移除 Security 无用的 secret 配置项

This commit is contained in:
YunaiV 2022-03-10 00:39:43 +08:00
parent 3c3919545a
commit 9a9dbf0e97
4 changed files with 1 additions and 10 deletions

View File

@ -4,7 +4,6 @@ import lombok.Data;
import org.springframework.boot.context.properties.ConfigurationProperties; import org.springframework.boot.context.properties.ConfigurationProperties;
import org.springframework.validation.annotation.Validated; import org.springframework.validation.annotation.Validated;
import javax.validation.Valid;
import javax.validation.constraints.NotEmpty; import javax.validation.constraints.NotEmpty;
import javax.validation.constraints.NotNull; import javax.validation.constraints.NotNull;
import java.time.Duration; import java.time.Duration;
@ -24,11 +23,6 @@ public class SecurityProperties {
*/ */
@NotNull(message = "Token 过期时间不能为空") @NotNull(message = "Token 过期时间不能为空")
private Duration tokenTimeout; private Duration tokenTimeout;
/**
* Token 秘钥
*/
@NotEmpty(message = "Token 秘钥不能为空")
private String tokenSecret;
/** /**
* Session 过期时间 * Session 过期时间
* *

View File

@ -66,7 +66,7 @@ public class JWTAuthenticationTokenFilter extends OncePerRequestFilter {
* 注意在线上环境下一定要关闭该功能 * 注意在线上环境下一定要关闭该功能
* *
* @param request 请求 * @param request 请求
* @param token 模拟的 token格式为 {@link SecurityProperties#getTokenSecret()} + 用户编号 * @param token 模拟的 token格式为 {@link SecurityProperties#getMockSecret()} + 用户编号
* @return 模拟的 LoginUser * @return 模拟的 LoginUser
*/ */
private LoginUser mockLoginUser(HttpServletRequest request, String token) { private LoginUser mockLoginUser(HttpServletRequest request, String token) {

View File

@ -168,7 +168,6 @@ wx: # 参见 https://github.com/Wechat-Group/WxJava/blob/develop/spring-boot-sta
yudao: yudao:
security: security:
token-header: Authorization token-header: Authorization
token-secret: abcdefghijklmnopqrstuvwxyz
token-timeout: 1d token-timeout: 1d
session-timeout: 30m session-timeout: 30m
mock-enable: true mock-enable: true

View File

@ -180,9 +180,7 @@ yudao:
enable: false # 本地环境,暂时关闭图片验证码,方便登录等接口的测试 enable: false # 本地环境,暂时关闭图片验证码,方便登录等接口的测试
security: security:
token-header: Authorization token-header: Authorization
token-secret: abcdefghijklmnopqrstuvwxyz
token-timeout: 1d token-timeout: 1d
# session-timeout: 30m
session-timeout: 1d session-timeout: 1d
mock-enable: true mock-enable: true
mock-secret: test mock-secret: test