{"id":336714,"date":"2022-08-08T15:00:08","date_gmt":"2022-08-08T15:00:08","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=336714"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=336714","title":{"rendered":"<span>\u0421\u0435\u0440\u0432\u0435\u0440 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 \u0434\u043b\u044f \u043c\u0438\u043a\u0440\u043e\u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 \u043d\u0430 Spring Boot<\/span>"},"content":{"rendered":"<div><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/d93\/0d9\/ca2\/d930d9ca221a940f39e8081ddd93e0b2.png\" width=\"780\" height=\"439\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/d93\/0d9\/ca2\/d930d9ca221a940f39e8081ddd93e0b2.png\"\/><figcaption><\/figcaption><\/figure>\n<p>\u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c, \u043a\u0430\u043a \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0446\u0435\u043d\u0442\u0440\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 (Authorization Server) \u0438 API-\u0448\u043b\u044e\u0437\u0430 (API Gateway).<\/p>\n<h2>\u0427\u0442\u043e \u0442\u0430\u043a\u043e\u0435 JWT-\u0442\u043e\u043a\u0435\u043d \u0438 \u0437\u0430\u0447\u0435\u043c \u0435\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c?<\/h2>\n<p><em>JSON Web Token (JWT) \u2014 \u044d\u0442\u043e \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442 \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0441 \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0439 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u043e\u0439 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0435 JSON \u0432 \u0432\u0438\u0434\u0435 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u0430 \u0443\u0442\u0432\u0435\u0440\u0436\u0434\u0435\u043d\u0438\u0439 (claim)\u00a0 \u0441 \u043e\u043f\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u044c\u044e \u0438\/\u0438\u043b\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435\u043c.<\/em><\/p>\n<p>JWT-\u0442\u043e\u043a\u0435\u043d\u044b \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0442 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438 \u043c\u043e\u0433\u0443\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0432 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u0430\u0445, \u0438\u043d\u0441\u0442\u0430\u043d\u0441\u0430\u0445 \u0434\u043b\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 stateless-\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 (\u0431\u0435\u0437 \u0441\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u044f). \u041f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 JWT-\u0442\u043e\u043a\u0435\u043d\u043e\u0432 \u043d\u0435\u0442 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u0438 \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0442\u044c \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0435 \u0440\u0435\u0441\u0443\u0440\u0441\u044b \u0434\u043b\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u0438\u0445 \u0441\u0435\u0441\u0441\u0438\u0439 \u0438\u043b\u0438 \u0445\u0440\u0430\u043d\u0438\u0442\u044c \u0442\u043e\u043a\u0435\u043d\u044b\/\u0441\u0435\u0441\u0441\u0438\u0438 \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0439 \u0431\u0430\u0437\u0435 \u0434\u0430\u043d\u043d\u044b\u0445\/\u043a\u044d\u0448\u0435.<\/p>\n<h3>\u0410\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u0430 \u0440\u0435\u0448\u0435\u043d\u0438\u044f<\/h3>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/697\/82b\/dfc\/69782bdfc988da2f09c7d9550240ca68.png\" width=\"1782\" height=\"804\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/697\/82b\/dfc\/69782bdfc988da2f09c7d9550240ca68.png\"\/><figcaption><\/figcaption><\/figure>\n<p>\u041e\u0442\u043c\u0435\u0442\u0438\u043c \u043e\u0441\u043d\u043e\u0432\u043d\u044b\u0435 \u043c\u043e\u043c\u0435\u043d\u0442\u044b:<\/p>\n<ul>\n<li>\n<p>\u0414\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 JWT-\u0442\u043e\u043a\u0435\u043d\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0446\u0435\u043d\u0442\u0440\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u0441\u0435\u0440\u0432\u0435\u0440 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 (Authorization Server).<\/p>\n<\/li>\n<li>\n<p>API Gateway \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u0441\u043e\u0431\u043e\u0439 \u0435\u0434\u0438\u043d\u0443\u044e \u0442\u043e\u0447\u043a\u0443 \u0432\u0445\u043e\u0434\u0430 \u0432 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u0442 \u0437\u0430\u043f\u0440\u043e\u0441\u044b \u043a \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u043c \u043c\u0438\u043a\u0440\u043e\u0441\u0435\u0440\u0432\u0438\u0441\u0430\u043c.<\/p>\n<\/li>\n<li>\n<p>\u041a \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0430\u043c (routes) \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442\u0441\u044f Gateway-\u0444\u0438\u043b\u044c\u0442\u0440, \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u044e\u0449\u0438\u0439 JWT-\u0442\u043e\u043a\u0435\u043d\u044b \u0432 \u0437\u0430\u043f\u0440\u043e\u0441\u0430\u0445 \u043a \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u043c\u044b\u043c \u0440\u0435\u0441\u0443\u0440\u0441\u0430\u043c. \u0414\u043b\u044f \u0432\u0430\u043b\u0438\u0434\u0430\u0446\u0438\u0438 \u0442\u043e\u043a\u0435\u043d\u0430 \u0438 \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0438\u043c\u0435\u043d\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0441 \u0435\u0433\u043e \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u044f\u043c\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442\u0441\u044f \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0435 \u043a \u0441\u0435\u0440\u0432\u0435\u0440\u0443 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 (Authorization Server). \u0414\u0430\u043b\u0435\u0435 \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u043d\u0430\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043f\u0435\u0440\u0435\u0434\u0430\u0435\u0442\u0441\u044f \u0434\u0440\u0443\u0433\u0438\u043c \u0441\u0435\u0440\u0432\u0438\u0441\u0430\u043c \u0432 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u0430.<\/p>\n<\/li>\n<li>\n<p>\u0414\u043b\u044f Service Discovery (\u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u044f \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432) \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c Eureka Discovery Client.<\/p>\n<\/li>\n<\/ul>\n<h3>\u0410\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044f<\/h3>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/b90\/a3c\/304\/b90a3c3044f562550a4bbff9620d9d7b.png\" width=\"1780\" height=\"711\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/b90\/a3c\/304\/b90a3c3044f562550a4bbff9620d9d7b.png\"\/><figcaption><\/figcaption><\/figure>\n<p>\u0410\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044f \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c:<\/p>\n<ul>\n<li>\n<p>\u041f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u043b\u043e\u0433\u0438\u043d\u0438\u0442\u0441\u044f (\u0441\u043e\u0437\u0434\u0430\u0435\u0442 \u0442\u043e\u043a\u0435\u043d \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438), \u0432\u044b\u0437\u044b\u0432\u0430\u044f \u043a\u043e\u043d\u0435\u0447\u043d\u0443\u044e \u0442\u043e\u0447\u043a\u0443 <code>\/login<\/code> (POST) \u0441 \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0435\u0439 \u0438\u043c\u0435\u043d\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438 \u043f\u0430\u0440\u043e\u043b\u044f. \u0412 \u043e\u0442\u0432\u0435\u0442 \u0432 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0435 \u043e\u043d \u043f\u043e\u043b\u0443\u0447\u0430\u0435\u0442 Bearer-\u0442\u043e\u043a\u0435\u043d.<\/p>\n<\/li>\n<li>\n<p>\u0422\u043e\u043a\u0435\u043d \u043f\u0435\u0440\u0435\u0434\u0430\u0435\u0442\u0441\u044f \u0432 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0435 \u0432 \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0435 <code>Authorization<\/code><strong> <\/strong>\u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0435 <code>Bearer access_token<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u0414\u043b\u044f \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u043a \u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u044b\u043c \u0440\u0435\u0441\u0443\u0440\u0441\u0430\u043c \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u043a\u0430\u0441\u0442\u043e\u043c\u043d\u044b\u0439 <strong>Gateway Filter (AuthenticationPrefilter)<\/strong>. \u0412 \u0444\u0438\u043b\u044c\u0442\u0440\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442\u0441\u044f \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0435 \u043a \u043a\u043e\u043d\u0435\u0447\u043d\u043e\u0439 \u0442\u043e\u0447\u043a\u0435 <strong>\/api\/v1\/validateToken<\/strong> \u0441\u0435\u0440\u0432\u0438\u0441\u0430 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 (Authentication Service), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0432\u0430\u043b\u0438\u0434\u0438\u0440\u0443\u0435\u0442 \u0442\u043e\u043a\u0435\u043d \u0438, \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0443\u0441\u043f\u0435\u0448\u043d\u043e\u0439 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438, \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u0442 \u0432 \u043e\u0442\u0432\u0435\u0442 \u0438\u043c\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438 \u0435\u0433\u043e \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u044f (authorities).<\/p>\n<\/li>\n<li>\n<p>\u0415\u0441\u043b\u0438 \u0442\u043e\u043a\u0435\u043d \u0432\u0430\u043b\u0438\u0434\u043d\u044b\u0439, \u0442\u043e \u043f\u0435\u0440\u0435\u0434 \u043f\u0435\u0440\u0435\u0430\u0434\u0440\u0435\u0441\u0430\u0446\u0438\u0435\u0439 \u043d\u0430 \u0440\u0435\u0441\u0443\u0440\u0441, \u0437\u0430\u043f\u0440\u043e\u0448\u0435\u043d\u043d\u044b\u0439 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c, \u043a \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0443 \u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u0438\u043c\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438 <a href=\"https:\/\/javarevisited.blogspot.com\/2013\/07\/role-based-access-control-using-spring-security-ldap-authorities-mapping-mvc.html\"><u>\u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u044f<\/u><\/a>.<\/p>\n<\/li>\n<li>\n<p>\u0412 \u043e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0438\u043a\u0440\u043e\u0441\u0435\u0440\u0432\u0438\u0441\u0430\u0445 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, user-service) \u0444\u0438\u043b\u044c\u0442\u0440 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438, \u043d\u0430\u0441\u043b\u0435\u0434\u0443\u0435\u043c\u044b\u0439 \u043e\u0442 <code>OncePerRequestFilter<\/code>, \u0441\u043e\u0437\u0434\u0430\u0435\u0442 \u043e\u0431\u044a\u0435\u043a\u0442 <code>Authentication<\/code>, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043a\u043b\u0430\u0441\u0441 <code>UsernamePasswordAuthenticationToken<\/code> (\u0441 <em>username<\/em> \u0438 <em>SimpleGrantedAuthority<\/em> \u0438\u0437 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0430, \u0441 \u043f\u0430\u0440\u043e\u043b\u0435\u043c null).