yinjihuan / monkey-api-encrypt

monkey-api-encrypt是对基于Servlet的Web框架API请求进行统一加解密操作
Apache License 2.0
792 stars 347 forks source link

开启@EnableEncrypt注解后 oauth/token 获取token的也被拦截进行加解密了? #90

Closed randeexiong closed 2 years ago

randeexiong commented 2 years ago

开启 @EnableEncrypt 注解后, 连oauth获取token的 链接返回的数据都被进行加密了,不是只对 @Decrypt的方法才进行 解密处理??? oauth/token?grant_type=password&username=user1&password=123

返回的值

nsbPm4T/UA4jKBUJpTeERtYwq08MTht6FiYp2OkpchREjvT1wjlTxn/xxIAQGr8JybcfVvnz3baoXUEQpQeIlV5RfUUMVD+A7J+dTenm7Ytc2Rw8uXFWTNJaZKfKBDru9p2Ob1dQBrbGGiuvBOxeAPKZ8DZ7+k6+mPaWRcpcfPRm9LpK7IkREWOiCKikQ3uAFQfySVLQnPuiTOaeKqVgfXcDy62rneOtW8gASHluUMRaxRXIdGT+KEyLjDNxuiu/KLtdoWZeLbGtKaGcP59jofrEW6DL/ZjOUi/OiSht7P5erlXLcXog8k18Ts0F5yRq2uwUCxJj8xXVuaIwyTpS2CqNeaqgNezHfuKyM+Y58rztdAj6eDI5+AQEbuBA2XPfvU0epJL2ju9Qfdo4ACi9gvgPjI/z0ebuPtye71za3ATPyYp2kfTi0FitnCOsaFPFBDLneU3vNr2W0JswOZuapF5FHE27VLLOkXg5+wlKCdgAWCo4uYwAGur3I1u31vBnKnwEFiC6/Bl3hJyCbphmMpS3MKIW/dptNyc3FaJ9dFEcY97r3NfqaN1WPKln8VWDoXjk8EjOj9xrQzWLcLr3BTHGQttajoxu3uasMwP2/PVJ9hMGdPS6s485UoN2ZLFVw/tG8+ZpHw5abSppGIJAwjQpUeyoP0Xzl30Q2DboP69tak8fU99fw294SGM18EhZ0RBZygF/34gLNxoGKkqcG3nnkobNmIai1i4oIkDMSUzqad1LhuRq6SdQbLDeD8MUHYLOEo5LRkta7jz8Ucs2VGprNXUQGzAzDMBDULJaeCRa+5VwGd7sfplJDnMhCtfbVMqLJ3UWT/xU5NopyY/QspOO9mONvM1EzUGWdsONs5AJS3zNtMlys/X68EhG2IeEnV2W3w3oHO6gPUibZ+bMN33vOJU069j67p5N3ty4u4xMHRE8+JbCXsLV7/l6gq2jiX1iMc0kZ44O7bxQ1IvsVA==
randeexiong commented 2 years ago

已经找到原因了,在默认不配置任何加解密,会对所有方法进行加解密

建议增加两个属性来确定开启全局加密和解密