一、使用方式
資料權限控制需要對查詢出的資料進行篩選,對業務入侵最少的方式就是利用mybatis或者資料庫連接配接池的切片對已有業務的sql進行修改。切片邏輯完成後,僅需要在業務中加入少量标記代碼,就可以實作對資料權限的控制。這種修改方式,對老業務的邏輯沒有入侵或隻有少量入侵,基本不影響老業務的邏輯和可讀性;對新業務,業務開發人員無需過多關注權限問題,可以集中精力處理業務邏輯。
由于部門代碼中使用的資料庫連接配接池種類較多,不利于切片控制邏輯的快速完成,而sql拼接的部分基本隻有mybatis和java字元串直接拼接兩種方式,是以使用mybatis切片的方式來完成資料權限控制邏輯。在mybatis的mapper檔案的接口上添加注解,注解中寫明需要控制的權限種類、要控制的表名、列名即可控制接口的資料權限。
由于mybatis的mapper檔案中的同一接口在多個地方被調用,有的需要控制資料權限,有的不需要,是以增加一種權限控制方式:通過ThreadLocal傳遞權限控制規則來控制目前sql執行時控制資料權限。
權限控制規則格式如下:
限權規則code1(表名1.字段名1,表名2.字段名2);限權規則code2(表名3.字段名3,表名4.字段名4)
例如:enterprise(channel.enterprise_code);account(table.column);channel(table3.id)
上下文傳遞工具類如下所示,使用回調的方式傳遞ThreadLocal可以防止使用者忘記清除上下文。
public class DataAuthContextUtil {
/**
* 不友善使用注解的地方,可以直接使用上下文設定資料規則
*/
private static ThreadLocal<String> useDataAuth = new ThreadLocal<>();
/**
* 有的sql隻在部分情況下需要使用資料權限限制
* 上下文和注解中均可設定資料權限規則,都設定時,上下文中的優先
*
* @param supplier
*/
public static <T> T executeSqlWithDataAuthRule(String rule, Supplier<T> supplier) {
try {
useDataAuth.set(rule);
return supplier.get();
} finally {
useDataAuth.remove();
}
}
/**
* 擷取資料權限标志
*
* @return
*/
public static String getUseDataAuthRule() {
return useDataAuth.get();
}
}
二、切片實作流程
三、其他技術細節
(1)在切面中擷取原始sql
import lombok.extern.slf4j.Slf4j;
import org.apache.commons.collections4.CollectionUtils;
import org.apache.commons.lang3.StringUtils;
import org.apache.ibatis.cache.CacheKey;
import org.apache.ibatis.executor.Executor;
import org.apache.ibatis.mapping.BoundSql;
import org.apache.ibatis.mapping.MappedStatement;
import org.apache.ibatis.mapping.SqlSource;
import org.apache.ibatis.plugin.Interceptor;
import org.apache.ibatis.plugin.Intercepts;
import org.apache.ibatis.plugin.Invocation;
import org.apache.ibatis.plugin.Signature;
import org.apache.ibatis.reflection.DefaultReflectorFactory;
import org.apache.ibatis.reflection.MetaObject;
import org.apache.ibatis.reflection.factory.DefaultObjectFactory;
import org.apache.ibatis.reflection.wrapper.DefaultObjectWrapperFactory;
import org.apache.ibatis.session.ResultHandler;
import org.apache.ibatis.session.RowBounds;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Component;
import reactor.util.function.Tuple2;
import java.lang.reflect.Method;
import java.util.HashMap;
import java.util.List;
import java.util.Map;
import java.util.Set;
@Component
@Intercepts({
// @Signature(type = Executor.class, method = "update", args = {MappedStatement.class, Object.class}),
@Signature(type = Executor.class, method = "query", args = {MappedStatement.class, Object.class, RowBounds.class, ResultHandler.class}),
@Signature(type = Executor.class, method = "query", args = {MappedStatement.class, Object.class, RowBounds.class, ResultHandler.class, CacheKey.class, BoundSql.class})
})
@Slf4j
public class DataAuthInterceptor implements Interceptor {
@Override
public Object intercept(Invocation invocation) throws Throwable {
try {
MappedStatement mappedStatement = (MappedStatement) invocation.getArgs()[0];
BoundSql boundSql = mappedStatement.getBoundSql(invocation.getArgs()[1]);
String sql = boundSql.getSql();
} catch (Exception e) {
log.error("資料權限添加出錯,目前sql未加資料權限限制!", e);
throw e;
}
return invocation.proceed();
}
}
(2)将權限項加入原始sql中
使用druid附帶的ast解析功能修改sql,代碼如下
/**
* 權限限制寫入sql
*
* @param sql
* @param tableAuthMap key:table value1:column value2:values權限項
* @return
*/