<\/p>\n<\/li>\n<li>\n<p>\u0415\u0441\u043b\u0438 \u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0435\u0441\u0442\u044c \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u044f\/\u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0440\u0435\u0441\u0443\u0440\u0441\u0443, \u0442\u043e \u0437\u0430\u043f\u0440\u043e\u0441 \u0440\u0430\u0437\u0440\u0435\u0448\u0430\u0435\u0442\u0441\u044f. \u0412 \u043f\u0440\u043e\u0442\u0438\u0432\u043d\u043e\u043c \u0441\u043b\u0443\u0447\u0430\u0435 \u043a\u043b\u0438\u0435\u043d\u0442\u0443 \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u0442\u0441\u044f \u043e\u0442\u0432\u0435\u0442 401 Unathorized \/ 403 Forbidden.<\/p>\n<\/li>\n<\/ul>\n<h2>\u041f\u0438\u0448\u0435\u043c \u0441\u0435\u0440\u0432\u0438\u0441\u044b<\/h2>\n<h3>Eureka Server<\/h3>\n<ul>\n<li>\n<p>\u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 Spring Boot, \u0447\u0435\u0440\u0435\u0437 <a href=\"https:\/\/start.spring.io\/\"><u>Spring Initializr<\/u><\/a> \u0441 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044c\u044e <code>spring-cloud-starter-netflix-eureka-server<\/code>. \u0422\u0430\u043a\u0436\u0435 \u0434\u043e\u0431\u0430\u0432\u044c\u0442\u0435 <code>spring-cloud-dependencies<\/code><strong> <\/strong>\u0432 <code>dependencyManagement<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u0434\u043b\u044f \u0437\u0430\u043f\u0443\u0441\u043a\u0430 Eureka Server \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c \u0430\u043d\u043d\u043e\u0442\u0430\u0446\u0438\u044e <a href=\"https:\/\/www.java67.com\/2018\/12\/top-5-spring-cloud-annotations-for-java.html\"><u>@EnableEurekaServer<\/u><\/a> \u043a \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u043c\u0443 \u043a\u043b\u0430\u0441\u0441\u0443 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f.<\/p>\n<\/li>\n<li>\n<p>\u0412 property-\u0444\u0430\u0439\u043b \u0434\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 Eureka Server:<\/p>\n<\/li>\n<\/ul>\n<pre><code>spring.application.name=naming-server server.port=8761  eureka.client.register-with-eureka=false eureka.client.fetch-registry=false eureka.instance.prefer-ip-address=true<\/code><\/pre>\n<ul>\n<li>\n<p>Eureka Server \u0431\u0443\u0434\u0435\u0442 \u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u043f\u043e \u0430\u0434\u0440\u0435\u0441\u0443 <a href=\"http:\/\/localhost:8761\/\"><u>http:\/\/localhost:8761\/<\/u><\/a>. \u041d\u0430 \u0433\u043b\u0430\u0432\u043d\u043e\u0439 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0435 \u043c\u043e\u0436\u043d\u043e \u0443\u0432\u0438\u0434\u0435\u0442\u044c \u0441\u043f\u0438\u0441\u043e\u043a \u0437\u0430\u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432.<\/p>\n<\/li>\n<\/ul>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/fca\/90d\/b01\/fca90db01c90040ae0a18b1edcccc0bd.png\" width=\"1400\" height=\"787\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/fca\/90d\/b01\/fca90db01c90040ae0a18b1edcccc0bd.png\"\/><figcaption><\/figcaption><\/figure>\n<h3>Authorization Service (\u0441\u0435\u0440\u0432\u0438\u0441 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438)<\/h3>\n<ul>\n<li>\n<p>\u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f Spring Boot \u0441\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c\u0438 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u043c\u0438: <code>spring-boot-starter-security<\/code><strong>, <\/strong><code>spring-boot-starter-web<\/code><strong>, <\/strong><code>spring-cloud-starter-sleuth<\/code><strong>, <\/strong><code>spring-cloud-starter-config<\/code><strong>, <\/strong><code>spring-cloud-starter-netflix-eureka-client<\/code><strong>, <\/strong><code>spring-boot-starter-data-jpa<\/code><strong>, <\/strong><code>spring-boot-starter-data-mongodb<\/code><strong>, <\/strong><code>spring-boot-starter-data-redis<\/code> \u0438<strong> <\/strong><code>lombok<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u0417\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044c <code>spring-boot-starter-security<\/code> \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u0430 \u0434\u043b\u044f \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 \u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438, <code>spring-boot-starter-data-mongodb<\/code> \u0438 <code>spring-boot-starter-data-jpa<\/code><strong> \u2014 <\/strong>\u0434\u043b\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043a \u0443\u0447\u0435\u0442\u043d\u044b\u043c \u0434\u0430\u043d\u043d\u044b\u043c \u0432 MongoDB. \u0414\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 JWT-\u0442\u043e\u043a\u0435\u043d\u043e\u0432 \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c <code>io.jsonwebtoken:jjwt<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u0414\u043b\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u0443\u0447\u0435\u0442\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u0431\u0430\u0437\u0435 \u0434\u0430\u043d\u043d\u044b\u0445 \u043d\u0430\u043f\u0438\u0448\u0435\u043c \u0441\u0432\u043e\u044e \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e <code>UserDetailsService<\/code> \u0438\u0437 <a href=\"https:\/\/medium.com\/javarevisited\/top-10-courses-to-learn-spring-security-and-oauth2-with-spring-boot-for-java-developers-8f0222d6066d\"><u>Spring Security<\/u><\/a>. \u0414\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0443\u0447\u0435\u0442\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438\u0437 <a href=\"https:\/\/medium.com\/javarevisited\/top-5-sql-and-database-courses-to-learn-online-48424533ac61\"><u>\u0431\u0430\u0437\u044b \u0434\u0430\u043d\u043d\u044b\u0445 <\/u><\/a>\u0438 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u044d\u043a\u0437\u0435\u043c\u043f\u043b\u044f\u0440\u0430 <code>UserDetails<\/code> \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043c\u0435\u0442\u043e\u0434 <code>loadUserByUsername()<\/code>.<\/p>\n<\/li>\n<\/ul>\n<pre><code>@Service public class ApplicationUserDetailsService implements UserDetailsService {      @Autowired     private UsersService usersService;       @Override     public UserDetails loadUserByUsername(String s) throws UsernameNotFoundException {         return new ApplicationUsers(usersService.getByUsrName(s).orElseThrow(() -> new UsernameNotFoundException(\"Username Not Found\")));     } }<\/code><\/pre>\n<ul>\n<li>\n<p>\u0421\u0432\u043e\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f <code>UserDetails<\/code> \u043d\u0430\u043c \u043d\u0443\u0436\u043d\u0430 \u0434\u043b\u044f \u043c\u0430\u043f\u043f\u0438\u043d\u0433\u0430 \u043e\u0431\u044a\u0435\u043a\u0442\u043e\u0432, \u0445\u0440\u0430\u043d\u044f\u0449\u0438\u0445\u0441\u044f \u0432 \u0431\u0430\u0437\u0435 \u0434\u0430\u043d\u043d\u044b\u0445, \u043d\u0430 \u043e\u0431\u044a\u0435\u043a\u0442\u044b, \u0442\u0440\u0435\u0431\u0443\u0435\u043c\u044b\u0435 Spring Security.<\/p>\n<\/li>\n<li>\n<p>\u0421\u043e\u0437\u0434\u0430\u0435\u043c \u043a\u043b\u0430\u0441\u0441 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u2014 \u043d\u0430\u0441\u043b\u0435\u0434\u043d\u0438\u043a <code>WebSecurityConfigurerAdapter<\/code>.<\/p>\n<\/li>\n<\/ul>\n<pre><code class=\"java\">package com.infotrends.in.authenticationserver.security.config;  import com.infotrends.in.authenticationserver.security.filters.JWTAuthenticationFilter; import com.infotrends.in.authenticationserver.security.filters.JWTVerifierFilter; import com.infotrends.in.authenticationserver.security.services.ApplicationUserDetailsService; import com.infotrends.in.authenticationserver.services.redis.TokensRedisService; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.authentication.dao.DaoAuthenticationProvider; import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; import org.springframework.security.config.http.SessionCreationPolicy; import org.springframework.security.crypto.password.PasswordEncoder;  @Configuration @EnableWebSecurity public class WebSecurityConfig extends WebSecurityConfigurerAdapter {       @Autowired     private PasswordEncoder encoder;      @Autowired     private ApplicationUserDetailsService applicationUserDetailsService;      @Autowired     private TokensRedisService redisService;      @Override     protected void configure(HttpSecurity http) throws Exception {         http.csrf().disable()                 .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS)                 .and()                 .addFilter(new JWTAuthenticationFilter(authenticationManager(), redisService))                 .addFilterAfter(new JWTVerifierFilter(redisService), JWTAuthenticationFilter.class)                 .authorizeRequests()                 .antMatchers(\"\/api\/v1\/validateConnection\/whitelisted\").permitAll()                 .anyRequest()                 .authenticated()                 .and().httpBasic();     }      @Override     protected void configure(AuthenticationManagerBuilder auth) throws Exception {         auth.authenticationProvider(authenticationProvider());     }      @Bean     public DaoAuthenticationProvider authenticationProvider() {         DaoAuthenticationProvider authenticationProvider = new DaoAuthenticationProvider();         authenticationProvider.setPasswordEncoder(encoder);         authenticationProvider.setUserDetailsService(applicationUserDetailsService);          return authenticationProvider;     } }<\/code><\/pre>\n<ul>\n<li>\n<p>\u0417\u0434\u0435\u0441\u044c \u043c\u044b \u0441\u043e\u0437\u0434\u0430\u0435\u043c \u0431\u0438\u043d <code>DaoAuthenticationProvider<\/code> \u0441 \u043a\u043e\u0434\u0438\u0440\u043e\u0432\u0449\u0438\u043a\u043e\u043c \u043f\u0430\u0440\u043e\u043b\u0435\u0439 \u0438 \u043d\u0430\u0448\u0435\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0435\u0439 <code>UserDetailsService<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u041a\u043e\u0442\u043e\u0440\u044b\u0435, \u0432 \u0441\u0432\u043e\u044e \u043e\u0447\u0435\u0440\u0435\u0434\u044c, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0442\u0441\u044f \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f <code>configure(AuthenticationManagerBuilder auth)<\/code>, \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e <code>AuthenticationManagerBuilder<\/code> \u0434\u043b\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u043d\u043e\u0433\u043e \u043d\u0430\u043c\u0438 Authentication Provider.<\/p>\n<\/li>\n<li>\n<p>\u0414\u0430\u043b\u0435\u0435 \u0434\u043b\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f JWT\/Bearer-\u0442\u043e\u043a\u0435\u043d\u043e\u0432 \u0432\u043c\u0435\u0441\u0442\u043e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u043f\u043e \u043b\u043e\u0433\u0438\u043d\u0443 \u0438 \u043f\u0430\u0440\u043e\u043b\u044e, \u043d\u0430\u0434\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0434\u0432\u0430 \u0444\u0438\u043b\u044c\u0442\u0440\u0430: \u043e\u0434\u0438\u043d \u0434\u043b\u044f \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 Bearer-\u0442\u043e\u043a\u0435\u043d\u0430, \u0430 \u0434\u0440\u0443\u0433\u043e\u0439 \u2014 \u0434\u043b\u044f \u0435\u0433\u043e \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438.