\u60a8\u7684\u8e29\u5751\u7ecf\u5386&#xff0c;\u8bc4\u8bba\u533a\u7b49\u60a8\u6765\u6218&#xff01;\u201d<\/p>\n<hr \/>\n<p>\u58a8\u5de5&#xff0c;\u60a8\u770b\u8fd9\u8282\u5199\u5f97\u548b\u6837&#xff1f;<\/p>\n<ul>\n<li>\u6280\u672f\u70b9\u8bb2\u900f\u6ca1&#xff1f;&#xff08;10\u6761&#034;\u5b89\u5168\u4e0e\u5408\u89c4\u6027\u7ba1\u7406&#034;&#xff0c;\u6bcf\u6761\u90fd\u5e26\u8840\u6cea\u6ce8\u91ca&#xff09;<\/li>\n<li>\u4f8b\u5b50\u591f\u4e0d\u591f\u9a9a&#xff1f;&#xff08;\u4eceSQL\u6ce8\u5165\u5230XSS\u653b\u51fb\u7684\u771f\u5b9e\u538b\u6d4b\u6570\u636e&#xff09;<\/li>\n<li>\u5e7d\u9ed8\u611f\u5728\u7ebf\u4e0d&#xff1f;&#xff08;&#034;\u4ee3\u7801\u5728\u76d1\u72f1\u91cc\u8df3\u821e&#034;\u8fd9\u79cd\u5927\u767d\u8bdd&#xff09;<\/li>\n<li>\u6ce8\u91ca\u591f\u4e0d\u591f\u4fdd\u59c6\u7ea7&#xff1f;&#xff08;\u6bcf\u884c\u4ee3\u7801\u90fd\u6709\u8840\u6cea\u6ce8\u91ca&#xff0c;\u62d2\u7edd&#034;\u61c2\u7684\u90fd\u61c2&#034;&#xff09;<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>10\u6761\\&#8221;\u5b89\u5168\u4e0e\u5408\u89c4\u6027\u7ba1\u7406\\&#8221;&#xff0c;\u6bcf\u6761\u90fd\u5e26\u8840\u6cea\u6ce8\u91ca<br \/>\n\u8beb1&#xff1a;\u522b\u8ba9\u6743\u9650\u63a7\u5236\u6210\\&#8221;\u88f8\u5954\u7684\u4ee3\u7801\\&#8221;<br \/>\n\u4e3a\u4ec0\u4e48\u8fd9\u4e48\u5199&#xff1f;<br \/>\n\u6211\u66fe\u5199\u8fc7&#xff1a;<br \/>\n\/\/ \u4f2a\u4ee3\u7801&#xff1a;\u76f4\u63a5\u64cd\u4f5c\u6570\u636e\u5e93<br \/>\npublic User getUserById(String userId) {return jdbcTemplate.queryForObject(\\&#8221;SELECT * FROM users WHERE id  \\&#8221;  userId, \/\/ \u76f4\u63a5\u62fc\u63a5SQLnew Bean<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[99,190],"topic":[],"class_list":["post-60585","post","type-post","status-publish","format-standard","hentry","category-server","tag-java","tag-190"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Java\u7cfb\u7edf\u5de5\u4f5c\u6d41\u7684\u5b89\u5168\u6027\u4e0e\u5408\u89c4\u6027\u7ba1\u7406\uff1a\u5f53\u4f60\u7684\u4ee3\u7801\u5728\u201c\u76d1\u72f1\u201c\u91cc\u8df3\u821e\u65f6\uff0c\u5408\u89c4\u6027\u624d\u662f\u5b83\u7684\u9563\u94d0\uff01 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wsisp.com\/helps\/60585.html\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Java\u7cfb\u7edf\u5de5\u4f5c\u6d41\u7684\u5b89\u5168\u6027\u4e0e\u5408\u89c4\u6027\u7ba1\u7406\uff1a\u5f53\u4f60\u7684\u4ee3\u7801\u5728\u201c\u76d1\u72f1\u201c\u91cc\u8df3\u821e\u65f6\uff0c\u5408\u89c4\u6027\u624d\u662f\u5b83\u7684\u9563\u94d0\uff01 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"og:description\" content=\"10\u6761&quot;\u5b89\u5168\u4e0e\u5408\u89c4\u6027\u7ba1\u7406&quot;&#xff0c;\u6bcf\u6761\u90fd\u5e26\u8840\u6cea\u6ce8\u91ca \u8beb1&#xff1a;\u522b\u8ba9\u6743\u9650\u63a7\u5236\u6210&quot;\u88f8\u5954\u7684\u4ee3\u7801&quot; \u4e3a\u4ec0\u4e48\u8fd9\u4e48\u5199&#xff1f; \u6211\u66fe\u5199\u8fc7&#xff1a; \/\/ \u4f2a\u4ee3\u7801&#xff1a;\u76f4\u63a5\u64cd\u4f5c\u6570\u636e\u5e93 public User getUserById(String userId) {return jdbcTemplate.queryForObject(&quot;SELECT * FROM users WHERE id &quot; userId, \/\/ \u76f4\u63a5\u62fc\u63a5SQLnew Bean\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wsisp.com\/helps\/60585.html\" \/>\n<meta property=\"og:site_name\" content=\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"article:published_time\" content=\"2026-01-15T15:33:27+00:00\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/60585.html\",\"url\":\"https:\/\/www.wsisp.com\/helps\/60585.html\",\"name\":\"Java\u7cfb\u7edf\u5de5\u4f5c\u6d41\u7684\u5b89\u5168\u6027\u4e0e\u5408\u89c4\u6027\u7ba1\u7406\uff1a\u5f53\u4f60\u7684\u4ee3\u7801\u5728\u201c\u76d1\u72f1\u201c\u91cc\u8df3\u821e\u65f6\uff0c\u5408\u89c4\u6027\u624d\u662f\u5b83\u7684\u9563\u94d0\uff01 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"isPartOf\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\"},\"datePublished\":\"2026-01-15T15:33:27+00:00\",\"dateModified\":\"2026-01-15T15:33:27+00:00\",\"author\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/60585.html#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.wsisp.com\/helps\/60585.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/60585.