update 删除异常用户token

This commit is contained in:
疯狂的狮子Li 2021-12-09 16:21:26 +08:00
parent f7664a2d7e
commit e442bce607
2 changed files with 5 additions and 0 deletions

View File

@ -49,6 +49,7 @@ public class SysUserOnlineController extends BaseController {
// 如果已经过期则踢下线
if (StpUtil.stpLogic.getTokenActivityTimeoutByToken(key) < 0) {
StpUtil.kickoutByTokenValue(key);
continue;
}
String onlineKey = key.replace(Constants.LOGIN_TOKEN_KEY, Constants.ONLINE_TOKEN_KEY);
userOnlineDTOList.add(RedisUtils.getCacheObject(onlineKey));

View File

@ -4,9 +4,11 @@ import cn.dev33.satoken.exception.NotLoginException;
import cn.dev33.satoken.exception.NotPermissionException;
import cn.dev33.satoken.exception.NotRoleException;
import cn.hutool.http.HttpStatus;
import com.ruoyi.common.constant.Constants;
import com.ruoyi.common.core.domain.AjaxResult;
import com.ruoyi.common.exception.DemoModeException;
import com.ruoyi.common.exception.ServiceException;
import com.ruoyi.common.utils.RedisUtils;
import com.ruoyi.common.utils.StringUtils;
import lombok.extern.slf4j.Slf4j;
import org.springframework.context.support.DefaultMessageSourceResolvable;
@ -56,6 +58,8 @@ public class GlobalExceptionHandler {
@ExceptionHandler(NotLoginException.class)
public AjaxResult<Void> handleAccessDeniedException(NotLoginException e, HttpServletRequest request) {
String requestURI = request.getRequestURI();
String token = e.getMessage().split("")[1];
RedisUtils.deleteObject(Constants.ONLINE_TOKEN_KEY + token);
log.error("请求地址'{}',认证失败'{}',无法访问系统资源", requestURI, e.getMessage());
return AjaxResult.error(HttpStatus.HTTP_UNAUTHORIZED, StringUtils.format("请求地址'{}',认证失败'{}',无法访问系统资源", requestURI));
}