<\/p>\n<\/li>\n<li>\n<p>\u0424\u0438\u043b\u044c\u0442\u0440 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 JWT \u0441\u043e\u0437\u0434\u0430\u0435\u043c \u043a\u0430\u043a \u043f\u043e\u0434\u043a\u043b\u0430\u0441\u0441 <code>UsernamePasswordAuthenticationFilter<\/code>. <strong>\u00a0<\/strong>\u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0443\u0447\u0435\u0442\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u043f\u0435\u0440\u0435\u043e\u043f\u0440\u0435\u0434\u0435\u043b\u044f\u0435\u043c \u043c\u0435\u0442\u043e\u0434 <code>attemptAuthentication()<\/code>. \u0414\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f JWT-\u0442\u043e\u043a\u0435\u043d\u0430 \u043f\u0440\u0438 \u0443\u0441\u043f\u0435\u0448\u043d\u043e\u0439 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u2014 \u043c\u0435\u0442\u043e\u0434 \u0438 <code>successAuthentication<\/code><strong>()<\/strong>.<\/p>\n<\/li>\n<\/ul>\n<pre><code class=\"java\">package com.infotrends.in.authenticationserver.security.filters;  import com.fasterxml.jackson.databind.ObjectMapper; import com.infotrends.in.InfoTrendsIn.security.SecurityConstants; import com.infotrends.in.authenticationserver.model.ConnValidationResponse; import com.infotrends.in.authenticationserver.model.JwtAuthenticationModel; import com.infotrends.in.authenticationserver.model.redis.TokensEntity; import com.infotrends.in.authenticationserver.services.redis.TokensRedisService; import com.infotrends.in.authenticationserver.utils.Utilities; import io.jsonwebtoken.Jwts; import io.jsonwebtoken.SignatureAlgorithm; import lombok.RequiredArgsConstructor; import lombok.extern.slf4j.Slf4j; import org.springframework.http.HttpHeaders; import org.springframework.http.MediaType; import org.springframework.security.authentication.AuthenticationManager; import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; import org.springframework.security.core.Authentication; import org.springframework.security.core.AuthenticationException; import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter;  import javax.servlet.FilterChain; import javax.servlet.ServletException; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletResponse; import java.io.IOException; import java.time.LocalDateTime; import java.time.ZoneOffset; import java.util.Date;  @Slf4j @RequiredArgsConstructor public class JWTAuthenticationFilter extends UsernamePasswordAuthenticationFilter {      private final AuthenticationManager authenticationManager;     private ObjectMapper mapper=new ObjectMapper();      private final TokensRedisService tokensRedisService;      @Override     public Authentication attemptAuthentication(HttpServletRequest request, HttpServletResponse response) throws AuthenticationException {         try {             JwtAuthenticationModel authModel = mapper.readValue(request.getInputStream(), JwtAuthenticationModel.class);             Authentication authentication = new UsernamePasswordAuthenticationToken(authModel.getUsername(), authModel.getPassword());             return authenticationManager.authenticate(authentication);          } catch (IOException e) {             throw new RuntimeException(e);         }     }      @Override     protected void successfulAuthentication(HttpServletRequest request, HttpServletResponse response, FilterChain chain, Authentication authResult) throws IOException, ServletException {         String token = Jwts.builder()                 .setSubject(authResult.getName())                 .claim(\"authorities\", authResult.getAuthorities())                 .claim(\"principal\", authResult.getPrincipal())                 .setIssuedAt(new Date())                 .setIssuer(SecurityConstants.ISSUER)                 .setExpiration(Date.from(LocalDateTime.now().plusMinutes(30).toInstant(ZoneOffset.UTC)))                 .signWith(SignatureAlgorithm.HS256, SecurityConstants.KEY)                 .compact();          log.info(token);         TokensEntity tokensEntity = TokensEntity.builder().id(Utilities.generateUuid()).authenticationToken(token)                         .username(authResult.getName())                         .createdBy(\"SYSTEM\").createdOn(LocalDateTime.now())                         .modifiedBy(\"SYSTEM\").modifiedOn(LocalDateTime.now())                         .build();         tokensEntity = tokensRedisService.save(tokensEntity);         response.addHeader(SecurityConstants.HEADER, String.format(\"Bearer %s\", tokensEntity.getId())); \/\/        response.addHeader(\"Expiration\", String.valueOf(30*60));          ConnValidationResponse respModel = ConnValidationResponse.builder().isAuthenticated(true).build();         response.addHeader(HttpHeaders.CONTENT_TYPE, MediaType.APPLICATION_JSON_VALUE);         response.getOutputStream().write(mapper.writeValueAsBytes(respModel));     } }<\/code><\/pre>\n<ul>\n<li>\n<p>\u0424\u0438\u043b\u044c\u0442\u0440 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 JWT \u043d\u0430\u0441\u043b\u0435\u0434\u0443\u0435\u043c \u043e\u0442 <code>OncePerRequestFilter<\/code><strong> <\/strong>\u0438 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c \u0435\u0433\u043e \u0432\u044b\u0437\u043e\u0432 \u043f\u043e\u0441\u043b\u0435 \u0444\u0438\u043b\u044c\u0442\u0440\u0430, \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u044e\u0449\u0435\u0433\u043e JWT, \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e <code>addFilterAfter()<\/code> \u0432 \u043a\u043b\u0430\u0441\u0441\u0435 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 <code>WebSecurityConfig<\/code>.<\/p>\n<\/li>\n<\/ul>\n<pre><code class=\"java\">package com.infotrends.in.authenticationserver.security.filters;  import com.infotrends.in.InfoTrendsIn.security.SecurityConstants; import com.infotrends.in.authenticationserver.model.redis.TokensEntity; import com.infotrends.in.authenticationserver.services.redis.TokensRedisService; import com.infotrends.in.authenticationserver.utils.Utilities; import io.jsonwebtoken.Claims; import io.jsonwebtoken.Jws; import io.jsonwebtoken.Jwts; import lombok.RequiredArgsConstructor; import org.apache.tomcat.util.http.parser.Authorization; import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; import org.springframework.security.core.Authentication; import org.springframework.security.core.GrantedAuthority; import org.springframework.security.core.authority.SimpleGrantedAuthority; import org.springframework.security.core.context.SecurityContext; import org.springframework.security.core.context.SecurityContextHolder; import org.springframework.web.filter.OncePerRequestFilter;  import javax.servlet.FilterChain; import javax.servlet.ServletException; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletResponse; import java.io.IOException; import java.util.List; import java.util.Map; import java.util.Optional; import java.util.Set; import java.util.stream.Collectors;  @RequiredArgsConstructor public class JWTVerifierFilter extends OncePerRequestFilter {      private final TokensRedisService tokensRedisService;      @Override     protected void doFilterInternal(HttpServletRequest httpServletRequest, HttpServletResponse httpServletResponse, FilterChain filterChain) throws ServletException, IOException {         String bearerToken = httpServletRequest.getHeader(SecurityConstants.HEADER);         if(!(Utilities.validString(bearerToken) &amp;&amp; bearerToken.startsWith(SecurityConstants.PREFIX))) {             filterChain.doFilter(httpServletRequest, httpServletResponse);             return;         }          String authToken = bearerToken.replace(SecurityConstants.PREFIX, \"\");          Optional&lt;TokensEntity> tokensEntity = tokensRedisService.findById(authToken);          if(!tokensEntity.isPresent()) {             filterChain.doFilter(httpServletRequest, httpServletResponse);             return;         }          String token = tokensEntity.get().getAuthenticationToken();         Jws&lt;Claims> authClaim = Jwts.parser().setSigningKey(SecurityConstants.KEY)                 .requireIssuer(SecurityConstants.ISSUER)                 .parseClaimsJws(token);          String username = authClaim.getBody().getSubject();          List&lt;Map&lt;String, String>> authorities = (List&lt;Map&lt;String, String>>) authClaim.getBody().get(\"authorities\");         List&lt;GrantedAuthority> grantedAuthorities = authorities.stream().map(map -> new SimpleGrantedAuthority(map.get(\"authority\")))                 .collect(Collectors.toList());         Authentication authentication = new UsernamePasswordAuthenticationToken(username, null, grantedAuthorities);         SecurityContextHolder.getContext().setAuthentication(authentication);          httpServletRequest.setAttribute(\"username\", username);         httpServletRequest.setAttribute(\"authorities\", grantedAuthorities);          filterChain.doFilter(httpServletRequest, httpServletResponse);      } }<\/code><\/pre>\n<pre><code class=\"java\">package com.infotrends.in.authenticationserver.resources;  import com.sun.security.auth.UserPrincipal; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.http.HttpMethod; import org.springframework.http.MediaType; import org.springframework.http.ResponseEntity; import org.springframework.security.core.GrantedAuthority; import org.springframework.web.bind.annotation.GetMapping; import org.springframework.web.bind.annotation.PostMapping; import org.springframework.web.bind.annotation.RequestMapping; import org.springframework.web.bind.annotation.RestController;  import javax.servlet.http.HttpServletRequest; import java.util.List;  @RestController @RequestMapping(\"\/api\/v1\/validateToken\") public class ConnectionValidatorResource {      @GetMapping(value = \"\", produces = {MediaType.APPLICATION_JSON_VALUE})     public ResponseEntity&lt;ConnValidationResponse> validateGet(HttpServletRequest request) {         String username = (String) request.getAttribute(\"username\");         List&lt;GrantedAuthority> grantedAuthorities = (List&lt;GrantedAuthority>) request.getAttribute(\"authorities\");         return ResponseEntity.ok(ConnValidationResponse.builder().status(\"OK\").methodType(HttpMethod.GET.name())                         .username(username).authorities(grantedAuthorities)                 .isAuthenticated(true).build());     }          @Getter     @Builder     @ToString     public class ConnValidationResponse {         private String status;         private boolean isAuthenticated;         private String methodType;         private String username;         private List&lt;GrantedAuthority> authorities;     }      }<\/code><\/pre>\n<h3>\u0414\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u0430\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c<\/h3>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/bf1\/f75\/256\/bf1f75256bd4f899817474eaa19a424c.png\" width=\"1760\" height=\"788\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/bf1\/f75\/256\/bf1f75256bd4f899817474eaa19a424c.png\"\/><figcaption><\/figcaption><\/figure>\n<p>\u041a\u0430\u043a \u043f\u0440\u0430\u0432\u0438\u043b\u043e, \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 JWT-\u0442\u043e\u043a\u0435\u043d\u0430 \u043d\u0435\u043b\u044c\u0437\u044f \u0438\u0437\u043c\u0435\u043d\u0438\u0442\u044c \u043f\u043e\u0441\u043b\u0435 \u0435\u0433\u043e \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f. \u041e\u0434\u043d\u0430\u043a\u043e \u0442\u043e\u043a\u0435\u043d \u043c\u043e\u0436\u043d\u043e \u043b\u0435\u0433\u043a\u043e \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u0442\u044c \u0438 \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c.