1 Star 0 Fork 0

zarchary / LogAuit

加入 Gitee
与超过 1200万 开发者一起发现、参与优秀开源项目,私有仓库也完全免费 :)
免费加入
克隆/下载
贡献代码
同步代码
取消
提示: 由于 Git 不支持空文件夾,创建文件夹后会生成空的 .keep 文件
Loading...
README
AFL-3.0

java 日志审计

一、引言 阐述日志审计在保证系统安全、追踪操作行为、满足合规要求等方面的关键作用,并指出为何选用SLF4J作为统一日志接口,以及 Aspect作为具体的日志实现框架来完成日志审计功能。

模块介绍

  • demo-a 为模块A。简单的controller,全局拦截器GlobalInterctor 记录日志,拦截器配置CustomWebConfig
  • demo-b 为模块B。 简单的controller,全局拦截器GlobalInterctor 记录日志,拦截器配置CustomWebConfig
  • demo-log 为日志模块 公共模块 切面操作

附上对应demo 地址:

二、SLF4J与Aspect简介

  • SLF4J的核心价值及其适配多种日志框架的能力
  • Aspect 来作为无侵入拦截

三、利用Aspect实现日志审计功能

* 日志切面类上应有@Aspect注解。
* 切面方法的切入点表达式应能匹配到模块A和B中的Controller方法,例如:Java
@Pointcut*("execution (* com.demo.demob.controller..*.*(..)) || " +
        "execution (* com.demo.demoa.controller..*.*(..)) ||" +
        "@annotation(com.demo.log.OperLog)")
* 确保公共模块作为依赖被正确地引入到模块A和B中。

1 启用Spring AOP代理: 在模块A和B的Spring Boot应用主类上添加@EnableAspectJAutoProxy注解来启用AOP代理。

2 确保拦截器工作正常

  • 拦截器类应正确地注册到Spring容器中,例如使用@Component注解,并在配置类中通过@Bean方法暴露出去,或者实现WebMvcConfigurer接口重写addInterceptors方法添加拦截器。

3 在线程局部存储中传递日志信息

  • 在切面中,将日志信息存入ThreadLocal变量。
  • 在拦截器的后置处理方法中,从ThreadLocal中取出并处理日志信息。

四、核心代码

1.切面注解

  • 通过注解形式添加到需要记录的方法上,即可完成对此方法的监控
package com.demo.log;

import java.lang.annotation.*;

/**
 * @author zzz
 * @pack_name com.mw.core.log
 * @project_name mcloud
 * @date 2024/3/25 11:03:40
 * @Description 注解操作
 */
@Target(ElementType.METHOD)
@Documented
@Retention(RetentionPolicy.RUNTIME)
public @interface OperLog {
    String operModul() default ""; // 操作模块
    String operType() default "";  // 操作类型
    String operDesc() default "";  // 操作说明
}

例如

在controller中 ,使用 @OperLog 记录操作的模块,内容等记录

@GetMapping("/test")
    @OperLog(operType = "测试", operDesc = "切面内容测试a")
    public String test() {
       return "HelloController.test------a";
    }

@Pointcut注解用于定义一个切入点(Pointcut)

  • @annotation 填入注解所在包
 @Pointcut("@annotation(com.demo.log.OperLog)")
    public void operLogPointCut() {
    }

@AfterReturning 通知 pointcut 填写切入

@AfterReturning(pointcut = "operLogPointCut()", returning = "keys")
    public JSONObject saveOperLog(JoinPoint joinPoint, Object keys) {
		// 具体增强内容。包含日志等。 具体代码参照 demo-log包内OperLogAspect类
		//伪代码
		// 获取RequestAttributes
        RequestAttributes requestAttributes = RequestContextHolder.getRequestAttributes();
		HttpServletRequest request = (HttpServletRequest) requestAttributes
                .resolveReference(RequestAttributes.REFERENCE_REQUEST);
        // 请求路径
        String requestURI = request.getRequestURI();
        // 请求路径
        logEntity.setFUrl(requestURI);
        // 主机地址
        String host = request.getRemoteAddr();

