TransientBa 2022-09-06 19:40 采纳率: 0%
浏览 268
已结题

security+redis实现session共享序列化失败且替换RedisTemplate失败

模块化springboot做redisSession共享 原来单机 现在两台 项目使用platform-bom 2.0.8 对应springboot1.3.8版本 已经是内网最高版本了 不支持升级 spring-boot-starter-redis 1.3.8
本身项目用的是SessionRedis+sercurity这一套 最近把@EnableRedisHttpSession打开了,但是RedisTemplate默认用的JdkSerializationRedisSerializer ,sercurite验证登录后会自动保存一个key为SPRING_SECURITY_CONTEXT的对象,导致序列化时报错
20:25:17.629 [http-nio-8099-exec-6] ERROR o.s.boot.web.support.ErrorPageFilter - Forwarding to error page from request [/login] due to exception [Cannot serialize; nested exception is org.springframework.core.serializer.support.SerializationFailedException: Failed to serialize object using DefaultSerializer; nested exception is java.io.NotSerializableException: org.springframework.session.web.http.SessionRepositoryFilter$SessionRepositoryRequestWrapper$HttpSessionWrapper]
org.springframework.data.redis.serializer.SerializationException: Cannot serialize; nested exception is org.springframework.core.serializer.support.SerializationFailedException: Failed to serialize object using DefaultSerializer; nested exception is java.io.NotSerializableException: org.springframework.session.web.http.SessionRepositoryFilter$SessionRepositoryRequestWrapper$HttpSessionWrapper
    at org.springframework.data.redis.serializer.JdkSerializationRedisSerializer.serialize(JdkSerializationRedisSerializer.java:93)
    at org.springframework.data.redis.core.AbstractOperations.rawHashValue(AbstractOperations.java:171)
    at org.springframework.data.redis.core.DefaultHashOperations.putAll(DefaultHashOperations.java:129)
    at org.springframework.data.redis.core.DefaultBoundHashOperations.putAll(DefaultBoundHashOperations.java:86)
    at org.springframework.session.data.redis.RedisOperationsSessionRepository$RedisSession.saveDelta(RedisOperationsSessionRepository.java:770)
    at org.springframework.session.data.redis.RedisOperationsSessionRepository$RedisSession.access$000(RedisOperationsSessionRepository.java:662)
    at org.springframework.session.data.redis.RedisOperationsSessionRepository.save(RedisOperationsSessionRepository.java:388)
    at org.springframework.session.data.redis.RedisOperationsSessionRepository.save(RedisOperationsSessionRepository.java:245)
    at org.springframework.session.web.http.SessionRepositoryFilter$SessionRepositoryRequestWrapper.commitSession(SessionRepositoryFilter.java:245)
    at org.springframework.session.web.http.SessionRepositoryFilter$SessionRepositoryRequestWrapper.access$100(SessionRepositoryFilter.java:217)
    at org.springframework.session.web.http.SessionRepositoryFilter.doFilterInternal(SessionRepositoryFilter.java:170)
    at org.springframework.session.web.http.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:80)
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
    at org.springframework.web.filter.CharacterEncodingFilter.doFilterInternal(CharacterEncodingFilter.java:197)
    at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
    at org.springframework.boot.web.support.ErrorPageFilter.doFilter(ErrorPageFilter.java:117)
    at org.springframework.boot.web.support.ErrorPageFilter.access$000(ErrorPageFilter.java:61)
    at org.springframework.boot.web.support.ErrorPageFilter$1.doFilterInternal(ErrorPageFilter.java:92)
    at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)
    at org.springframework.boot.web.support.ErrorPageFilter.doFilter(ErrorPageFilter.java:110)
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
    at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:198)
    at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:96)
    at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:496)
    at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:140)
    at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:81)
    at org.apache.catalina.valves.AbstractAccessLogValve.invoke(AbstractAccessLogValve.java:650)
    at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:87)
    at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:342)
    at org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:803)
    at org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:66)
    at org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:790)
    at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1459)
    at org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49)
    at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
    at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
    at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)
    at java.lang.Thread.run(Thread.java:748)

大概这样,转换思路既然没办法默认JDKSerial序列化,想自定义RedisTemplate用FastJsonRedisSerializer序列化value,定义了一个RedisConfig类

内网代码 手敲重点部分

@EnableRedisHttpSession
@Configuration
public class RedisConfig{
    @Bean(name = "redisTemplate")
    @Primy
    public RedisTemplate<String,Object> redisTemplate(RedisConnectionFactory redisConnectionFactory){
        这里new 了一个RedisTemplate  然后设置了KeyHashKeyvaluehashValue,defaultSerializer这些属性
        return 我自定义的redisTemplate
    }
}

想覆盖默认的RedisTemplate,再次验证登陆后,jar自动调用的时候用的还是原来的RedisTemplate,debugger发现调用的redisTemplate和我自定义的地址不是同一个地址,不是一个RedisTemplate,反复试验后依然无法覆盖原来的RedisTemplate

于是写了一个ApplicationContextUtils的工具类,继承 ApplicationContextAware,BeanPostProcessor

在这个类里面实现了postProcessAfterInitialization方法去替换这个RedisTemplate
逻辑是
1.项目启动
2.EnableRedisHttpSession引入RedisHttpSessionConfiguration 生成默认的RedisTemplate
3.执行我的自定义RedisTemplate
4.在ApplicationContextUtils中检测我的自定义RedisTemplate执行后,通过DefaultListableBeanFactory和beanName取出我的自定义RedisTemplate的BeanDefinition,然后把jar调用生成的RedisTemplate给Remove掉,再把自定义的这个BeanDefinition加上redisTemplate这个BeanName放回到beanFactory中

beanFactory.registerBeanDefinition("redisTemplate",我的自定义BeanDefinition)
再次运行后发现还是不行 ,在执行BeanDefinition的时候确认已经remove掉原来的RedisTemplate了 但是debug发现jar自动调用的redisTemplate依然是之前的那个地址,暂时不知道这个redisTemplate他是从哪里取的
解决结果可以是用默认的JDKSerializer或者能够替换掉默认的redisTemplate,最终目的是把jar自动存的这个SPRING_SECURITY_CONTEXT 对象保存到redis中并可以取到

实现一个security+redis+session共享的一个效果

  • 写回答

9条回答 默认 最新

  • TransientBa 2022-09-06 20:17
    关注

    刚提完问题 自己找到答案了 Enbale里面RedisTemplate的Bean是<String,ExpiringSession>类型的 beanName是sessionRedisTemplate 替换这个才行

    评论

报告相同问题?

问题事件

  • 系统已结题 9月14日
  • 创建了问题 9月6日

悬赏问题

  • ¥15 django项目运行报编码错误
  • ¥15 请问这个是什么意思?
  • ¥15 STM32驱动继电器
  • ¥15 Windows server update services
  • ¥15 关于#c语言#的问题:我现在在做一个墨水屏设计,2.9英寸的小屏怎么换4.2英寸大屏
  • ¥15 模糊pid与pid仿真结果几乎一样
  • ¥15 java的GUI的运用
  • ¥15 我想付费需要AKM公司DSP开发资料及相关开发。
  • ¥15 怎么配置广告联盟瀑布流
  • ¥15 Rstudio 保存代码闪退