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.wsisp.com\/helps\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Java\u7cfb\u7edf\u5de5\u4f5c\u6d41\u7684\u5b89\u5168\u6027\u4e0e\u5408\u89c4\u6027\u7ba1\u7406\uff1a\u5f53\u4f60\u7684\u4ee3\u7801\u5728\u201c\u76d1\u72f1\u201c\u91cc\u8df3\u821e\u65f6\uff0c\u5408\u89c4\u6027\u624d\u662f\u5b83\u7684\u9563\u94d0\uff01\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\",\"url\":\"https:\/\/www.wsisp.com\/helps\/\",\"name\":\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"description\":\"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"contentUrl\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/wp.wsisp.com\"],\"url\":\"https:\/\/www.wsisp.com\/helps\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Java\u7cfb\u7edf\u5de5\u4f5c\u6d41\u7684\u5b89\u5168\u6027\u4e0e\u5408\u89c4\u6027\u7ba1\u7406\uff1a\u5f53\u4f60\u7684\u4ee3\u7801\u5728\u201c\u76d1\u72f1\u201c\u91cc\u8df3\u821e\u65f6\uff0c\u5408\u89c4\u6027\u624d\u662f\u5b83\u7684\u9563\u94d0\uff01 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wsisp.com\/helps\/60585.html","og_locale":"zh_CN","og_type":"article","og_title":"Java\u7cfb\u7edf\u5de5\u4f5c\u6d41\u7684\u5b89\u5168\u6027\u4e0e\u5408\u89c4\u6027\u7ba1\u7406\uff1a\u5f53\u4f60\u7684\u4ee3\u7801\u5728\u201c\u76d1\u72f1\u201c\u91cc\u8df3\u821e\u65f6\uff0c\u5408\u89c4\u6027\u624d\u662f\u5b83\u7684\u9563\u94d0\uff01 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","og_description":"10\u6761\"\u5b89\u5168\u4e0e\u5408\u89c4\u6027\u7ba1\u7406\"&#xff0c;\u6bcf\u6761\u90fd\u5e26\u8840\u6cea\u6ce8\u91ca \u8beb1&#xff1a;\u522b\u8ba9\u6743\u9650\u63a7\u5236\u6210\"\u88f8\u5954\u7684\u4ee3\u7801\" \u4e3a\u4ec0\u4e48\u8fd9\u4e48\u5199&#xff1f; \u6211\u66fe\u5199\u8fc7&#xff1a; \/\/ \u4f2a\u4ee3\u7801&#xff1a;\u76f4\u63a5\u64cd\u4f5c\u6570\u636e\u5e93 public User getUserById(String userId) {return jdbcTemplate.queryForObject(\"SELECT * FROM users WHERE id \" userId, \/\/ \u76f4\u63a5\u62fc\u63a5SQLnew Bean","og_url":"https:\/\/www.wsisp.com\/helps\/60585.html","og_site_name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","article_published_time":"2026-01-15T15:33:27+00:00","author":"admin","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"admin","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"6 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wsisp.com\/helps\/60585.html","url":"https:\/\/www.wsisp.com\/helps\/60585.html","name":"Java\u7cfb\u7edf\u5de5\u4f5c\u6d41\u7684\u5b89\u5168\u6027\u4e0e\u5408\u89c4\u6027\u7ba1\u7406\uff1a\u5f53\u4f60\u7684\u4ee3\u7801\u5728\u201c\u76d1\u72f1\u201c\u91cc\u8df3\u821e\u65f6\uff0c\u5408\u89c4\u6027\u624d\u662f\u5b83\u7684\u9563\u94d0\uff01 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","isPartOf":{"@id":"https:\/\/www.wsisp.com\/helps\/#website"},"datePublished":"2026-01-15T15:33:27+00:00","dateModified":"2026-01-15T15:33:27+00:00","author":{"@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41"},"breadcrumb":{"@id":"https:\/\/www.wsisp.com\/helps\/60585.html#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wsisp.com\/helps\/60585.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wsisp.com\/helps\/60585.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.wsisp.com\/helps"},{"@type":"ListItem","position":2,"name":"Java\u7cfb\u7edf\u5de5\u4f5c\u6d41\u7684\u5b89\u5168\u6027\u4e0e\u5408\u89c4\u6027\u7ba1\u7406\uff1a\u5f53\u4f60\u7684\u4ee3\u7801\u5728\u201c\u76d1\u72f1\u201c\u91cc\u8df3\u821e\u65f6\uff0c\u5408\u89c4\u6027\u624d\u662f\u5b83\u7684\u9563\u94d0\uff01"}]},{"@type":"WebSite","@id":"https:\/\/www.wsisp.com\/helps\/#website","url":"https:\/\/www.wsisp.com\/helps\/","name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","description":"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41","name":"admin","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/","url":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","contentUrl":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","caption":"admin"},"sameAs":["http:\/\/wp.wsisp.com"],"url":"https:\/\/www.wsisp.com\/helps\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/60585","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/comments?post=60585"}],"version-history":[{"count":0,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/60585\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media?parent=60585"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/categories?post=60585"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/tags?post=60585"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/topic?post=60585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}