public static StringBuilder addAuthLimitToSql(String sql, Map<String, Tuple2<String, Set<String>>> tableAuthMap) {
List<SQLStatement> stmtList = SQLUtils.parseStatements(sql, "mysql");
StringBuilder authSql = new StringBuilder();
for (SQLStatement stmt : stmtList) {
stmt.accept(new MySqlASTVisitorAdapter() {
@Override
public boolean visit(MySqlSelectQueryBlock x) {
SQLTableSource from = x.getFrom();
Set<String> tableList = new HashSet<>();
getTableList(from, tableList);
for (String tableName : tableList) {
if (tableAuthMap.containsKey(tableName)) {
x.addCondition(tableName + "in (...略)");
}
}
return true;
}
});
authSql.append(stmt);
}
return authSql;
}
private static void getTableList(SQLTableSource from, Set<String> tableList) {
if (from instanceof SQLExprTableSource) {
SQLExprTableSource tableSource = (SQLExprTableSource) from;
String name = tableSource.getTableName().replace("`", "");
tableList.add(name);
String alias = tableSource.getAlias();
if (StringUtils.isNotBlank(alias)) {
tableList.add(alias.replace("`", ""));
}
} else if (from instanceof SQLJoinTableSource) {
SQLJoinTableSource joinTableSource = (SQLJoinTableSource) from;
getTableList(joinTableSource.getLeft(), tableList);
getTableList(joinTableSource.getRight(), tableList);
} else if (from instanceof SQLSubqueryTableSource) {
SQLSubqueryTableSource tableSource = (SQLSubqueryTableSource) from;
tableList.add(tableSource.getAlias().replace("`", ""));
} else if (from instanceof SQLLateralViewTableSource) {
log.warn("SQLLateralView不用處理");
} else if (from instanceof SQLUnionQueryTableSource) {
//union 不需要處理
log.warn("union不用處理");
} else if (from instanceof SQLUnnestTableSource) {
log.warn("Unnest不用處理");
} else if (from instanceof SQLValuesTableSource) {
log.warn("Values不用處理");
} else if (from instanceof SQLWithSubqueryClause) {
log.warn("子查詢不用處理");
} else if (from instanceof SQLTableSourceImpl) {
log.warn("Impl不用處理");
}
}
}
(3)将修改過後的sql寫回mybatis
MappedStatement ms = (MappedStatement) invocation.getArgs()[0];
BoundSql boundSql = ms.getBoundSql(invocation.getArgs()[1]);
// 組裝 MappedStatement
MappedStatement.Builder builder = new MappedStatement.Builder(ms.getConfiguration(), ms.getId(), new MySqlSource(boundSql), ms.getSqlCommandType());
builder.resource(ms.getResource());
builder.fetchSize(ms.getFetchSize());
builder.statementType(ms.getStatementType());
builder.keyGenerator(ms.getKeyGenerator());
if (ms.getKeyProperties() != null && ms.getKeyProperties().length != 0) {
StringBuilder keyProperties = new StringBuilder();
for (String keyProperty : ms.getKeyProperties()) {
keyProperties.append(keyProperty).append(",");
}
keyProperties.delete(keyProperties.length() - 1, keyProperties.length());
builder.keyProperty(keyProperties.toString());
}
builder.timeout(ms.getTimeout());
builder.parameterMap(ms.getParameterMap());
builder.resultMaps(ms.getResultMaps());
builder.resultSetType(ms.getResultSetType());
builder.cache(ms.getCache());
builder.flushCacheRequired(ms.isFlushCacheRequired());
builder.useCache(ms.isUseCache());
MappedStatement newMappedStatement = builder.build();
MetaObject metaObject = MetaObject.forObject(newMappedStatement, new DefaultObjectFactory(), new DefaultObjectWrapperFactory(), new DefaultReflectorFactory());
metaObject.setValue("sqlSource.boundSql.sql", newSql);
invocation.getArgs()[0] = newMappedStatement;
參考文章: https://blog.csdn.net/e_anjing/article/details/79102693