<\/p>\n<p>\u041d\u043e \u043c\u044b \u043c\u043e\u0436\u0435\u043c \u0432\u043c\u0435\u0441\u0442\u043e \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e JWT-\u0442\u043e\u043a\u0435\u043d\u0430, \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u0433\u043e \u0432\u0441\u0435 \u0434\u0430\u043d\u043d\u044b\u0435, \u0432\u0435\u0440\u043d\u0443\u0442\u044c \u0442\u043e\u043b\u044c\u043a\u043e <a href=\"https:\/\/javarevisited.blogspot.com\/2021\/05\/3-examples-to-generate-random-alphanumeric-string-in-java0.html\"><u>\u0441\u043b\u0443\u0447\u0430\u0439\u043d\u044b\u0439 UUID<\/u><\/a>, \u0441\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u0434\u043b\u044f \u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438, \u0430 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u0441\u043e\u0445\u0440\u0430\u043d\u0438\u0442\u044c \u0432 \u043a\u044d\u0448\u0435 Redis.<\/p>\n<p>\u0422\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c, \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u043c\u0443 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044e \u0431\u0443\u0434\u0435\u0442 \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0435\u043d \u0442\u043e\u043b\u044c\u043a\u043e \u0441\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 UUID, \u0430 JWT-\u0442\u043e\u043a\u0435\u043d \u0431\u0443\u0434\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u0440\u0443\u0433\u0438\u043c\u0438 \u0441\u0435\u0440\u0432\u0438\u0441\u0430\u043c\u0438 \u0434\u043b\u044f \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438\/\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438.<\/p>\n<pre><code class=\"java\">package com.infotrends.in.authenticationserver.model.redis;  import lombok.*; import org.springframework.beans.factory.annotation.Value; import org.springframework.data.redis.core.RedisHash;  import java.time.LocalDateTime;  @RedisHash(value = \"Tokens\", timeToLive = 86400) @Getter @Setter @Builder @NoArgsConstructor @AllArgsConstructor public class TokensEntity {       private String id;      private String username;     private String authenticationToken;     private String modifiedBy;     private LocalDateTime modifiedOn;     private String createdBy;     private LocalDateTime createdOn; }<\/code><\/pre>\n<h3>API Gateway<\/h3>\n<ul>\n<li>\n<p>\u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 Spring Boot \u0441\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c\u0438 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u043c\u0438, \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b\u043c\u0438 \u0434\u043b\u044f API Gateway \u0441 Eureka Client: <code>spring-cloud-starter-gateway<\/code>, <code>spring-cloud-starter-config<\/code> \u0438 <code>spring-cloud-starter-netflix-eureka-client<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u0424\u0430\u0439\u043b \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043a Cloud Config Server \u0438 Eureka Server:<\/p>\n<\/li>\n<\/ul>\n<pre><code>debug: true logging:   level:     org.springframework.cloud.gateway: DEBUG     reactor.netty.http.client: DEBUG server:   port: '8765' spring:   cloud:     config:       profile: dev     gateway:       discovery.locator.enabled: true   config:     import: optional:configserver:http:\/\/clouduser:configserver705!@localhost:8888   application:     name: api-gateway   jackson:     date-format: yyyy-MM-dd HH:mm:ss management:   endpoints:     web:       exposure:         include: '*' eureka:   client:     serviceUrl:       defaultZone: http:\/\/eurekauser:eureka124!@localhost:8761\/eureka   instance:     prefer-ip-address: 'true'<\/code><\/pre>\n<ul>\n<li>\n<p>\u0414\u0430\u043b\u0435\u0435 \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u043c \u043a \u043a\u043b\u0430\u0441\u0441\u0443 <code>ApiGatewayApplication<\/code> \u0430\u043d\u043d\u043e\u0442\u0430\u0446\u0438\u044e <code>@EnableFeignClients<\/code> \u0434\u043b\u044f \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0438\u044f \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u043a Eureka Server.<\/p>\n<\/li>\n<li>\n<p>\u0418 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c Gateway Filter, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u0442 Bearer-\u0442\u043e\u043a\u0435\u043d \u0432 \u0437\u0430\u043f\u0440\u043e\u0441\u0430\u0445, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043a\u043e\u043d\u0435\u0447\u043d\u0443\u044e \u0442\u043e\u0447\u043a\u0443 <code>\/validateToken<\/code> \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438. \u0414\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u043d\u0430\u0441\u043b\u0435\u0434\u0443\u0435\u043c\u0441\u044f \u043e\u0442 \u043a\u043b\u0430\u0441\u0441\u0430 <code>AbstractGatewayFilterFactory<\/code>, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0433\u043e Spring-API Gateway, \u0438 \u043f\u0435\u0440\u0435\u043e\u043f\u0440\u0435\u0434\u0435\u043b\u044f\u0435\u043c \u043c\u0435\u0442\u043e\u0434 <code>apply(Config config)<\/code>, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u0442 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e <code>GatewayFilter<\/code>.<\/p>\n<\/li>\n<\/ul>\n<pre><code class=\"java\">package com.infotrends.in.InfoTrendsIn.ApiGateway.filters;  import com.fasterxml.jackson.core.JsonProcessingException; import com.fasterxml.jackson.core.type.TypeReference; import com.fasterxml.jackson.databind.ObjectMapper; import com.infotrends.in.InfoTrendsIn.ApiGateway.model.Authorities; import com.infotrends.in.InfoTrendsIn.ApiGateway.model.ConnValidationResponse; import com.infotrends.in.InfoTrendsIn.ApiGateway.utils.Utilities; import com.infotrends.in.InfoTrendsIn.exceptions.model.ExceptionResponseModel; import com.infotrends.in.InfoTrendsIn.security.SecurityConstants; import lombok.AllArgsConstructor; import lombok.NoArgsConstructor; import lombok.RequiredArgsConstructor; import lombok.extern.slf4j.Slf4j; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.beans.factory.annotation.Qualifier; import org.springframework.cloud.context.config.annotation.RefreshScope; import org.springframework.cloud.gateway.filter.GatewayFilter; import org.springframework.cloud.gateway.filter.GatewayFilterChain; import org.springframework.cloud.gateway.filter.GlobalFilter; import org.springframework.cloud.gateway.filter.factory.AbstractGatewayFilterFactory; import org.springframework.core.io.buffer.DataBufferFactory; import org.springframework.http.HttpHeaders; import org.springframework.http.HttpStatus; import org.springframework.http.ResponseEntity; import org.springframework.http.server.reactive.ServerHttpRequest; import org.springframework.http.server.reactive.ServerHttpResponse; import org.springframework.stereotype.Component; import org.springframework.web.reactive.function.client.WebClient; import org.springframework.web.reactive.function.client.WebClientResponseException; import org.springframework.web.server.ServerWebExchange; import reactor.core.publisher.Mono;  import java.util.Date; import java.util.List; import java.util.function.Predicate;  @Component @Slf4j public class AuthenticationPrefilter extends AbstractGatewayFilterFactory&lt;AuthenticationPrefilter.Config> {      @Autowired     @Qualifier(\"excludedUrls\")     List&lt;String> excludedUrls;     private final WebClient.Builder webClientBuilder;      public AuthenticationPrefilter(WebClient.Builder webClientBuilder) {         super(Config.class);         this.webClientBuilder=webClientBuilder;     }      @Autowired     private ObjectMapper objectMapper;      @Override     public GatewayFilter apply(Config config) {         return (exchange, chain) -> {             ServerHttpRequest request = exchange.getRequest();             log.info(\"**************************************************************************\");             log.info(\"URL is - \" + request.getURI().getPath());             String bearerToken = request.getHeaders().getFirst(SecurityConstants.HEADER);             log.info(\"Bearer Token: \"+ bearerToken);              if(isSecured.test(request)) {                 return webClientBuilder.build().get()                         .uri(\"lb:\/\/authentication-service\/api\/v1\/validateToken\")                         .header(SecurityConstants.HEADER, bearerToken)                         .retrieve().bodyToMono(ConnValidationResponse.class)                         .map(response -> {                             exchange.getRequest().mutate().header(\"username\", response.getUsername());                             exchange.getRequest().mutate().header(\"authorities\", response.getAuthorities().stream().map(Authorities::getAuthority).reduce(\"\", (a, b) -> a + \",\" + b));                              return exchange;                         }).flatMap(chain::filter).onErrorResume(error -> {                             log.info(\"Error Happened\");                             HttpStatus errorCode = null;                             String errorMsg = \"\";                             if (error instanceof WebClientResponseException) {                                 WebClientResponseException webCLientException = (WebClientResponseException) error;                                 errorCode = webCLientException.getStatusCode();                                 errorMsg = webCLientException.getStatusText();                              } else {                                 errorCode = HttpStatus.BAD_GATEWAY;                                 errorMsg = HttpStatus.BAD_GATEWAY.getReasonPhrase();                             } \/\/                            AuthorizationFilter.AUTH_FAILED_CODE                             return onError(exchange, String.valueOf(errorCode.value()) ,errorMsg, \"JWT Authentication Failed\", errorCode);                         });             }              return chain.filter(exchange);         };     }      public Predicate&lt;ServerHttpRequest> isSecured = request -> excludedUrls.stream().noneMatch(uri -> request.getURI().getPath().contains(uri));     private Mono&lt;Void> onError(ServerWebExchange exchange, String errCode, String err, String errDetails, HttpStatus httpStatus) {         DataBufferFactory dataBufferFactory = exchange.getResponse().bufferFactory(); \/\/        ObjectMapper objMapper = new ObjectMapper();         ServerHttpResponse response = exchange.getResponse();         response.setStatusCode(httpStatus);         try {             response.getHeaders().add(\"Content-Type\", \"application\/json\");             ExceptionResponseModel data = new ExceptionResponseModel(errCode, err, errDetails, null, new Date());             byte[] byteData = objectMapper.writeValueAsBytes(data);             return response.writeWith(Mono.just(byteData).map(t -> dataBufferFactory.wrap(t)));          } catch (JsonProcessingException e) {             e.printStackTrace();          }         return response.setComplete();     }      @NoArgsConstructor     public static class Config {       } }<\/code><\/pre>\n<h3>\u041c\u0430\u0440\u0448\u0440\u0443\u0442\u044b<\/h3>\n<p>\u0412 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0439 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u044b (routes) \u043d\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 \u0441\u043e\u0437\u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u0448\u0435 <code>GatewayFilter<\/code>.