		// 获取日志注解的@OperLog的内容
		 // 从切面织入点处通过反射机制获取织入点处的方法
        MethodSignature signature = (MethodSignature) joinPoint.getSignature();
        // 获取切入点所在的方法
        Method method = signature.getMethod();
        // 获取操作 添加在controller上的@OperLog 
        OperLog opLog = method.getAnnotation(OperLog.class);
        logEntity.setFTitle(opLog.operDesc());

		// 当然,如果项目使用了 swagger或者增强knife4j-openapi3-spring-boot-starter
		//通过 反射获取 接口文档提供的注解 。获取接口文档里面的内容。获取 @ApiMethod 中的内容。完善日志记录内容
		/**
		 *   @ApiMethod(desc = "审批回调相关业务接口:", 
		 * 	 outerPath = "/{groupId}/callback", 	
		 *   innerPath = "/{groupId}/callback")

		 */
        // 从切面织入点处通过反射机制获取织入点处的方法
        MethodSignature signature = (MethodSignature) joinPoint.getSignature();
        // 获取切入点所在的方法
		ApiOperation annotation = method.getAnnotation(ApiOperation.class);

		// 最后 将处理内容设置到 本地线程上线文中
		ThreadUitl.set("log",logEntity )
	}

具体代码参照 demo-log包内OperLogAspect类

2.日记记录

  • 创建全局拦截器
  • 拦截器后置处理记录产生的日志

模块 demo-a 实现拦截器

package com.demo.demoa.interctor;

import com.alibaba.fastjson2.JSONObject;
import com.demo.util.ThreadLocalUtil;
import jakarta.servlet.http.HttpServletRequest;
import jakarta.servlet.http.HttpServletResponse;
import lombok.extern.slf4j.Slf4j;
import org.springframework.stereotype.Component;
import org.springframework.web.servlet.HandlerInterceptor;

/**
 * @author zzz
 * @pack_name com.demo.demoa.interctor
 * @project_name Log-Auit
 * @date 2024/3/26 14:03:54
 * @Description 全局拦截器
 */
@Component
@Slf4j
public class GlobalInterctor  implements HandlerInterceptor {

    @Override
    public void afterCompletion(HttpServletRequest request, HttpServletResponse response, Object handler, Exception ex) throws Exception {
        /**
         * demo A 日记记录。
         * 因为是跨应用获取日志。这里采用本地线程获取上下文  通过ThreadLocalUtil.get("log")获取
         */
        JSONObject logEntity = (JSONObject)ThreadLocalUtil.get("log");
        if (logEntity !=null){
            // 可以记录进数据库
            log.info("日志记录-===========》:{}",logEntity.toJSONString());
        }


        HandlerInterceptor.super.afterCompletion(request, response, handler, ex);
    }
}

注册拦截器

package com.demo.demoa.config;

import com.demo.demoa.interctor.GlobalInterctor;
import lombok.RequiredArgsConstructor;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.servlet.HandlerAdapter;
import org.springframework.web.servlet.HandlerInterceptor;
import org.springframework.web.servlet.config.annotation.InterceptorRegistry;
import org.springframework.web.servlet.config.annotation.WebMvcConfigurer;

/**
 * @author zzz
 * @pack_name com.demo.demoa
 * @project_name Log-Auit
 * @date 2024/3/26 15:03:03
 * @Description
 */
@Configuration
@RequiredArgsConstructor
public class CustomWebConfig implements WebMvcConfigurer {
    private final GlobalInterctor globalInterctor;



    @Override
    public void addInterceptors(InterceptorRegistry registry) {
        registry.addInterceptor(globalInterctor).addPathPatterns("/**");
    }
}

模块B类似。 只需要保证在切面类中 能对B模块需要 记录日记的包进行切入即可

例如:

