2017å¹´11æ24æ¥ã®Spring Fest 2017ã§ã®çºè¡¨ã«ä½¿ç¨ããè³æã§ãï¼ WebFlux対å¿ã®å 容ã¯å ç°ããã«ä½æé ãããã®ã§ããï¼è¨±å¯ãå¾ã¦å ¬éãã¦ããã¾ãï¼
2017å¹´11æ24æ¥ã®Spring Fest 2017ã§ã®çºè¡¨ã«ä½¿ç¨ããè³æã§ãï¼ WebFlux対å¿ã®å 容ã¯å ç°ããã«ä½æé ãããã®ã§ããï¼è¨±å¯ãå¾ã¦å ¬éãã¦ããã¾ãï¼
ããã«ã¡ã¯ãã¢ããªã±ã¼ã·ã§ã³åºç¤ãã¼ã ã®éæ¨(@a_o_k_i_n_g)ã§ãã ä»å㯠Java ã¢ããªã±ã¼ã·ã§ã³ãã»ãã¥ã¢ã«éç¨ããä»çµã¿ã§ãã Java Security Manager ã«ã¤ãã¦ç´¹ä»ãããã¨æãã¾ãããã®ä»çµã¿ã¯ Linux ã®å¼·å¶ã¢ã¯ã»ã¹å¶å¾¡æ©æ§ï¼SELinux ã AppArmor) ã® Java çã«ç¸å½ãããã®ã§ãããã°ã©ã ã®æåãå¶éãããã¨ãã§ãã¾ããå¼ç¤¾ãæä¾ããã¯ã©ã¦ããµã¼ãã¹ cybozu.com ã§ãæå¹åããã¦ãã¾ãã ã»ãã¥ã¢ãªãµã¼ãã¹ãæä¾ããä¸ã§ã¯è¯ãä»çµã¿ã ã¨æãã®ã§ãããæ¤ç´¢ããã¨ãã Java Security Manager ã«é¢ããè¨äºããã¾ãå¤ããªãã£ããããæã ãå¾ãç¥è¦ãããã«è¨ãã¾ãã Java Security Manager ã¨ã¯ Java Security Manager (ä»¥ä¸ JSM) ã¨ã¯ãJava ã³ã¼ããå®
GitHubã¢ã«ã¦ã³ãã§ãã°ã¤ã³ã§ããWebã¢ããªã±ã¼ã·ã§ã³ãä½ããããªã¼ã¨æã£ã¦ããã®ã§ãããJavaã ã¨pac4jã¨ããã©ã¤ãã©ãªã使ãã¨GitHubãå§ããTwitterãFacebookãªã©æ§ã ãªãµã¼ãã¹ã®OAuthèªè¨¼ãæ±ããã¨ãã§ããããã§ãã github.com SpringMVCãJAX-RSãªã©ã®ãã¬ã¼ã ã¯ã¼ã¯ã¨ã®é£æºæ©è½ãæä¾ããã¦ããããã§ãããä»åã¯åºæ¬çãªä½¿ãæ¹ãææ¡ããããã«pac4j-oauthã¨ããã¢ã¸ã¥ã¼ã«ã使ã£ã¦ãµã¼ãã¬ãããã¼ã¹ã§è©¦ãã¦ã¿ã¾ããã ã¾ãã¯GitHubä¸ã§ã¢ããªã±ã¼ã·ã§ã³ã®ç»é²ãè¡ãå¿ è¦ãããã¾ãã ç¶ãã¦ããã°ã©ã ã®å®è£ ã«ç§»ãã¾ããpom.xmlã«ä»¥ä¸ã®ä¾åé¢ä¿ã追å ãã¾ãã <dependency> <groupId>org.pac4j</groupId> <artifactId>pac4j-oauth</artifactId> <
buildscript { repositories { mavenCentral() maven { url "https://plugins.gradle.org/m2/" } } dependencies { classpath "org.springframework.boot:spring-boot-gradle-plugin:${SPRING_BOOT_VERSION}" classpath "org.springframework:springloaded:${SPRING_LOADED_VERSION}" } } apply plugin: 'java' apply plugin: 'spring-boot' sourceCompatibility = "${JAVA_VERSION}" targetCompatibility = "${JAVA_VERSION}" rep