<\/p>\n<pre><code class=\"java\">package com.infotrends.in.InfoTrendsIn.ApiGateway.config;  import com.fasterxml.jackson.core.JsonFactory; import com.fasterxml.jackson.core.JsonGenerator; import com.fasterxml.jackson.databind.DeserializationFeature; import com.fasterxml.jackson.databind.ObjectMapper; import com.fasterxml.jackson.datatype.jsr310.ser.LocalDateSerializer; import com.fasterxml.jackson.datatype.jsr310.ser.LocalDateTimeSerializer; import com.infotrends.in.InfoTrendsIn.ApiGateway.filters.AuthenticationPrefilter; import org.springframework.beans.factory.annotation.Qualifier; import org.springframework.beans.factory.annotation.Value; import org.springframework.boot.autoconfigure.jackson.Jackson2ObjectMapperBuilderCustomizer; import org.springframework.cloud.gateway.route.RouteLocator; import org.springframework.cloud.gateway.route.builder.RouteLocatorBuilder; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration;  import java.text.SimpleDateFormat; import java.time.format.DateTimeFormatter; import java.util.Arrays; import java.util.List; import java.util.stream.Collectors;  @Configuration public class RouteConfiguration {      @Bean     public RouteLocator routes(             RouteLocatorBuilder builder,             AuthenticationPrefilter authFilter) {         return builder.routes()                 .route(\"auth-service-route\", r -> r.path(\"\/authentication-service\/**\")                         .filters(f ->                                 f.rewritePath(\"\/authentication-service(?&lt;segment>\/?.*)\", \"$\\\\{segment}\")                                         .filter(authFilter.apply(                                                 new AuthenticationPrefilter.Config())))                         .uri(\"lb:\/\/authentication-service\"))                 .route(\"user-service-route\", r -> r.path(\"\/user-service\/**\")                         .filters(f ->                                 f.rewritePath(\"\/user-service(?&lt;segment>\/?.*)\", \"$\\\\{segment}\")                                         .filter(authFilter.apply(                                                 new AuthenticationPrefilter.Config())))                         .uri(\"lb:\/\/user-service\"))                 .build();     }  }<\/code><\/pre>\n<h3>User-Service<\/h3>\n<ul>\n<li>\n<p>\u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u043f\u0440\u043e\u0435\u043a\u0442 User-Service \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e Spring Initializr. \u0412 \u044d\u0442\u043e\u043c \u0441\u0435\u0440\u0432\u0438\u0441\u0435 \u0431\u0443\u0434\u0443\u0442 \u0445\u0440\u0430\u043d\u0438\u0442\u044c\u0441\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438. \u042d\u0442\u043e \u0431\u0443\u0434\u0435\u0442 \u043f\u0440\u0438\u043c\u0435\u0440 \u0431\u044d\u043a\u0435\u043d\u0434\u0430.<\/p>\n<\/li>\n<li>\n<p>\u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u043a\u043b\u0430\u0441\u0441 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438, \u043d\u0430\u0441\u043b\u0435\u0434\u0443\u044f \u043a\u043b\u0430\u0441\u0441 <code>WebSecurityConfigurerAdapter<\/code>, \u0438 \u043f\u0435\u0440\u0435\u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u0435 \u043c\u0435\u0442\u043e\u0434 <code>void configure(HttpSecurity http)<\/code>. \u0417\u0434\u0435\u0441\u044c \u043c\u044b \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u043c \u0437\u0430\u043f\u0443\u0441\u043a \u043d\u0430\u0448\u0435\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0442\u043e\u043a\u0435\u043d\u0430 (JWTVerifierFilter) \u043f\u0435\u0440\u0435\u0434 <code>UsernamePasswordAuthenticationFilter<\/code>.<\/p>\n<\/li>\n<\/ul>\n<pre><code class=\"java\">@Configuration @EnableWebSecurity @EnableGlobalMethodSecurity(prePostEnabled = true) public class SecurityConfig extends WebSecurityConfigurerAdapter{      @Autowired     private PasswordEncoder encoder;      @Value(\"${security.users.username}\")     private String username;      @Value(\"${security.users.password}\")     private String password;      @Autowired     private AppUserDetailsService appUserDetailsService;       @Override     protected void configure(HttpSecurity http)       throws Exception {         http.csrf().disable()                 .headers().frameOptions().disable()                 .and()                 .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS)                 .and()                 .addFilterBefore(new JWTVerifierFilter(), UsernamePasswordAuthenticationFilter.class)                 .authorizeRequests()                 .antMatchers(HttpMethod.GET, \"\/api\/v1\/users\").permitAll()                 .anyRequest()                 .authenticated()                 .and().httpBasic();              } }<\/code><\/pre>\n<ul>\n<li>\n<p><code>JWTVerifierFilter<\/code> \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u0442 \u043d\u0430\u043b\u0438\u0447\u0438\u0435 \u0432 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u0434\u0430\u043d\u043d\u044b\u0445 \u043e\u0431 \u0438\u043c\u0435\u043d\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438 \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u044f\u0445, \u0438 \u0441\u043e\u0437\u0434\u0430\u0435\u0442 \u043e\u0431\u044a\u0435\u043a\u0442 Authentication, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043a\u043b\u0430\u0441\u0441 <code>UsernamePasswordAuthenticationToken<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u0414\u0430\u043b\u0435\u0435, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f <code>SecurityContextHolder<\/code><strong>,<\/strong> \u0441\u043e\u0445\u0440\u0430\u043d\u044f\u0435\u0442 authentication \u0432 <a href=\"https:\/\/javarevisited.blogspot.com\/2018\/02\/what-is-securitycontext-and-SecurityContextHolder-Spring-security.html\"><u>\u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Spring Security<\/u><\/a>.<\/p>\n<\/li>\n<\/ul>\n<pre><code class=\"java\">package com.infotrends.in.InfoTrendsIn.config.security.filters;  import com.infotrends.in.InfoTrendsIn.security.SecurityConstants; import com.infotrends.in.InfoTrendsIn.utils.Utilities; import io.jsonwebtoken.Claims; import io.jsonwebtoken.Jws; import io.jsonwebtoken.Jwts; import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; import org.springframework.security.core.Authentication; import org.springframework.security.core.authority.SimpleGrantedAuthority; import org.springframework.security.core.context.SecurityContextHolder; import org.springframework.util.StringUtils; import org.springframework.web.filter.OncePerRequestFilter;  import javax.servlet.FilterChain; import javax.servlet.ServletException; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletResponse; import java.io.IOException; import java.util.*; import java.util.stream.Collectors;  public class JWTVerifierFilter extends OncePerRequestFilter {       @Override     protected void doFilterInternal(HttpServletRequest httpServletRequest, HttpServletResponse httpServletResponse, FilterChain filterChain) throws ServletException, IOException {         String authHeader = httpServletRequest.getHeader(\"Authorization\");         if(!Utilities.validString(authHeader) || !authHeader.startsWith(\"Bearer \")) {             filterChain.doFilter(httpServletRequest, httpServletResponse);             return;         }          logHeaders(httpServletRequest);         String username=httpServletRequest.getHeader(\"username\");         List&lt;Map&lt;String, String>> authorities = new ArrayList&lt;>();         String authoritiesStr = httpServletRequest.getHeader(\"authorities\");         Set&lt;SimpleGrantedAuthority> simpleGrantedAuthorities = new HashSet&lt;>();         if(Utilities.validString(authoritiesStr)) {             simpleGrantedAuthorities=Arrays.stream(authoritiesStr.split(\",\")).distinct()                     .filter(Utilities::validString).map(SimpleGrantedAuthority::new).collect(Collectors.toSet());;         }         Authentication authentication = new UsernamePasswordAuthenticationToken(username, null, simpleGrantedAuthorities);         SecurityContextHolder.getContext().setAuthentication(authentication);          filterChain.doFilter(httpServletRequest, httpServletResponse);      }      private void logHeaders(HttpServletRequest httpServletRequest) {         Enumeration&lt;String> headerNames = httpServletRequest.getHeaderNames();         while(headerNames.hasMoreElements()) {             String header=headerNames.nextElement();             logger.info(String.format(\"Header: %s --- Value: %s\", header, httpServletRequest.getHeader(header)));          }     } }<\/code><\/pre>\n<p>\u0422\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c, \u0437\u0430\u043f\u0440\u043e\u0441 \u043a \u0440\u0435\u0441\u0443\u0440\u0441\u0443 \/ \u043a\u043e\u043d\u0435\u0447\u043d\u043e\u0439 \u0442\u043e\u0447\u043a\u0435 \u0440\u0430\u0437\u0440\u0435\u0448\u0430\u0435\u0442\u0441\u044f, \u0435\u0441\u043b\u0438 \u0437\u0430\u043f\u0440\u0430\u0448\u0438\u0432\u0430\u044e\u0449\u0438\u0439 \u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0438\u043c\u0435\u0435\u0442 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0439 \u0434\u043e\u0441\u0442\u0443\u043f\/\u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u044f (authority). \u041d\u0438\u0436\u0435 \u043f\u0440\u0438\u0432\u0435\u0434\u0435\u043d \u043f\u0440\u0438\u043c\u0435\u0440 \u0434\u043b\u044f <strong>GET<\/strong>-\u0437\u0430\u043f\u0440\u043e\u0441\u0430.