  • 需要拦截多个模块, 就需要 @execution切入点对应想要记录的哪个包下面的内容。如果我想要 模块A和模块B都想切入,那么使用 || 分割即可
@Pointcut("execution (* com.demo.demob.controller..*.*(..)) || " +
            "execution (* com.demo.demoa.controller..*.*(..))
    public void operLogPointCut() {
    }
Academic Free License (“AFL”) v. 3.0 This Academic Free License (the "License") applies to any original work of authorship (the "Original Work") whose owner (the "Licensor") has placed the following licensing notice adjacent to the copyright notice for the Original Work: Licensed under the Academic Free License version 3.0 1) Grant of Copyright License. Licensor grants You a worldwide, royalty-free, non-exclusive, sublicensable license, for the duration of the copyright, to do the following: a) to reproduce the Original Work in copies, either alone or as part of a collective work; b) to translate, adapt, alter, transform, modify, or arrange the Original Work, thereby creating derivative works ("Derivative Works") based upon the Original Work; c) to distribute or communicate copies of the Original Work and Derivative Works to the public, under any license of your choice that does not contradict the terms and conditions, including Licensor’s reserved rights and remedies, in this Academic Free License; d) to perform the Original Work publicly; and e) to display the Original Work publicly. 2) Grant of Patent License. Licensor grants You a worldwide, royalty-free, non-exclusive, sublicensable license, under patent claims owned or controlled by the Licensor that are embodied in the Original Work as furnished by the Licensor, for the duration of the patents, to make, use, sell, offer for sale, have made, and import the Original Work and Derivative Works. 3) Grant of Source Code License. The term "Source Code" means the preferred form of the Original Work for making modifications to it and all available documentation describing how to modify the Original Work. Licensor agrees to provide a machine-readable copy of the Source Code of the Original Work along with each copy of the Original Work that Licensor distributes. Licensor reserves the right to satisfy this obligation by placing a machine-readable copy of the Source Code in an information repository reasonably calculated to permit inexpensive and convenient access by You for as long as Licensor continues to distribute the Original Work. 4) Exclusions From License Grant. Neither the names of Licensor, nor the names of any contributors to the Original Work, nor any of their trademarks or service marks, may be used to endorse or promote products derived from this Original Work without express prior permission of the Licensor. Except as expressly stated herein, nothing in this License grants any license to Licensor’s trademarks, copyrights, patents, trade secrets or any other intellectual property. No patent license is granted to make, use, sell, offer for sale, have made, or import embodiments of any patent claims other than the licensed claims defined in Section 2. No license is granted to the trademarks of Licensor even if such marks are included in the Original Work. Nothing in this License shall be interpreted to prohibit Licensor from licensing under terms different from this License any Original Work that Licensor otherwise would have a right to license. 5) External Deployment. The term "External Deployment" means the use, distribution, or communication of the Original Work or Derivative Works in any way such that the Original Work or Derivative Works may be used by anyone other than You, whether those works are distributed or communicated to those persons or made available as an application intended for use over a network. As an express condition for the grants of license hereunder, You must treat any External Deployment by You of the Original Work or a Derivative Work as a distribution under section 1(c). 6) Attribution Rights. You must retain, in the Source Code of any Derivative Works that You create, all copyright, patent, or trademark notices from the Source Code of the Original Work, as well as any notices of licensing and any descriptive text identified therein as an "Attribution Notice." You must cause the Source Code for any Derivative Works that You create to carry a prominent Attribution Notice reasonably calculated to inform recipients that You have modified the Original Work. 7) Warranty of Provenance and Disclaimer of Warranty. Licensor warrants that the copyright in and to the Original Work and the patent rights granted herein by Licensor are owned by the Licensor or are sublicensed to You under the terms of this License with the permission of the contributor(s) of those copyrights and patent rights. Except as expressly stated in the immediately preceding sentence, the Original Work is provided under this License on an "AS IS" BASIS and WITHOUT WARRANTY, either express or implied, including, without limitation, the warranties of non-infringement, merchantability or fitness for a particular purpose. THE ENTIRE RISK AS TO THE QUALITY OF THE ORIGINAL WORK IS WITH YOU. This DISCLAIMER OF WARRANTY constitutes an essential part of this License. No license to the Original Work is granted by this License except under this disclaimer. 