iamsungink / spring-security-practice-copy

0 stars 0 forks source link

04. SecurityContextHolder & Authentication #8

Open iamsungink opened 1 week ago

iamsungink commented 1 week ago

Spring Security의 내부구조

SecurityContextHolder

SecurityContext

Principal

GrantAuthority

실습

// note: SecurityContextHolder 살펴보기
        SecurityContext securityContext = SecurityContextHolder.getContext();
iamsungink commented 1 week ago

Thread Local

요청 1개에 Thread 1개가 생성됨.

그러나 ThreadLocal만 강제로 사용해야하는 것은 아니며 원하면 SecurityContext 공유 전략을 바꿀수 있음

  1. MODE_THREADLOCAL ThreadLocalSecurityContextHolderStrategy를 사용 ThreadLocal을 사용하여 같은 Thread안에서 SecurityContext를 공유
  2. MODE_INHERITABLETHREADLOCAL InheritableThreadLocalSecurityContextHolderStrategy를 사용 InheritableThreadLocal을 사용하여 자식 Thread까지도 SecurityContext를 공유
  3. MODE_GLOBAL GlobalSecurityContextHolderStrategy 를 사용 Global로 설정되어 애플리케이션 전체에서 SecurityContext를 공유
iamsungink commented 1 week ago

ThreadLocalSecurityContextHolderStrategy

/*
 * Copyright 2004, 2005, 2006 Acegi Technology Pty Limited
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *      https://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

package org.springframework.security.core.context;

import org.springframework.util.Assert;

/**
 * A <code>ThreadLocal</code>-based implementation of
 * {@link SecurityContextHolderStrategy}.
 *
 * @author Ben Alex
 * @see java.lang.ThreadLocal
 * @see org.springframework.security.core.context.web.SecurityContextPersistenceFilter
 */
final class ThreadLocalSecurityContextHolderStrategy implements SecurityContextHolderStrategy {

    private static final ThreadLocal<SecurityContext> contextHolder = new ThreadLocal<>();

    @Override
    public void clearContext() {
        contextHolder.remove();
    }

    @Override
    public SecurityContext getContext() {
        SecurityContext ctx = contextHolder.get();
        if (ctx == null) {
            ctx = createEmptyContext();
            contextHolder.set(ctx);
        }
        return ctx;
    }

    @Override
    public void setContext(SecurityContext context) {
        Assert.notNull(context, "Only non-null SecurityContext instances are permitted");
        contextHolder.set(context);
    }

    @Override
    public SecurityContext createEmptyContext() {
        return new SecurityContextImpl();
    }

}