<\/p>\n<pre><code class=\"java\">@PreAuthorize(\"hasAnyAuthority('USER_READ', 'USER')\") @GetMapping(value = \"\/{id}\", produces = {MediaType.APPLICATION_JSON_VALUE}) public ResponseEntity&lt;EntityModel&lt;UsersResponseModel>> getUserById(@PathVariable(\"id\") String id) {     UsersResponseModel respModel = new UsersResponseModel();     Optional&lt;Users> user = usersSvc.findById(id);     if(!user.isPresent()) {     throw new UserExceptions.UserNotFoudException(ErrorsMappings.USER_NOT_FOUND_MESSAGE);     }     respModel.setUser(user.get());     respModel.setCode(HttpStatus.OK.value());      EntityModel&lt;UsersResponseModel> entity = EntityModel.of(respModel);     entity = usersProcess.generateHateoas(entity, this, \"view-user\", user.get().getId());     return new ResponseEntity(entity, HttpStatus.OK); }<\/code><\/pre>\n<p><strong>\u0418\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0435 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438:<\/strong><\/p>\n<pre><code>&lt;dependency>     &lt;groupId>org.springframework.boot&lt;\/groupId>     &lt;artifactId>spring-boot-starter-security&lt;\/artifactId> &lt;\/dependency> &lt;dependency>     &lt;groupId>org.projectlombok&lt;\/groupId>     &lt;artifactId>lombok&lt;\/artifactId>     &lt;optional>true&lt;\/optional> &lt;\/dependency> &lt;dependency>     &lt;groupId>io.jsonwebtoken&lt;\/groupId>     &lt;artifactId>jjwt&lt;\/artifactId>     &lt;version>0.9.1&lt;\/version> &lt;\/dependency> &lt;dependency>     &lt;groupId>org.springframework.cloud&lt;\/groupId>     &lt;artifactId>spring-cloud-starter-config&lt;\/artifactId> &lt;\/dependency> &lt;dependency>     &lt;groupId>org.springframework.cloud&lt;\/groupId>     &lt;artifactId>spring-cloud-starter-netflix-eureka-client&lt;\/artifactId> &lt;\/dependency><\/code><\/pre>\n<p>\u0414\u043b\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f Config Server \u0438 Eureka Client \u0442\u0430\u043a\u0436\u0435 \u0434\u043e\u0431\u0430\u0432\u0438\u043c \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0440\u0430\u0437\u0434\u0435\u043b dependencyManagement.<\/p>\n<pre><code>&lt;properties>    &lt;spring-cloud.version>2020.0.3&lt;\/spring-cloud.version> &lt;\/properties> &lt;dependencyManagement>    &lt;dependencies>       &lt;dependency>          &lt;groupId>org.springframework.cloud&lt;\/groupId>          &lt;artifactId>spring-cloud-dependencies&lt;\/artifactId>          &lt;version>${spring-cloud.version}&lt;\/version>          &lt;type>pom&lt;\/type>          &lt;scope>import&lt;\/scope>       &lt;\/dependency>    &lt;\/dependencies> &lt;\/dependencyManagement><\/code><\/pre>\n<h2>\u0418\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 JWT-\u0442\u043e\u043a\u0435\u043d\u0430<\/h2>\n<h3>\u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u043a \u043c\u0438\u043a\u0440\u043e\u0441\u0435\u0440\u0432\u0438\u0441\u0430\u043c<\/h3>\n<ul>\n<li>\n<p>API \u0434\u043b\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 JWT-\u0442\u043e\u043a\u0435\u043d\u0430:<\/p>\n<\/li>\n<\/ul>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/ee0\/14f\/966\/ee014f9668257c55285c7a8857bf25a7.png\" width=\"1400\" height=\"787\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/ee0\/14f\/966\/ee014f9668257c55285c7a8857bf25a7.png\"\/><figcaption><\/figcaption><\/figure>\n<ul>\n<li>\n<p>API <strong>validateToken<\/strong>, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0439 \u0434\u043b\u044f \u0432\u0430\u043b\u0438\u0434\u0430\u0446\u0438\u0438 \u0442\u043e\u043a\u0435\u043d\u0430, \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0433\u043e \u0432 \u0437\u0430\u043f\u0440\u043e\u0441\u0435, \u0438 \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u0439 \u043e\u0431 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438. (\u042d\u0442\u043e\u0442 API \u043f\u043e\u0437\u0436\u0435 \u0431\u0443\u0434\u0435\u0442 \u0437\u0430\u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u043d \u043e\u0442 \u0432\u043d\u0435\u0448\u043d\u0435\u0433\u043e \u0434\u043e\u0441\u0442\u0443\u043f\u0430).<\/p>\n<\/li>\n<\/ul>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/f35\/038\/be1\/f35038be163b0d7b2c390f7e478a13f7.png\" width=\"1400\" height=\"787\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/f35\/038\/be1\/f35038be163b0d7b2c390f7e478a13f7.png\"\/><figcaption><\/figcaption><\/figure>\n<ul>\n<li>\n<p>\u0417\u0430\u043f\u0440\u043e\u0441 \u043a \u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u043e\u043c\u0443 \u0440\u0435\u0441\u0443\u0440\u0441\u0443 \u0432 User-Service \u043f\u0440\u0438 \u0432\u044b\u0437\u043e\u0432\u0435 \u0447\u0435\u0440\u0435\u0437 API Gateway \u0441 \u0432\u0430\u043b\u0438\u0434\u043d\u044b\u043c \u0442\u043e\u043a\u0435\u043d\u043e\u043c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438:<\/p>\n<\/li>\n<\/ul>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/1a7\/aa7\/38f\/1a7aa738fd5c56f2818f79758cd88231.png\" width=\"1400\" height=\"776\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/1a7\/aa7\/38f\/1a7aa738fd5c56f2818f79758cd88231.png\"\/><figcaption><\/figcaption><\/figure>\n<ul>\n<li>\n<p>\u0417\u0430\u043f\u0440\u043e\u0441 \u043a \u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u043e\u043c\u0443 \u0440\u0435\u0441\u0443\u0440\u0441\u0443 \u0432 User-Service \u043f\u0440\u0438 \u0432\u044b\u0437\u043e\u0432\u0435 \u0447\u0435\u0440\u0435\u0437 API Gateway \u0431\u0435\u0437 \u0432\u0430\u043b\u0438\u0434\u043d\u043e\u0433\u043e \u0442\u043e\u043a\u0435\u043d\u0430:<\/p>\n<\/li>\n<\/ul>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/fc0\/534\/fda\/fc0534fda9c3d7a34492943cf9f427a9.png\" width=\"1400\" height=\"787\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/fc0\/534\/fda\/fc0534fda9c3d7a34492943cf9f427a9.png\"\/><figcaption><\/figcaption><\/figure>\n<ul>\n<li>\n<p>\u041f\u0440\u0438\u043c\u0435\u0440 JWT-\u0442\u043e\u043a\u0435\u043d\u0430, \u0441\u043e\u0437\u0434\u0430\u043d\u043d\u044b\u0439 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u043c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438:<\/p>\n<\/li>\n<\/ul>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/ec5\/24e\/f41\/ec524ef41e7ea23359c037ec0db72d69.png\" width=\"1400\" height=\"671\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/ec5\/24e\/f41\/ec524ef41e7ea23359c037ec0db72d69.png\"\/><figcaption><\/figcaption><\/figure>\n<p>\u041f\u043e\u043b\u043d\u044b\u0439 \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u0439 \u043a\u043e\u0434 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0432\u044b \u043c\u043e\u0436\u0435\u0442\u0435 \u043d\u0430\u0439\u0442\u0438 \u043f\u043e \u0430\u0434\u0440\u0435\u0441\u0443 <a href=\"https:\/\/github.com\/Vicky-cmd\/Authentication-Service.git\"><u>https:\/\/github.com\/Vicky-cmd\/Authentication-Service.git<\/u><\/a><\/p>\n<hr\/>\n<blockquote>\n<p>\u0421\u0435\u0433\u043e\u0434\u043d\u044f \u0432 20:00 \u0441\u043e\u0441\u0442\u043e\u0438\u0442\u0441\u044f \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0435 \u0437\u0430\u043d\u044f\u0442\u0438\u0435 \u00ab<strong>\u0421\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b \u043d\u0430 Java. \u041f\u0440\u0438\u043c\u0438\u0442\u0438\u0432\u043d\u044b\u0435 \u0442\u0438\u043f\u044b<\/strong>\u00bb. \u041d\u0430 \u044d\u0442\u043e\u043c \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u0443\u0440\u043e\u043a\u0435 \u0432\u044b \u0441\u043c\u043e\u0436\u0435\u0442\u0435 \u043f\u043e\u0437\u043d\u0430\u043a\u043e\u043c\u0438\u0442\u044c\u0441\u044f \u0441 \u043e\u0441\u043d\u043e\u0432\u043d\u044b\u043c\u0438 \u044d\u0442\u0430\u043f\u0430\u043c\u0438 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u043f\u0440\u043e\u0441\u0442\u0435\u0439\u0448\u0435\u0439 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b \u043d\u0430 Java, \u043f\u043e\u043d\u044f\u0442\u044c \u043f\u0440\u0438\u043d\u0446\u0438\u043f\u044b \u0440\u0430\u0431\u043e\u0442\u044b \u043a\u043e\u043c\u043f\u0438\u043b\u044f\u0442\u043e\u0440\u0430 \u0438 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u044b, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0440\u0430\u0437\u043e\u0431\u0440\u0430\u0442\u044c\u0441\u044f \u0441 class-\u0444\u0430\u0439\u043b\u0430\u043c\u0438. \u041d\u0430 \u0443\u0440\u043e\u043a\u0435 \u043c\u044b \u0438\u0437\u0443\u0447\u0438\u043c \u043f\u0440\u0438\u043c\u0438\u0442\u0438\u0432\u043d\u044b\u0435 \u0442\u0438\u043f\u044b \u0434\u0430\u043d\u043d\u044b\u0445, \u043a\u043e\u043d\u0441\u0442\u0430\u043d\u0442\u044b \u0438 enum. \u0420\u0435\u0433\u0438\u0441\u0442\u0440\u0430\u0446\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u0430 <a href=\"https:\/\/otus.pw\/fwCW\/\"><strong>\u043f\u043e \u0441\u0441\u044b\u043b\u043a\u0435<\/strong><\/a> \u0434\u043b\u044f \u0432\u0441\u0435\u0445 \u0436\u0435\u043b\u0430\u044e\u0449\u0438\u0445.<\/p>\n<\/blockquote>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"v-portal\" style=\"display:none;\"><\/div>\n<\/div>\n<p> <!----> <!----><br \/> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/company\/otus\/blog\/681448\/\"> https:\/\/habr.com\/ru\/company\/otus\/blog\/681448\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<p>\u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c, \u043a\u0430\u043a \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0446\u0435\u043d\u0442\u0440\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 (Authorization Server) \u0438 API-\u0448\u043b\u044e\u0437\u0430 (API Gateway).<\/p>\n<h2>\u0427\u0442\u043e \u0442\u0430\u043a\u043e\u0435 JWT-\u0442\u043e\u043a\u0435\u043d \u0438 \u0437\u0430\u0447\u0435\u043c \u0435\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c?<\/h2>\n<p><em>JSON Web Token (JWT) \u2014 \u044d\u0442\u043e \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442 \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0441 \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0439 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u043e\u0439 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0435 JSON \u0432 \u0432\u0438\u0434\u0435 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u0430 \u0443\u0442\u0432\u0435\u0440\u0436\u0434\u0435\u043d\u0438\u0439 (claim)\u00a0 \u0441 \u043e\u043f\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u044c\u044e \u0438\/\u0438\u043b\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435\u043c.<\/em><\/p>\n<p>JWT-\u0442\u043e\u043a\u0435\u043d\u044b \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0442 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438 \u043c\u043e\u0433\u0443\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0432 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u0430\u0445, \u0438\u043d\u0441\u0442\u0430\u043d\u0441\u0430\u0445 \u0434\u043b\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 stateless-\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 (\u0431\u0435\u0437 \u0441\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u044f). \u041f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 JWT-\u0442\u043e\u043a\u0435\u043d\u043e\u0432 \u043d\u0435\u0442 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u0438 \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0442\u044c \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0435 \u0440\u0435\u0441\u0443\u0440\u0441\u044b \u0434\u043b\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u0438\u0445 \u0441\u0435\u0441\u0441\u0438\u0439 \u0438\u043b\u0438 \u0445\u0440\u0430\u043d\u0438\u0442\u044c \u0442\u043e\u043a\u0435\u043d\u044b\/\u0441\u0435\u0441\u0441\u0438\u0438 \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0439 \u0431\u0430\u0437\u0435 \u0434\u0430\u043d\u043d\u044b\u0445\/\u043a\u044d\u0448\u0435.