# Apache Shiro Configuration ã®æ¥æ¬èªè¨³ åç´ãªã³ãã³ãã©ã¤ã³ã»ã¢ããªã±ã¼ã·ã§ã³ããã¯ã©ã¹ã¿ã¼åãããå¤§è¦æ¨¡ã¨ã³ã¿ã¼ãã©ã¤ãºã¢ããªã±ã¼ã·ã§ã³ã«è³ãã¾ã§ãããããç°å¢ã§åä½ããããã« Shiro ã¯è¨è¨ããã¦ãã¾ããç°å¢ã¯å¤å²ã«ããããããé©åã«è¨å®ããããªãããããè¨å®æ¹æ³ãæ°å¤ãåå¨ãã¾ãããã®ç¯ã§ã¯ãShiro core ã«ãããµãã¼ããããè¨å®æ¹æ³ã«ã¤ãã¦èª¬æãã¾ãã å¤ãã®è¨å®ãªãã·ã§ã³ Shiro ã® SecurityManager å®è£ 群ã¨è£å©ã³ã³ãã¼ãã³ã群ã¯ãå ¨ã¦ JavaBeans äºæã§ããããã«ãããäºå®ä¸ Shiro ã¯ãé常㮠JavaãXML (Spring, JBoss, Guice, etc), YAML, JSON, Groovy Builder ãã¼ã¯ã¢ãããçã ãè¨å®æ¸å¼ãåããã«è¨å®ãå¯è½ã¨ãªã£ã¦ãã¾ãã ããã°ã©ã ã«ãã
Apache Shiro⢠is a powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management. With Shiroâs easy-to-understand API, you can quickly and easily secure any application â from the smallest mobile applications to the largest web and enterprise applications.
èªè¨¼ã»æ¿èªãè¡ãããã°ã©ã ã¦ã¼ã¶ã¼èªè¨¼ã権éã®å¶å¾¡ãè¡ãããã«æ¨æºAPIã¨ãã¦JAAS(Java Authentication and Authorization Service) APIãããã¾ãã JAASã«ã¯ãã¦ã¼ã¶ã¼ãæ£å½ã§ãããã¨ã確èªããèªè¨¼ã¨ãã¦ã¼ã¶ã¼ã®æ¨©éã«å¿ãã¦è¦æ±ãå¶å¾¡ããæ¿èªã®2ã¤ã®è¦ç´ ãããã¾ãã èªè¨¼ èªè¨¼ã§ä½¿ç¨ãã主è¦APIã¯ä»¥ä¸ã§ãã javax.security.auth.login.LoginContext javax.security.auth.spi.LoginModule javax.security.auth.callback.CallbackHandler javax.security.atth.callback.Callback èªè¨¼ã®ããã¼ã¯å¤§ã¾ãã«ã¯ä»¥ä¸ã§ãã ã¢ããªã±ã¼ã·ã§ã³ãLoginContextã¯ã©ã¹ãã¤ã³ã¹ã¿ã³ã¹åãã Logi
ã¨ãã»ãã¥ã¢ããã° : åé²ï¼ãã¹ã¯ã¼ãã¯æ¬å½ã«SHA-1+saltã§ååã ã¨æãã¾ããï¼ ã«æã¾ãããã¹ã¯ã¼ãã®ããã·ã¥åæ¹æ³ã«ã¤ãã¦å ·ä½çã«è¼ã£ã¦ããã®ã§ãJavaã§ã©ããªæãã«ãªãã®ã確èªãã¦ã¿ãã 使ãã®ã¯ç¾å¨ä¸å¿å®å ¨ã ã¨èªãããã¦ããã£ã½ããã®ã§ãOracle JDKã«ãæ¨æºã§å«ã¾ãã¦ãã PBKDF2 *1 ã¨ããæ¹å¼ãWikipedia ã«ããã¨è²ã ãªãããã¯ãã§ã使ããã¦ããããã ã ãã¹ã package example; import java.security.NoSuchAlgorithmException; import java.security.SecureRandom; import java.security.spec.InvalidKeySpecException; import java.security.spec.KeySpec; import ja
Top 㸠AAåèæ å ± References (CERT Oracle Coding Standard for Java ã®ãã¼ã¸ã«ã¨ã³ã¾ã) ãJava ã»ãã¥ã¢ã³ã¼ãã£ã³ã° 並è¡å¦çç·¨ã Top 㸠BBGlossary Glossary (CERT Oracle Coding Standard for Java ã®ãã¼ã¸ã«ã¨ã³ã¾ã) Top 㸠XXãåãåãã æ¬ãã¼ã¸ã«é¢ããã質åã»ãåãåããã¯ãsecure-coding@jpcert.or.jp ã¾ã§ã¡ã¼ã«ã«ã¦ãé¡ããããã¾ãã Top ã¸
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã¡ã³ããã³ã¹
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}