8) Limitation of Liability. Under no circumstances and under no legal theory, whether in tort (including negligence), contract, or otherwise, shall the Licensor be liable to anyone for any indirect, special, incidental, or consequential damages of any character arising as a result of this License or the use of the Original Work including, without limitation, damages for loss of goodwill, work stoppage, computer failure or malfunction, or any and all other commercial damages or losses. This limitation of liability shall not apply to the extent applicable law prohibits such limitation. 9) Acceptance and Termination. If, at any time, You expressly assented to this License, that assent indicates your clear and irrevocable acceptance of this License and all of its terms and conditions. If You distribute or communicate copies of the Original Work or a Derivative Work, You must make a reasonable effort under the circumstances to obtain the express assent of recipients to the terms of this License. This License conditions your rights to undertake the activities listed in Section 1, including your right to create Derivative Works based upon the Original Work, and doing so without honoring these terms and conditions is prohibited by copyright law and international treaty. Nothing in this License is intended to affect copyright exceptions and limitations (including “fair use” or “fair dealing”). This License shall terminate immediately and You may no longer exercise any of the rights granted to You by this License upon your failure to honor the conditions in Section 1(c). 10) Termination for Patent Action. This License shall terminate automatically and You may no longer exercise any of the rights granted to You by this License as of the date You commence an action, including a cross-claim or counterclaim, against Licensor or any licensee alleging that the Original Work infringes a patent. This termination provision shall not apply for an action alleging patent infringement by combinations of the Original Work with other software or hardware. 11) Jurisdiction, Venue and Governing Law. Any action or suit relating to this License may be brought only in the courts of a jurisdiction wherein the Licensor resides or in which Licensor conducts its primary business, and under the laws of that jurisdiction excluding its conflict-of-law provisions. The application of the United Nations Convention on Contracts for the International Sale of Goods is expressly excluded. Any use of the Original Work outside the scope of this License or after its termination shall be subject to the requirements and penalties of copyright or patent law in the appropriate jurisdiction. This section shall survive the termination of this License. 12) Attorneys’ Fees. In any action to enforce the terms of this License or seeking damages relating thereto, the prevailing party shall be entitled to recover its costs and expenses, including, without limitation, reasonable attorneys' fees and costs incurred in connection with such action, including any appeal of such action. This section shall survive the termination of this License. 13) Miscellaneous. If any provision of this License is held to be unenforceable, such provision shall be reformed only to the extent necessary to make it enforceable. 14) Definition of "You" in This License. "You" throughout this License, whether in upper or lower case, means an individual or a legal entity exercising rights under, and complying with all of the terms of, this License. For legal entities, "You" includes any entity that controls, is controlled by, or is under common control with you. For purposes of this definition, "control" means (i) the power, direct or indirect, to cause the direction or management of such entity, whether by contract or otherwise, or (ii) ownership of fifty percent (50%) or more of the outstanding shares, or (iii) beneficial ownership of such entity. 15) Right to Use. You may use the Original Work in all ways not otherwise restricted or conditioned by this License or by law, and Licensor promises not to interfere with or be responsible for such uses by You. 16) Modification of This License. This License is Copyright © 2005 Lawrence Rosen. Permission is granted to copy, distribute, or communicate this License without modification. Nothing in this License permits You to modify this License as applied to the Original Work or to Derivative Works. However, You may modify the text of this License and copy, distribute or communicate your modified version (the "Modified License") and apply it to other original works of authorship subject to the following conditions: (i) You may not indicate in any way that your Modified License is the "Academic Free License" or "AFL" and you may not use those names in the name of your Modified License; (ii) You must replace the notice specified in the first paragraph above with the notice "Licensed under <insert your license name here>" or with a notice of your own that is not confusingly similar to the notice in this License; and (iii) You may not claim that your original works are open source software unless your Modified License has been approved by Open Source Initiative (OSI) and You comply with its license review and certification process.

简介

日志审计、切面 展开 收起
Java
AFL-3.0
取消

发行版

暂无发行版

贡献者

全部

近期动态

加载更多
不能加载更多了
1
https://gitee.com/zarchary/log-auit.git
git@gitee.com:zarchary/log-auit.git
zarchary
log-auit
LogAuit
master

搜索帮助