<\/p>\n<h3>\u0410\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u0430 \u0440\u0435\u0448\u0435\u043d\u0438\u044f<\/h3>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<p>\u041e\u0442\u043c\u0435\u0442\u0438\u043c \u043e\u0441\u043d\u043e\u0432\u043d\u044b\u0435 \u043c\u043e\u043c\u0435\u043d\u0442\u044b:<\/p>\n<ul>\n<li>\n<p>\u0414\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 JWT-\u0442\u043e\u043a\u0435\u043d\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0446\u0435\u043d\u0442\u0440\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u0441\u0435\u0440\u0432\u0435\u0440 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 (Authorization Server).<\/p>\n<\/li>\n<li>\n<p>API Gateway \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u0441\u043e\u0431\u043e\u0439 \u0435\u0434\u0438\u043d\u0443\u044e \u0442\u043e\u0447\u043a\u0443 \u0432\u0445\u043e\u0434\u0430 \u0432 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u0442 \u0437\u0430\u043f\u0440\u043e\u0441\u044b \u043a \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u043c \u043c\u0438\u043a\u0440\u043e\u0441\u0435\u0440\u0432\u0438\u0441\u0430\u043c.<\/p>\n<\/li>\n<li>\n<p>\u041a \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0430\u043c (routes) \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442\u0441\u044f Gateway-\u0444\u0438\u043b\u044c\u0442\u0440, \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u044e\u0449\u0438\u0439 JWT-\u0442\u043e\u043a\u0435\u043d\u044b \u0432 \u0437\u0430\u043f\u0440\u043e\u0441\u0430\u0445 \u043a \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u043c\u044b\u043c \u0440\u0435\u0441\u0443\u0440\u0441\u0430\u043c. \u0414\u043b\u044f \u0432\u0430\u043b\u0438\u0434\u0430\u0446\u0438\u0438 \u0442\u043e\u043a\u0435\u043d\u0430 \u0438 \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0438\u043c\u0435\u043d\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0441 \u0435\u0433\u043e \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u044f\u043c\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442\u0441\u044f \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0435 \u043a \u0441\u0435\u0440\u0432\u0435\u0440\u0443 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 (Authorization Server). \u0414\u0430\u043b\u0435\u0435 \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u043d\u0430\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043f\u0435\u0440\u0435\u0434\u0430\u0435\u0442\u0441\u044f \u0434\u0440\u0443\u0433\u0438\u043c \u0441\u0435\u0440\u0432\u0438\u0441\u0430\u043c \u0432 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u0430.<\/p>\n<\/li>\n<li>\n<p>\u0414\u043b\u044f Service Discovery (\u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u044f \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432) \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c Eureka Discovery Client.<\/p>\n<\/li>\n<\/ul>\n<h3>\u0410\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044f<\/h3>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<p>\u0410\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044f \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c:<\/p>\n<ul>\n<li>\n<p>\u041f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u043b\u043e\u0433\u0438\u043d\u0438\u0442\u0441\u044f (\u0441\u043e\u0437\u0434\u0430\u0435\u0442 \u0442\u043e\u043a\u0435\u043d \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438), \u0432\u044b\u0437\u044b\u0432\u0430\u044f \u043a\u043e\u043d\u0435\u0447\u043d\u0443\u044e \u0442\u043e\u0447\u043a\u0443 <code>\/login<\/code> (POST) \u0441 \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0435\u0439 \u0438\u043c\u0435\u043d\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438 \u043f\u0430\u0440\u043e\u043b\u044f. \u0412 \u043e\u0442\u0432\u0435\u0442 \u0432 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0435 \u043e\u043d \u043f\u043e\u043b\u0443\u0447\u0430\u0435\u0442 Bearer-\u0442\u043e\u043a\u0435\u043d.<\/p>\n<\/li>\n<li>\n<p>\u0422\u043e\u043a\u0435\u043d \u043f\u0435\u0440\u0435\u0434\u0430\u0435\u0442\u0441\u044f \u0432 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0435 \u0432 \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0435 <code>Authorization<\/code><strong> <\/strong>\u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0435 <code>Bearer access_token<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u0414\u043b\u044f \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u043a \u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u044b\u043c \u0440\u0435\u0441\u0443\u0440\u0441\u0430\u043c \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u043a\u0430\u0441\u0442\u043e\u043c\u043d\u044b\u0439 <strong>Gateway Filter (AuthenticationPrefilter)<\/strong>. \u0412 \u0444\u0438\u043b\u044c\u0442\u0440\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442\u0441\u044f \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0435 \u043a \u043a\u043e\u043d\u0435\u0447\u043d\u043e\u0439 \u0442\u043e\u0447\u043a\u0435 <strong>\/api\/v1\/validateToken<\/strong> \u0441\u0435\u0440\u0432\u0438\u0441\u0430 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 (Authentication Service), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0432\u0430\u043b\u0438\u0434\u0438\u0440\u0443\u0435\u0442 \u0442\u043e\u043a\u0435\u043d \u0438, \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0443\u0441\u043f\u0435\u0448\u043d\u043e\u0439 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438, \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u0442 \u0432 \u043e\u0442\u0432\u0435\u0442 \u0438\u043c\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438 \u0435\u0433\u043e \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u044f (authorities).<\/p>\n<\/li>\n<li>\n<p>\u0415\u0441\u043b\u0438 \u0442\u043e\u043a\u0435\u043d \u0432\u0430\u043b\u0438\u0434\u043d\u044b\u0439, \u0442\u043e \u043f\u0435\u0440\u0435\u0434 \u043f\u0435\u0440\u0435\u0430\u0434\u0440\u0435\u0441\u0430\u0446\u0438\u0435\u0439 \u043d\u0430 \u0440\u0435\u0441\u0443\u0440\u0441, \u0437\u0430\u043f\u0440\u043e\u0448\u0435\u043d\u043d\u044b\u0439 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c, \u043a \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0443 \u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u0438\u043c\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438 <a href=\"https:\/\/javarevisited.blogspot.com\/2013\/07\/role-based-access-control-using-spring-security-ldap-authorities-mapping-mvc.html\"><u>\u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u044f<\/u><\/a>.<\/p>\n<\/li>\n<li>\n<p>\u0412 \u043e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0438\u043a\u0440\u043e\u0441\u0435\u0440\u0432\u0438\u0441\u0430\u0445 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, user-service) \u0444\u0438\u043b\u044c\u0442\u0440 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438, \u043d\u0430\u0441\u043b\u0435\u0434\u0443\u0435\u043c\u044b\u0439 \u043e\u0442 <code>OncePerRequestFilter<\/code>, \u0441\u043e\u0437\u0434\u0430\u0435\u0442 \u043e\u0431\u044a\u0435\u043a\u0442 <code>Authentication<\/code>, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043a\u043b\u0430\u0441\u0441 <code>UsernamePasswordAuthenticationToken<\/code> (\u0441 <em>username<\/em> \u0438 <em>SimpleGrantedAuthority<\/em> \u0438\u0437 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0430, \u0441 \u043f\u0430\u0440\u043e\u043b\u0435\u043c null).<\/p>\n<\/li>\n<li>\n<p>\u0415\u0441\u043b\u0438 \u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0435\u0441\u0442\u044c \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u044f\/\u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0440\u0435\u0441\u0443\u0440\u0441\u0443, \u0442\u043e \u0437\u0430\u043f\u0440\u043e\u0441 \u0440\u0430\u0437\u0440\u0435\u0448\u0430\u0435\u0442\u0441\u044f. \u0412 \u043f\u0440\u043e\u0442\u0438\u0432\u043d\u043e\u043c \u0441\u043b\u0443\u0447\u0430\u0435 \u043a\u043b\u0438\u0435\u043d\u0442\u0443 \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u0442\u0441\u044f \u043e\u0442\u0432\u0435\u0442 401 Unathorized \/ 403 Forbidden.<\/p>\n<\/li>\n<\/ul>\n<h2>\u041f\u0438\u0448\u0435\u043c \u0441\u0435\u0440\u0432\u0438\u0441\u044b<\/h2>\n<h3>Eureka Server<\/h3>\n<ul>\n<li>\n<p>\u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 Spring Boot, \u0447\u0435\u0440\u0435\u0437 <a href=\"https:\/\/start.spring.io\/\"><u>Spring Initializr<\/u><\/a> \u0441 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044c\u044e <code>spring-cloud-starter-netflix-eureka-server<\/code>. \u0422\u0430\u043a\u0436\u0435 \u0434\u043e\u0431\u0430\u0432\u044c\u0442\u0435 <code>spring-cloud-dependencies<\/code><strong> <\/strong>\u0432 <code>dependencyManagement<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u0434\u043b\u044f \u0437\u0430\u043f\u0443\u0441\u043a\u0430 Eureka Server \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c \u0430\u043d\u043d\u043e\u0442\u0430\u0446\u0438\u044e <a href=\"https:\/\/www.java67.com\/2018\/12\/top-5-spring-cloud-annotations-for-java.html\"><u>@EnableEurekaServer<\/u><\/a> \u043a \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u043c\u0443 \u043a\u043b\u0430\u0441\u0441\u0443 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f.<\/p>\n<\/li>\n<li>\n<p>\u0412 property-\u0444\u0430\u0439\u043b \u0434\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 Eureka Server:<\/p>\n<\/li>\n<\/ul>\n<pre><code>spring.application.name=naming-server server.port=8761  eureka.client.register-with-eureka=false eureka.client.fetch-registry=false eureka.instance.prefer-ip-address=true<\/code><\/pre>\n<ul>\n<li>\n<p>Eureka Server \u0431\u0443\u0434\u0435\u0442 \u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u043f\u043e \u0430\u0434\u0440\u0435\u0441\u0443 <a href=\"http:\/\/localhost:8761\/\"><u>http:\/\/localhost:8761\/<\/u><\/a>. \u041d\u0430 \u0433\u043b\u0430\u0432\u043d\u043e\u0439 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0435 \u043c\u043e\u0436\u043d\u043e \u0443\u0432\u0438\u0434\u0435\u0442\u044c \u0441\u043f\u0438\u0441\u043e\u043a \u0437\u0430\u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432.<\/p>\n<\/li>\n<\/ul>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<h3>Authorization Service (\u0441\u0435\u0440\u0432\u0438\u0441 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438)<\/h3>\n<ul>\n<li>\n<p>\u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f Spring Boot \u0441\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c\u0438 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u043c\u0438: <code>spring-boot-starter-security<\/code><strong>, <\/strong><code>spring-boot-starter-web<\/code><strong>, <\/strong><code>spring-cloud-starter-sleuth<\/code><strong>, <\/strong><code>spring-cloud-starter-config<\/code><strong>, <\/strong><code>spring-cloud-starter-netflix-eureka-client<\/code><strong>, <\/strong><code>spring-boot-starter-data-jpa<\/code><strong>, <\/strong><code>spring-boot-starter-data-mongodb<\/code><strong>, <\/strong><code>spring-boot-starter-data-redis<\/code> \u0438<strong> <\/strong><code>lombok<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u0417\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044c <code>spring-boot-starter-security<\/code> \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u0430 \u0434\u043b\u044f \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 \u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438, <code>spring-boot-starter-data-mongodb<\/code> \u0438 <code>spring-boot-starter-data-jpa<\/code><strong> \u2014 <\/strong>\u0434\u043b\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043a \u0443\u0447\u0435\u0442\u043d\u044b\u043c \u0434\u0430\u043d\u043d\u044b\u043c \u0432 MongoDB. \u0414\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 JWT-\u0442\u043e\u043a\u0435\u043d\u043e\u0432 \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c <code>io.jsonwebtoken:jjwt<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u0414\u043b\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u0443\u0447\u0435\u0442\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u0431\u0430\u0437\u0435 \u0434\u0430\u043d\u043d\u044b\u0445 \u043d\u0430\u043f\u0438\u0448\u0435\u043c \u0441\u0432\u043e\u044e \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e <code>UserDetailsService<\/code> \u0438\u0437 <a href=\"https:\/\/medium.com\/javarevisited\/top-10-courses-to-learn-spring-security-and-oauth2-with-spring-boot-for-java-developers-8f0222d6066d\"><u>Spring Security<\/u><\/a>. \u0414\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0443\u0447\u0435\u0442\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438\u0437 <a href=\"https:\/\/medium.com\/javarevisited\/top-5-sql-and-database-courses-to-learn-online-48424533ac61\"><u>\u0431\u0430\u0437\u044b \u0434\u0430\u043d\u043d\u044b\u0445 <\/u><\/a>\u0438 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u044d\u043a\u0437\u0435\u043c\u043f\u043b\u044f\u0440\u0430 <code>UserDetails<\/code> \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043c\u0435\u0442\u043e\u0434 <code>loadUserByUsername()<\/code>.<\/p>\n<\/li>\n<\/ul>\n<pre><code>@Service public class ApplicationUserDetailsService implements UserDetailsService {      @Autowired     private UsersService usersService;       @Override     public UserDetails loadUserByUsername(String s) throws UsernameNotFoundException {         return new ApplicationUsers(usersService.getByUsrName(s).orElseThrow(() -> new UsernameNotFoundException(\"Username Not Found\")));     } }<\/code><\/pre>\n<ul>\n<li>\n<p>\u0421\u0432\u043e\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f <code>UserDetails<\/code> \u043d\u0430\u043c \u043d\u0443\u0436\u043d\u0430 \u0434\u043b\u044f \u043c\u0430\u043f\u043f\u0438\u043d\u0433\u0430 \u043e\u0431\u044a\u0435\u043a\u0442\u043e\u0432, \u0445\u0440\u0430\u043d\u044f\u0449\u0438\u0445\u0441\u044f \u0432 \u0431\u0430\u0437\u0435 \u0434\u0430\u043d\u043d\u044b\u0445, \u043d\u0430 \u043e\u0431\u044a\u0435\u043a\u0442\u044b, \u0442\u0440\u0435\u0431\u0443\u0435\u043c\u044b\u0435 Spring Security.<\/p>\n<\/li>\n<li>\n<p>\u0421\u043e\u0437\u0434\u0430\u0435\u043c \u043a\u043b\u0430\u0441\u0441 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u2014 \u043d\u0430\u0441\u043b\u0435\u0434\u043d\u0438\u043a <code>WebSecurityConfigurerAdapter<\/code>.<\/p>\n<\/li>\n<\/ul>\n<pre><code class=\"java\">package com.infotrends.in.authenticationserver.security.config;  import com.infotrends.in.authenticationserver.security.filters.JWTAuthenticationFilter; import com.infotrends.in.authenticationserver.security.filters.JWTVerifierFilter; import com.infotrends.in.authenticationserver.security.services.ApplicationUserDetailsService; import com.infotrends.in.authenticationserver.services.redis.TokensRedisService; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.authentication.dao.DaoAuthenticationProvider; import org.springframework.security.config.annotation.authentication.builders.AuthenticationManagerBuilder; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; import org.springframework.security.config.http.SessionCreationPolicy; import org.springframework.security.crypto.password.PasswordEncoder;  @Configuration @EnableWebSecurity public class WebSecurityConfig extends WebSecurityConfigurerAdapter {       @Autowired     private PasswordEncoder encoder;      @Autowired     private ApplicationUserDetailsService applicationUserDetailsService;      @Autowired     private TokensRedisService redisService;      @Override     protected void configure(HttpSecurity http) throws Exception {         http.csrf().disable()                 .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS)                 .and()                 .addFilter(new JWTAuthenticationFilter(authenticationManager(), redisService))                 .addFilterAfter(new JWTVerifierFilter(redisService), JWTAuthenticationFilter.class)                 .authorizeRequests()                 .antMatchers(\"\/api\/v1\/validateConnection\/whitelisted\").permitAll()                 .anyRequest()                 .authenticated()                 .and().httpBasic();     }      @Override     protected void configure(AuthenticationManagerBuilder auth) throws Exception {         auth.authenticationProvider(authenticationProvider());     }      @Bean     public DaoAuthenticationProvider authenticationProvider() {         DaoAuthenticationProvider authenticationProvider = new DaoAuthenticationProvider();         authenticationProvider.setPasswordEncoder(encoder);         authenticationProvider.setUserDetailsService(applicationUserDetailsService);          return authenticationProvider;     } }<\/code><\/pre>\n<ul>\n<li>\n<p>\u0417\u0434\u0435\u0441\u044c \u043c\u044b \u0441\u043e\u0437\u0434\u0430\u0435\u043c \u0431\u0438\u043d <code>DaoAuthenticationProvider<\/code> \u0441 \u043a\u043e\u0434\u0438\u0440\u043e\u0432\u0449\u0438\u043a\u043e\u043c \u043f\u0430\u0440\u043e\u043b\u0435\u0439 \u0438 \u043d\u0430\u0448\u0435\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0435\u0439 <code>UserDetailsService<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u041a\u043e\u0442\u043e\u0440\u044b\u0435, \u0432 \u0441\u0432\u043e\u044e \u043e\u0447\u0435\u0440\u0435\u0434\u044c, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0442\u0441\u044f \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f <code>configure(AuthenticationManagerBuilder auth)<\/code>, \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e <code>AuthenticationManagerBuilder<\/code> \u0434\u043b\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u043d\u043e\u0433\u043e \u043d\u0430\u043c\u0438 Authentication Provider.<\/p>\n<\/li>\n<li>\n<p>\u0414\u0430\u043b\u0435\u0435 \u0434\u043b\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f JWT\/Bearer-\u0442\u043e\u043a\u0435\u043d\u043e\u0432 \u0432\u043c\u0435\u0441\u0442\u043e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u043f\u043e \u043b\u043e\u0433\u0438\u043d\u0443 \u0438 \u043f\u0430\u0440\u043e\u043b\u044e, \u043d\u0430\u0434\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0434\u0432\u0430 \u0444\u0438\u043b\u044c\u0442\u0440\u0430: \u043e\u0434\u0438\u043d \u0434\u043b\u044f \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 Bearer-\u0442\u043e\u043a\u0435\u043d\u0430, \u0430 \u0434\u0440\u0443\u0433\u043e\u0439 \u2014 \u0434\u043b\u044f \u0435\u0433\u043e \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438.<\/p>\n<\/li>\n<li>\n<p>\u0424\u0438\u043b\u044c\u0442\u0440 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 JWT \u0441\u043e\u0437\u0434\u0430\u0435\u043c \u043a\u0430\u043a \u043f\u043e\u0434\u043a\u043b\u0430\u0441\u0441 <code>UsernamePasswordAuthenticationFilter<\/code>. <strong>\u00a0<\/strong>\u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0443\u0447\u0435\u0442\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u043f\u0435\u0440\u0435\u043e\u043f\u0440\u0435\u0434\u0435\u043b\u044f\u0435\u043c \u043c\u0435\u0442\u043e\u0434 <code>attemptAuthentication()<\/code>. \u0414\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f JWT-\u0442\u043e\u043a\u0435\u043d\u0430 \u043f\u0440\u0438 \u0443\u0441\u043f\u0435\u0448\u043d\u043e\u0439 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u2014 \u043c\u0435\u0442\u043e\u0434 \u0438 <code>successAuthentication<\/code><strong>()<\/strong>.<\/p>\n<\/li>\n<\/ul>\n<pre><code class=\"java\">package com.infotrends.in.authenticationserver.security.filters;  import com.fasterxml.jackson.databind.ObjectMapper; import com.infotrends.in.InfoTrendsIn.security.SecurityConstants; import com.infotrends.in.authenticationserver.model.ConnValidationResponse; import com.infotrends.in.authenticationserver.model.JwtAuthenticationModel; import com.infotrends.in.authenticationserver.model.redis.TokensEntity; import com.infotrends.in.authenticationserver.services.redis.TokensRedisService; import com.infotrends.in.authenticationserver.utils.Utilities; import io.jsonwebtoken.Jwts; import io.jsonwebtoken.SignatureAlgorithm; import lombok.RequiredArgsConstructor; import lombok.extern.slf4j.Slf4j; import org.springframework.http.HttpHeaders; import org.springframework.http.MediaType; import org.springframework.security.authentication.AuthenticationManager; import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; import org.springframework.security.core.Authentication; import org.springframework.security.core.AuthenticationException; import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter;  import javax.servlet.FilterChain; import javax.servlet.ServletException; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletResponse; import java.io.IOException; import java.time.LocalDateTime; import java.time.ZoneOffset; import java.util.Date;  @Slf4j @RequiredArgsConstructor public class JWTAuthenticationFilter extends UsernamePasswordAuthenticationFilter {      private final AuthenticationManager authenticationManager;     private ObjectMapper mapper=new ObjectMapper();      private final TokensRedisService tokensRedisService;      @Override     public Authentication<\/code><\/pre>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-336714","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/336714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=336714"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/336714\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=336714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=336714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=336714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}